<?xml version="1.0" encoding="UTF-8"?>
<xccdf:Benchmark xmlns:xccdf="http://checklists.nist.gov/xccdf/1.1" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xhtml="http://www.w3.org/1999/xhtml" id="generated-xccdf" resolved="1">
  <xccdf:status>incomplete</xccdf:status>
  <xccdf:title>Red Hat Vulnerability Assessment for com.redhat.rhsa-all.xml</xccdf:title>
  <xccdf:description>This file has been automatically generated for purpose of vulnerability assessment of
            Red Hat products.</xccdf:description>
  <xccdf:rear-matter xml:lang="en-US">Red Hat and Red Hat Enterprise Linux are either registered trademarks or
            trademarks of Red Hat, Inc. in the United States and other countries. All other names are registered trademarks
            or trademarks of their respective companies.</xccdf:rear-matter>
  <xccdf:platform idref="cpe:/o:redhat:enterprise_linux"/>
  <xccdf:version time="2023-04-05T15:46:46">None, generated from OVAL file.</xccdf:version>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20070304" severity="high">
    <xccdf:title>RHBA-2007:0304: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 5 (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>New features introduced in this update include:

* Xen paravirt kernels for x86/x86_64* 
* CONFIG_SERIAL_8250_NR_UARTS is increased to 64
* implement diskdump support for sata_nv driver
* implement diskdump support for ibmvscsi driver
* add netdump support to 8139cp driver
* update CIFS to 1.45

Added Platform support:

* add support to allow disabling of MSI on PHX6700/6702 SHPC
* add support for Intel ICH9 chipset
* add PCIe power management quirk
* add support for H206 processor PowerNow! with new freqency control
* add support for AMD quad-core systems
* add support for RDTSCP
* add MCE Thresholding support for AMD 0x10 family processors
* add PCI-Express support for Altix
* add support for eClipz
* add new ppc host ethernet adapter device driver
* update SHUB2 hardware support

The following device drivers have been upgraded to new versions:

3w-9xxx: 2.26.04.010 to 2.26.05.007
ahci: 1.2 to 2.0
ata_piix: 1.05 to 2.00ac7
bnx2: 1.4.38 to 1.4.43-rh
bonding: 2.6.3 to 2.6.3-rh
cciss: 2.6.10 to 2.6.14
e1000: 7.0.33-k2-NAPI to 7.2.7-k2-NAPI
ibmvscsic: 1.5.6 to 1.5.7
ipr: 2.0.11.2 to 2.0.11.4
ixgb: 1.0.100-k2-NAPI to 1.0.109-k2-NAPI
libata: 1.20 to 2.00
megaraid_mm: 2.20.2.6 to 2.20.2.6rh
megaraid_sas: 00.00.02.03-RH1 to 00.00.03.05
mptbase: 3.02.62.01rh to 3.02.73rh
pdc_adma: 0.03 to 0.04
qla2100: 8.01.04-d7 to 8.01.04-d8-rh1
qla2200: 8.01.04-d7 to 8.01.04-d8-rh1
qla2300: 8.01.04-d7 to 8.01.04-d8-rh1
qla2322: 8.01.04-d7 to 8.01.04-d8-rh1
qla2400: 8.01.04-d7 to 8.01.04-d8-rh1
qla2xxx: 8.01.04-d7 to 8.01.04-d8-rh1
qla6312: 8.01.04-d7 to 8.01.04-d8-rh1
r8169: 1.2 to 2.2LK-NAPI
sata_mv: 0.6 to 0.7
sata_nv: 0.8 to 3.2
sata_promise: 1.04 to 1.05
sata_qstor: 0.05 to 0.06
sata_sil: 0.9 to 2.0
sata_sis: 0.5 to 0.6
sata_svw: 1.07 to 2.0
sata_sx4: 0.8 to 0.9
sata_uli: 0.5 to 1.0
sata_via: 1.1 to 2.0
sata_vsc: 1.2 to 2.0
sky2: 1.1 to 1.6
stex: 2.9.0.13 to 3.0.0.1
tg3: 3.52-rh to 3.64-rh

Infiniband update from 1.0 to OFED-1.1 code base

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2007:0304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2873</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3379</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20070304"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20070331" severity="low">
    <xccdf:title>RHBA-2007:0331: conga bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Conga package is a web-based administration tool for remote cluster and
storage management.

This erratum applies the following bug fixes:

- The borrowed Zope packages used by Conga have been patched to eliminate
a possibility of XSS attack.
- Passwords are no longer sent back from the server in cleartext for use as
input values.
- A form error was fixed so that Conga no longer allows for cluster
names of over 15 characters.
- An error wherein clusters and systems could not be deleted from the
manage systems interface has been addressed.
- Entering an incorrect password for a system no longer generates an
Unbound Local Reference exception.
- Luci failover domain forms are no longer empty
- The fence_xvm string in cluster.conf for virtual cluster fencing has been
corrected.
- The advanced options parameters section has been fixed.
- A bug where virtual services were unable for configuration has been
addressed.
- kmod-gfs-xen is now installed when necessary.
- The 'enable shared storage support' checkbox is now cleared when a
configuration error is encountered.
- When configuring an outer physical cluster, it is no longer necessary to
add the fence_xvmd tag manually.

Users of Conga are advised to upgrade to these updated packages, which
apply these fixes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2007:0331</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0240</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1462</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20070331"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20070565" severity="medium">
    <xccdf:title>RHBA-2007:0565: tcp_wrappers bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tcp_wrappers package provides small daemon programs which can monitor
and filter incoming requests for systat, finger, FTP, telnet, rlogin, rsh,
exec, tftp, talk and other network services. It also contains the libwrap
library that adds the same filtering capabilities to programs linked
against it, like sshd and more.

This update brings the following changes:

* localhost and localhost.localdomain are treated as being equivalent when
comparing the client hostname and the list of allowed/denied hostnames.

* the hosts_ctl function uses the address parameter to get the ip address
and resolve it to symbolic hostname, if not given.

* the behavior of signal handling when the "spawn" option is used has been
changed to be transparent to the application using the library.

These fixes correct the behavior of certain applications, including
net-snmp and vsftpd.

Users should upgrade to this updated package, which resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2007:0565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0786</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20070565"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20080314" severity="high">
    <xccdf:title>RHBA-2008:0314: Updated kernel packages for Red Hat Enterprise Linux 5.2 (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

General Kernel Feature Support:

* rebase xen packages to version 3.1.2
* performance improvements and bug fixes for GFS2
* update utrace support
* add eCryptfs support
* add NFS server support for 32-bit clients, and 64-bit inodes
* add memory accounting in UDP
* add RFC 4303 compliant auditing support
* add new algorithms and interfaces in IPsec
* add authenc in crypto library

General Platform Support:

* update on-demand governor driver
* enable config options for IPMI panic handling
* add HDMI support for AMD and ATI integrated chipsets
* update OFED support to v1.3
* update FireWire support to latest upstream
* eliminate erroneous PCI Rom warning messages
* add support to offline CPU when realtime processes are running

Architecture Specific Support:

x86, AMD64, Intel(R) 64:

* add support of pci=norom boot parameter to disable p2p rom window
* enable pci=bfsort
* increase boot command line size to 2048 for 64-bit architectures
* add event based profiling support to AMD Greyhound systems
* add Intel Dynamic Acceleration Technology

Intel(R) 64:

* add CMCI for hot-plugged processors
* remove Intel(R) 64 stack hard limit of DEFAULT_USER_STACK_SIZE
* add zonelist order sysctl/boot option on NUMA systems

64-bit PowerPC:

* add OProfile support to IBM Cell/B.E. platforms
* update PMI driver for Cell blades
* enable support of FB_RADEON driver for IBM Power6 blades
* update ehea driver to latest upstream
* add Scaled Processor Utilization of Resources Register SPURR support
* boot Cell blades with more than 2GB memory
* improve watchpoint support in GDB for power platform
* improve hugepage allocation with memory-less nodes
* add SLB shadow buffer support

IBM System z:

* add large page support to IBM System z
* add IBM eServer zSeries HiperSockets MAC layer routing and IP packet
support
* add IBM z/VM monitor stream state 2 application support
* add support for IBM z/VM DIAG 2FC for HYPFS
* add AF_IUCV Protocol support on BSD socket interface
* add dynamic CHPID reconfiguration support via SCLP

New Driver Support or Driver Updates:

Miscellaneous Driver Updates:

* add R500/R600 drm driver (X11 deccelerator driver) support
* add trust computing/trust platfrom module
* add support for Realtek ALC888S codec

Network Driver Updates:

* add bnx2x driver for Broadcom 10GbE hardware
* add dm9601 driver support for DAVICOM's ZT6688
* update bnx2, e1000, e1000e, tg3, forcedeth, igb, ixgb, and cxgb3 drivers
* add WEXT scan capabilities to wireless extensions API
* update mac80211/iwl4965 infrastructure
* update cfg80211 driver to support mac80211/iwl4965
* update ixgbe driver to support new Intel 10GbE hardware
* add r8169 driver support for Realtek 8111c and 8101e loms
* update bonding, netxen, and ioatdma driver

Storage Driver Updates:

* update aic94xx, areca, aacraid, cciss, ibmvSCSI driver
* update ipr driver to add dual SAS RAID controller support
* add iSCSI Boot Firmware Table tool support
* update qla2xxx, mpt-fusion, lpfc, stex, megaraid_sas
* update firmwire for Qlogic 25xxx
* update SATA driver and infrastructure
* add SB800/SB700/SB600 SATA/LAN support
* add DRAC4 hotplug support
* add hotplug docking support for some laptops
* add uevent, and kobject to device mapper infrastructure for xDR/GDPs
* update device mapper support

For a comprehensive list of kernel-related updates, refer to the latest
version of the Red Hat Enterprise Linux 5.2 release notes on:

http://www.redhat.com/docs/manuals/enterprise/

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which apply these kernel updates.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2008:0314</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2365</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20080314"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20090070" severity="low">
    <xccdf:title>RHBA-2009:0070: util-linux bug-fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. Among
others, util-linux contains the fdisk configuration tool and the login
program.

This update fixes the following bugs:

* The login command segmentation fault on EOF.
* The script command does not log all commands to the typescript file.
* Obsolete information in the mkfs man page.
* Obsolete information about fstab-sync in the fstab man page.
* Obsolete information in the fdisk man page.
* The blockdev command calls the blkpg ioctl with a wrong data structure.
* The mount command does not check for validity of mtab information.
* The mkswap defaults to v0 format on ppc64.
* The fdisk command does not warn about DOS partition table limitations on
on large hard drives.
* The fdisk command does not properly detect VMware partitions.
* The sfdisk command does not work correctly with large hard drives.
* The logger command cannot be used when /usr is non-root partition.
* The audit log injection attack via the login command.
* The swapon command with the "-a" option does not complain about missing
devices.

Users of util-linux are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2009:0070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1926</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20090070"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20100266" severity="low">
    <xccdf:title>RHBA-2010:0266: cman bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Cluster Manager (cman) utility provides user-level services for
managing a Linux cluster.

Changes in this update:

* fence_rsa fails to login with new RSA II firmware. (BZ#549473)

* fence_virsh reports vm status incorrectly. (BZ#544664)

* improve error messages from ccsd if there is a network problem.
(BZ#517399)

* new fence agent for VMWare. (BZ#548577)

Note: this is a Tech Preview only.

* fence agent for HP iLO2 MP. (BZ#508722)

* fence agent for RSB ends with traceback. (BZ#545054)

* security feature for SNMP based agent: apc_snmp &amp; ibmblade. (BZ#532922)

* change default timeout values for various fence agents. (BZ#549124)

* "Option -V" (show version) was not working in all fence agents.
(BZ#549113)

* automatically configure consensus based on token timeout. (BZ#544482)

* add readconfig &amp; dumpconfig to fence_tool. (BZ#514662)

* make groupd handle partition merges. (BZ#546082)

* groupd: clean up leaving failed node. (BZ#521817)

* scsi_reserve should always echo after failure. (BZ#514260)

* fence_scsi_test: add debug information. (BZ#516763)

* fence_scsi_test should not allow -c &amp; -s options together. (BZ#528832)

* fix fence_ipmilan read from unitialized memory. (BZ#532138)

* make qdiskd stop crying wolf. (BZ#532773)

* fencing failed when used without telnet or ssh. (BZ#512343)

* APC changed product name (MasterSwitch -&gt; Switched Rack PDU). (BZ#447481)

* fix invalid initalization introduced by retry-on option.

* broken device detection for DRAC3 ERA/O. (BZ#489809)

* fix case sensitivities in action parameter. (BZ#528938)

* fencing_snmp failed on all operations &amp; traceback fix. (BZ#528916)

* accept unknown options from standard input. (BZ#532920)

* fence_apc unable to obtain plug status. (BZ#532916)

* timeout options added. (BZ#507514)

* better default timeout for bladecenter. (BZ#526806)

* the LOGIN_TIMEOUT value was too short for fence_lpar &amp; the SSH login
timed out before the connection could be completed. (BZ#546340)

* add missing-as-off option (missing blade/device is always OFF).
(BZ#248006)

* make qdiskd "master-wins" node work. (BZ#372901)

* make qdisk self-fence system if write errors take longer than
interval*tko. (BZ#511113)

* make service_cman.lcrso executable, so RPM adds it to the debuginfo pkg.
(BZ#511346)

* don't check for xm command in cman init script: virsh is more
appropriate. (BZ#516111)

* allow re-registering of a quorum device. (BZ#525270)

* fix fence_scsi, multipath &amp; persistent reservations. (BZ#516625)

* cman_tool leave remove reduces quorum when no services are connected.
(BZ#515446)

* fence_sanbox2 unable to retrieve status. (BZ#512947)

* gfs_controld: GETLK should free unused resource. (BZ#513285)

* allow IP addresses as node names. (BZ#504158)

* fence_scsi man page contains invalid option. (BZ#515731)

* fence_scsi support for 2 node clusters. (BZ#516085)

* Support for power cycle in fence ipmi. (BZ#482913)

* add option 'list devices' for fencing agents. (BZ#519697)

* add support for switching IPv4/IPv6. (BZ#520458)

* fence agent ends with traceback if option is missing. (BZ#508262)

* command line options to override default ports for different services,
such as SSH &amp; Telnet (i.e. -u option) were added. (BZ#506928)

Note: "-u" does not currently work with fence_wti. Other agents honor the
port override command line options properly, however. (BZ#506928)

* force stdout close for fencing agents. (BZ#518622)

* support for long options. (BZ#519670)

* fix a situation where cman could kill the wrong nodes. (BZ#513260)

* fix support for &gt;100 gfs &amp; gfs2 file systems. (BZ#561892)

* fix a problem where 'dm suspend' would hang a withdrawn GFS file system.
(BZ#570530)

* fix a problem where fence_snmp returned success when the operation
failed. (BZ#573834)

* fencing support for the new iDRAC interface included with Dell PowerEdge
R710 &amp; R910 blade servers was added. (BZ#496748)

All cman users should install this update which makes these changes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2010:0266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4192</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20100266"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20110054" severity="low">
    <xccdf:title>RHBA-2011:0054: samba3x bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines for authentication, and file and printer sharing.

These updated samba3x packages provide fixes for the following bugs:

* Users of trusted child domains were not authenticated correctly. As a result, some users of such domains did not appear as members of the parent domain even if the child domain allowed full inheriting from the parent domain. With this update, all users of a trusted child domain are authenticated successfully. (BZ#459842)

* The smb.conf manual page  contained an ambiguous description of the 'default case' parameter. With this update, the description is updated and gives a clear description. (BZ#480405)

* Service principal names were not always created correctly and as a result, the system was attempting to acquire a service ticket using a wrong hostname. This caused the Kerberos authentication to fail. With this update, service principal names are created correctly. (BZ#560239)

* CUPS printing could fail in an Active Directory environment with Kerberos. With this update, regular users can print in such environment. (BZ#565774)

* When the 'normalize names' setting was enabled, the winbindd service could have failed after user authentication. With this update, authentication is successful. (BZ#565915)

* Packages requiring samba cannot recognize samba3x as an updated samba version. With this update, dependent packages recognize samba3x as the new samba version. (BZ#582756)

* Some remote users could not authenticate from workstations running Windows. This occurred, because the winbind service failed to authenticate to Windows Server 2008 using the "ntlm-server-1" ntm_auth protocol. With this update, the service works correctly. (BZ#590766)

* In the offline mode, the winbind service could have logged the following message: "Exceeding 200 client connections, no idle connection found." With this update, the error no longer occurs and you can set the client limit manually with the command 'winbind max clients'. (BZ#604081)

* The winbindd client limit was set to 200 and could not be changed. With this update, you can set the client limit manually with the command 'winbind max clients'. (BZ#641379)

* Previously, the samba3x package considered any samba package a conflicting package. With this update, samba3x checks for possible non-conflicting versions of the samba package. (BZ#609578)

* When using non-standard character sets, the command 'wbinfo' displayed user and group names with accented characters incorrectly. With this update, those names are displayed correctly with all supported character sets. (BZ#649708)

* Samba could have failed to connect to workstations running Windows 7 with Live Essentials installed due to a SPNEGO parsing failure. With this update, the connection succeeds. (BZ#651722)

In addition, these updated packages provide the following enhancements:

* Interoperation with Windows 7 and Windows Server 2008 was fixed. Secure channel connections to servers with Windows Server 2008 R2 and interdomain trusts with Windows Server 2008 domains are now supported. Previously also, due to errors in the secure channel to Windows 7 and Windows Server 2008 R2, the winbind daemon could corrupt the secure channel. With this update, this no longer occurs. (BZ#527997)

* In Red Hat Enterprise Linux 5.6, the samba3x package no longer provides the libtalloc library. The library is now provided in a separate source RPM. (BZ#596883)

* In Red Hat Enterprise Linux 5.6, the samba3x package no longer provides the libtdb library. The library is now provided in a separate source RPM. (BZ#596886)

Users are advised to upgrade to these updated samba3x packages, which resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2011:0054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0787</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20110054"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20111656" severity="medium">
    <xccdf:title>RHBA-2011:1656: mod_nss bug fix update  (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_nss module provides strong cryptography for the Apache HTTP Server via the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, using the Network Security Services (NSS) security library.

This update fixes the following bugs: 

* When the NSS library was not initialized and mod_nss tried to clear its SSL cache on start-up, mod_nss terminated unexpectedly when the NSS library was built with debugging enabled. With this update, mod_nss does not try to clear the SSL cache in the described scenario, thus preventing this bug. (BZ#691502)

* Previously, a static array containing the arguments for launching the nss_pcache command was overflowing the size by one. This could lead to a variety of issues including unexpected termination. This bug has been fixed, and mod_nss now uses properly sized static array when launching nss_pcache. (BZ#714154)

* Prior to this update, client certificates were only retrieved during the initial SSL handshake if the NSSVerifyClient option was set to "require" or "optional". Also, the FakeBasicAuth option only retrieved Common Name rather than the entire certificate subject. Consequently, it was possible to spoof an identity using that option. This bug has been fixed, the FakeBasicAuth option is now prefixed with "/" and is thus compatible with OpenSSL, and certificates are now retrieved on all subsequent requests beyond the first one. (BZ#702437)

Users of mod_nss are advised to upgrade to this updated package, which fixes these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2011:1656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4973</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20111656"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20120319" severity="low">
    <xccdf:title>RHBA-2012:0319: gnutls bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gnutls package provides the GNU Transport Layer Security (GnuTLS) library, which provides a secure layer over a transport layer using protocols such as TLS, SSL and DTLS.

This update fixes the following bug:

* Under certain circumstances, a NULL pointer could have been dereferenced in the GnuTLS library. This caused TLS clients, such as the rsyslog utility, to terminate unexpectedly with a segmentation fault. This update adds a test condition ensuring that a NULL pointer can no longer be dereferenced and TLS clients no longer crash. (BZ#789041)

All users of gnutls are advised to upgrade to these updated packages, which fix this bug. All applications linked with the GnuTLS library must be restarted (or the system rebooted) in order for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2012:0319</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7239</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20120319"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20120763" severity="medium">
    <xccdf:title>RHBA-2012:0763: glibc bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.

These updated glibc packages include numerous bug fixes and one enhancement. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.3 Technical Notes for information on the most significant of these changes:

https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/6.3_Technical_Notes/glibc.html#RHBA-2012-0763

Users of glibc are advised to upgrade to these updated packages, which fix these bugs and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2012:0763</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6686</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20120763"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20120881" severity="low">
    <xccdf:title>RHBA-2012:0881: freeradius bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is an open-source Remote Authentication Dial In User Service (RADIUS) server which allows RADIUS clients to perform authentication against the RADIUS server. The RADIUS server may optionally perform accounting of its operations using the RADIUS protocol.

The freeradius packages have been upgraded to upstream version 2.1.12, which provides a number of bug fixes and enhancements over the previous version. (BZ#736878)

This update fixes the following bugs:

* The radtest command-line argument to request the PPP hint option was not parsed correctly. Consequently, radclient did not add the PPP hint to the request packet and the test failed. This update corrects the problem and radtest now functions as expected. (BZ#787116)

* After log rotation, the freeradius logrotate script failed to reload the radiusd daemon after a log rotation and log messages were lost. This update has added a command to the freeradius logrotate script to reload the radiusd daemon and the radiusd daemon reinitializes and reopens its log files after log rotation as expected. (BZ#705723)

* The radtest argument with the eap-md5 option failed because it passed the IP family argument when invoking the radeapclient utility and the radeapclient utility did not recognize the IP family. The radeapclient now recognizes the IP family argument and radtest now works with eap-md5 as expected. (BZ#712803)

* Previously, freeradius was compiled without the "--with-udpfromto" option. Consequently, with a multihomed server and explicitly specifying the IP address, freeradius sent the reply from the wrong IP address. With this update, freeradius has been built with the --with-udpfromto configuration option and the RADIUS reply is always sourced from the IP the request was sent to. (BZ#700870)

* The password expiration field for local passwords was not checked by the unix module and the debug information was erroneous. Consequently, a user with an expired password in the local password file was authenticated despite having an expired password. With this update, check of the password expiration has been modified. A user with an expired local password is denied access and correct debugging information is written to the log file. (BZ#753764)

* Due to invalid syntax in the PostgreSQL admin schema file, the FreeRADIUS PostgreSQL tables failed to be created. With this update, the syntax has been adjusted and the tables are created as expected. (BZ#690756)

* When FreeRADIUS received a request, it sometimes failed with the following message:

    WARNING: Internal sanity check failed in event handler for request 6

This bug was fixed by upgrading to upstream version 2.1.12. (BZ#782905)

* FreeRADIUS has a thread pool that will dynamically grow based on load.  If multiple threads using the rlm_perl() function are spawned in quick succession, freeradius sometimes terminated unexpectedly with a segmentation fault due to parallel calls to the rlm_perl_clone() function. With this update, mutex for the threads has been added and the problem no longer occurs. (BZ#810605)

All users of freeradius are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2012:0881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4966</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20120881"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20130009" severity="medium">
    <xccdf:title>RHBA-2013:0009: mod_nss bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_nss module provides strong cryptography for the Apache HTTP Server via the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, using the Network Security Services (NSS) security library.

This update fixes the following bugs:

* The previous release had an incorrect post-install script. Consequently, when upgrading "mod_nss" from version 1.0.3 to 1.0.8, the group and file permissions were incorrectly set. The HTTP server (httpd) did not start and the following error message was displayed:

    [error] NSS_Initialize failed. Certificate database: /etc/httpd/alias.
    [error] SSL Library Error: -8038 SEC_ERROR_NOT_INITIALIZED

This update improves the post-install script to set file permissions and ownership correctly. As a result, all child processes of the Apache HTTP Server can enable SSL and now httpd starts as expected in the scenario described. (BZ#669963)

* With the release of "mod_nss" version 1.0.8 there was no lock mechanism to control sequential httpd process access to the "nss_pcache" process. This sometimes resulted in multiple requests being interpreted as a single request by "nss_pcache" and a single result returned. The calling process sometimes experienced a timeout error or a failure with the error message:

    [error] Unable to read from pin store

With this update the code has been improved and multiple requests to the "nss_pcache" process are processed sequentially without the errors described. (BZ#677698)

* Due to a regression, the "mod_proxy" module no longer worked when configured to support reverse proxy operation. The following error was logged:

    [error] SSL Proxy: I don't have the name of the host we're supposed to connect to so I can't verify that we are connecting to who we think we should be. Giving up.

A new patch has been applied and the "mod_proxy" module now works correctly to support SSL reverse proxy. (BZ#692868)

* Previously, a static array containing the arguments for launching the "nss_pcache" command overflowed the array size by one. This could lead to a variety of problems including unexpected termination. This bug has been fixed, and "mod_nss" now uses a properly sized static array when launching "nss_pcache". (BZ#714255)

* Due to an incorrect use of the memcpy() function in the "mod_nss" module, running the Apache HTTP Server with this module enabled could cause some requests to fail with the following message written to the error_log file:

    request failed: error reading the headers

This update applies a patch to ensure that the memcpy() function is now used in accordance with the current specification, and using the "mod_nss" module no longer causes HTTP requests to fail. (BZ#749401)

* Prior to this update, client certificates were only retrieved during the initial SSL handshake if the NSSVerifyClient option was set to "require" or "optional". Also, the FakeBasicAuth option only retrieved Common Name rather than the entire certificate subject. Consequently, it was possible to spoof an identity using that option. This bug has been fixed, the FakeBasicAuth option is now prefixed with "/" and is thus compatible with OpenSSL. Certificates are now retrieved on all subsequent requests beyond the first one. (BZ#749402).

* When the NSS library was not initialized and "mod_nss" tried to clear its SSL cache on start-up, "mod_nss" terminated unexpectedly when the NSS library was built with debugging enabled. With this update, "mod_nss" does not try to clear the SSL cache in the described scenario, thus preventing this bug. (BZ#749405, BZ#784548)

* The "Requires: %{_libdir}/libnssckbi.so" directive has been added to the spec file to make "libnssckbi.so" a runtime dependency. This is to prevent symbolic links failing. (BZ#749406)

All users of mod_nss are advised to upgrade to these updated packages, which fix these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4973</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20130009"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20130022" severity="medium">
    <xccdf:title>RHBA-2013:0022: glibc bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.

These updated glibc packages include numerous bug fixes and enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 5.9 Technical Notes for information on the most significant of these changes:

https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.9_Technical_Notes/glibc.html#RHBA-2013-0022

All users of glibc are advised to upgrade to these updated packages, which provide numerous bug fixes and enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:0022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6686</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20130022"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20130363" severity="low">
    <xccdf:title>RHBA-2013:0363: sudo bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (super user do) utility allows system administrators to give certain users the ability to run commands as root.

The updated sudo packages include numerous bug fixes and enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical Notes for information on the most significant of these changes:

https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/6/html/6.4_Technical_Notes/sudo.html

Users of sudo are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:0363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20130363"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20130386" severity="low">
    <xccdf:title>RHBA-2013:0386: tuned bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tuned packages contain a daemon that tunes system settings dynamically. It does so by monitoring the usage of several system components periodically. 

This update fixes the following bugs:

* Red Hat Enterprise Linux 6.1 and later enters processor power-saving states more aggressively. This could result in a small performance penalty on certain workloads. With this update, the pmqos-static.py daemon has been added to the tuned packages, which allows to set the requested latency using the kernel Power Management QoS interface. It is run when the "latency-performance" profile is activated and it sets cpu_dma_latency=0, which keeps the CPU in C0 state, thus making the system as responsive as possible. (BZ#714180)

* When the ELEVATOR_TUNE_DEVS option was set to a disk device in the /etc/sysconfig/ktune file instead of providing a disk scheduler control file, the scheduler setting was not written to a disk scheduler control file but directly into the disk device file. Consequently, contents of the disk could become corrupted. With this update, the value of ELEVATOR_TUNE_DEVS is checked and only the disk scheduler control file is allowed for writing. As a result, an invalid value of ELEVATOR_TUNE_DEVS is detected in the described scenario so that the disk contents damage can be prevented. (BZ#784308)

* When the tuned daemon run with the "enterprise-storage" profile enabled and a non-root, non-boot disk partition from a device with write-back cache was mounted, tuned remounted the partition with the "nobarriers" option. If a power failure occurred at that time, the file system could become corrupted. With this update, tuned can detect usage of write-back cache on devices communicating with kernel via SCSI. In these cases, "nobarriers" is now disabled, thus preventing this bug in the described scenario. (BZ#801561)

* Previously, when the tuned service was started, the tuned PID file was created with world-writable permissions. This bug has been fixed and the /var/run/tuned/tuned.pid file is now created with correct permissions as expected. (BZ#845336)

* On a machine with hot-plug disk devices with the "enterprise-storage" profile activated, a new disk device could be added into the system, or the disk could be removed and inserted back. In such a scenario, the scheduler and read-ahead settings from the profile were not applied on the newly-added disks. With this update, a new udev rule has been added, which restarts the ktune daemon whenever a new disk device is added, thus fixing this bug. (BZ#847445)

* The transparent hugepage kernel thread could interfere with latency-sensitive applications. To lower the latency, the transparent hugepages are now disabled in the latency-performance tuned profile. (BZ#887355)

* Previously, non-root, non-boot partitions were re-mounted using the "nobarrier" option to improve performance. On virtual guests, this could lead to data corruption if power supply was suddenly interrupted, because there was usually a host cache in transfer. This bug has been fixed and the virtual-guest profile no longer re-mounts partitions using "nobarrier". (BZ#886956)

Users of tuned are advised to upgrade to these updated packages, which fix these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6136</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20130386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20131150" severity="medium">
    <xccdf:title>RHBA-2013:1150: net-snmp bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple Network Management Protocol (SNMP), including an SNMP library, an extensible agent, tools for requesting or setting information from SNMP agents, tools for generating and handling SNMP traps, a version of the netstat command which uses SNMP, and a Tk/Perl Management Information Base (MIB) browser.

This update fixes the following bug:

* When an AgentX subagent disconnected from the SNMP daemon (snmpd), the daemon did not properly check that there were no active requests queued in the subagent and destroyed the session. Consequently, the session was referenced by snmpd later when processing queued requests and because it was already destroyed, snmpd terminated unexpectedly with a segmentation fault or looped indefinitely. This update adds several checks to prevent the destruction of sessions with active requests, and snmpd no longer crashes in the described scenario. (BZ#993579)

Users of net-snmp are advised to upgrade to these updated packages, which fix this bug.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:1150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6151</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20131150"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20131581" severity="medium">
    <xccdf:title>RHBA-2013:1581: libvirt bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.

These updated libvirt packages include numerous bug fixes and enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes for information on the most significant of these changes: 

https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/6.5_Technical_Notes/libvirt.html#RHBA-2013-1581 

All libvirt users are advised to upgrade to these updated packages, which fix these bugs and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:1581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7336</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20131581"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20131647" severity="low">
    <xccdf:title>RHBA-2013:1647: mysql bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes the following bugs:

* Prior to this update, the mysqld daemon worked with uninitialized memory when accessing non-nullable GEOMETRY types. Cosequenutly, mysqld could terminate unexpectedly when the mysqldump utility was running. With this update, mysqld initializes memory properly and thus no longer crashes in this scenario (BZ#842052)

* Previously, the mysqldump utility expected log tables to be created on the MySQL 5.0.x server, from which it retrieved data. Consequently, mysqldump could not dump the MySQL system table. With this update, mysqldump no longer expects log tables to be created, and it is now able to dump the system table in the described scenario as expected. (BZ#877557) 

* Prior to this update, the mysqld init script did not correctly verify the status of the mysqld daemon. Consequently, the script could return an error message even when the daemon had successfully started. The mysqld init script has been fixed, and it now checks the daemon status properly. (BZ#884651) 

* Previously, the mysql-server sub-packages did not contain the logrotate script. Consequently, the log rotation had to be configured manually. With this update, the logrotate script has been provided by the mysql-server sub-packages, and users can use the script to log into the mysqld.log file by uncommenting appropriate lines in the script. (BZ#904061)

Users of mysql are advised to upgrade to these updated packages, which fix these bugs. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2013:1647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3839</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20131647"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141200" severity="low">
    <xccdf:title>RHBA-2014:1200: sos bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sos package contains a set of utilities that gather information from system
hardware, logs, and configuration files. The information can then be used for
diagnostic purposes and debugging.

This update fixes the following bugs:

* Previously, the sosreport utility did not include the output of the "brctl
show" command for all systems. Consequently, information on bridged network
configurations was only available in the report tarball on systems using Xen for
virtualization. With this update, the networking module collects the output of
"brctl show" as well as "brctl showstp" commands for each configured bridge, and
thus bridged network configuration information is now available in the report
tarball for all hosts. (BZ#833406) 

* Previous versions of the sosreport utility used the legacy ifconfig command to
detect network interfaces, but ifconfig did not support interfaces named via
biosdevname. As a consequence, no information on biosdevname interfaces was
present in the report tarball. With this update, the sosreport networking
plug-in now uses the "ip" command to detect interfaces of all types, and full
information on biosdevname interfaces is now included. (BZ#980177) 

* Previously, the sosreport utility collected the krb5.keytab file from Kerberos
installations. Although encrypted, this file can contain sensitive key material.
With this update, sosreport collects a summary of krb5.keytab using the klist
command but does not collect the krb5.keytab file itself. As a result,
krb5.keytab data is still available but no sensitive information is included in
the report tarball. (BZ#1029017)

* Previously, the sosreport "ds" plug-in collected all directory server logs by
default. Depending on the log configuration, this could lead to very large
report sizes. With this update, sosreport collects by default only the current
version of the directory server logs regarding to "access", "errors" and
"audit", and rotated logs are not collected by default. In addition, the plug-in
now supports an "all_logs" option that can be used to request the old behavior.
As a result, the default report size for directory server hosts is now smaller
and more consistent unless full log data is explicitly requested. (BZ#1086736)

* Prior to this update, the sosreport utility could include password material in
the grub.conf and fstab files collected by the boot loader and file system
plug-ins if present on the collection system. Consequently, passwords, either
plain text or hashed, could be included in the report tarball. With this bug fix
update, password and other secrets are now removed during collection, and
passwords from the fstab or grub.conf files can no longer appear in the report
tarball. (BZ#1107751) 

Users of sos are advised to upgrade to this updated package, which fixes these
bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3925</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141200"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141206" severity="medium">
    <xccdf:title>RHBA-2014:1206: virt-who bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The virt-who package provides an agent that collects information about virtual
guests present in the system and reports them to the subscription manager.

The virt-who package has been upgraded to upstream version 0.9, which provides a
number of bug fixes and enhancements over the previous version. 
Notably, the permissions for the configuration file has been changed from
world-readable to root-only readable. This change is only for new installations
of virt-who; existing installations should be fixed manually by setting the
permission of the /etc/sysconfig/virt-who file to 600. (BZ#861552)

This update also fixes the following bugs:

* Prior to this update, the configuration file for virt-who contained incorrect
permissions and was world-readable, although this file can contain passwords. As
a consequence, any user could read the passwords from the configuration file. To
fix this bug, the permissions have been changed to be root-readable only, and
non-root users can no longer read passwords from the virt-who configuration
file. (BZ#1088756) 

* Previously, the virt-who utility did not report the state of virtual guests to
the Subscription Asset Manager (SAM) server. To fix this bug, the info() method
from libvirt has been used, and the state of a virtual machine is now reported
to the SAM server. (BZ#1124732)

In addition, this update adds the following enhancements:

* With this update, support for Red Hat Enterprise Virtualization Manager
virtualization back end has been added to virt-who. Now, the user can use
virt-who on Red Hat Enterprise Linux 5.11.0 to gather host/guest associations
from Red Hat Enterprise Virtualization Manager. (BZ#1009401)

* Although virt-who worked properly with VMware ESX software, the support for
VMware ESXi software was not functional due to differences between ESX and ESXi.
With this update, support for ESXi as virtualization back end has been provided
for virt-who, which can now use both ESX and ESXi as virtualization back ends.
(BZ#1078858)

Users of virt-who are advised to upgrade to these updated packages, which fix
these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0189</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141375" severity="low">
    <xccdf:title>RHBA-2014:1375: sssd bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) provides a set of daemons to manage
access to remote directories and authentication mechanisms. It provides the Name
Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces
toward the system and a pluggable back-end system to connect to multiple
different account sources.

These updated sssd packages include numerous bug fixes and enhancements. Space
precludes documenting all of these changes in this advisory. Users are directed
to the Red Hat Enterprise Linux 6.6 Technical Notes for information on the most
significant of these changes:

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/6.6_Technical_Notes/sssd.html#RHBA-2014-1375

Users of sssd are advised to upgrade to these updated packages, which fix these
bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0249</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141375"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141376" severity="medium">
    <xccdf:title>RHBA-2014:1376: xcb-util, xorg-x11-drivers, and mesa bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xcb-util package provides a number of libraries that use the libxcb library,
the core X protocol library, and some of the extension libraries. These
libraries provide convenience functions and interfaces which make the raw X
protocol more usable. Some of the libraries also provide client-side code which
is not strictly part of the X protocol but which have traditionally been
provided by the Xlib library. 

The individual X.Org drivers, previously provided by the xorg-x11-drivers
package, are included to allow installation of all drivers at once, without
having to track which individual drivers are present on each architecture.

This package also provides Mesa 3D graphics API that is compatible with Open
Graphics Library (OpenGL), as well as hardware-accelerated drivers for many
popular graphics chips.

The updated xcb-util packages include numerous bug fixes and one enhancement.
Space precludes documenting all of these changes in this advisory. Users are
directed to the Red Hat Enterprise Linux 6.6 Technical Notes for information on
the most significant of these changes: 

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/6.6_Technical_Notes/xcb-util.html#RHBA-2014-1376

Users of xcb-util, xorg-x11-drivers, and mesa are advised to upgrade to these
updated packages, which fix these bugs and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1994</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141417" severity="medium">
    <xccdf:title>RHBA-2014:1417: icedtea-web bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It also
contains a configuration tool for managing deployment settings for the plug-in
and Web Start implementations.

The icedtea-web packages have been upgraded to upstream version 1.5.1, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1075790)

Users of icedtea-web are advised to upgrade to these updated packages, which fix
these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141417"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20141513" severity="medium">
    <xccdf:title>RHBA-2014:1513: virt-who bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The virt-who package provides an agent that collects information about virtual
guests present in the system and reports them to the Red Hat Subscription
Manager tool.

The virt-who package has been upgraded to upstream version 0.10, which provides
a number of bug fixes and enhancements over the previous version. This update
includes support for multiple vCenter servers, fixed querying by cluster in
large ESX environments, corrected communication with Red Hat Satellite server
when ESXi has no host, fixed unregistering from Subscription Asset Manager (SAM)
server, fixed bug in Virtual Desktop and Server Management (VDSM) mode, support
for encrypted credentials, and fixed error when creating new VMs. (BZ#1002640,
BZ#994575, BZ#1002447, BZ#1009230, BZ#1011877, BZ#1017056, BZ#1081286,
BZ#1082416)

This update also fixes the following bugs:

* Previously, the virt-who daemon did not report guest attributes to the server,
which disabled the virt_guest_limit feature. With this update, virt-who has been
modified to correctly report guest attributes. As a result, virt_guest_limit is
now supported by virt-who. (BZ#1098019)

* Prior to this update, every call to Libvirtd.listDomains() function from the
/usr/share/virt-who/virt/libvirtd/libvirtd.py script opened a new connection to
the libvirtd daemon but did not close it. Consequently, after several
iterations, virt-who consumed all connections allowed for any client of
libvirtd. With this update, Libvirtd.listDomains() has been modified to properly
close the livirtd connections, thus fixing this bug. (BZ#1113938)

Users of virt-who are advised to upgrade to this updated package, which fixes
these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2014:1513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0189</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20141513"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150364" severity="medium">
    <xccdf:title>RHBA-2015:0364: nss, nss-softokn, nss-util, and nspr bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

The nss, nss-softokn, and nss-util packages have been upgraded to upstream versions 3.16.2.3, and the nspr packages have been upgraded to upstream version 4.10.6. The upgraded versions provide a number of bug fixes and enhancements over the previous versions, including:

* Updating to Firefox 31.3 is possible.
* The softokn database code now checks the "NSS_SDB_USE_CACHE" environment variable. As a result, using libcurl and curl for HTTPS requests no longer results in unnecessary access system calls to non-existent paths, directories, and files.
(BZ#1103250, BZ#1103251, BZ#1103252, BZ#1103925, BZ#1158161, BZ#1117959)

This update also fixes the following bugs:

* NSS changed the permissions of the /etc/pki/nssdb/pkcs11.txt file to the strict default value of 0600, even if the file had other permissions prior to this change. Consequently, users could not add security modules to their configuration under certain circumstances. NSS now only applies the strict default to new files and preserves existing permissions when replacing an existing pkcs11.txt. Users can make the necessary modifications to the NSS security module database. (BZ#1087926)

* The internal NSS stan_GetCERTCertificate() call did not properly ensure that objects were not removed until the operation was finished. Consequently, stan_GetCERTCertificate() could terminate unexpectedly in the 389 Directory Server (DS) under the replication replay failure condition. The source code has been modified to properly manage object references, and the crashes reported by 389 DS no longer occur. (BZ#1094468)

* The PKCS#12 decoder did not properly check the destination buffer length when decoding. Running the pk12util tool with the "-l" option to list the contents of certain PKCS#12-encoded files resulted in a segmentation fault. The decoder has been updated to perform the check, and pk12util now lists the encoded files as expected. (BZ#1174527)

* A build-time check for platforms without NSS initialization support was missing. The NSS security tools terminated unexpectedly with a core dump when running on the 64-bit PowerPC architecture. The build files now check for the "NSS_NO_INIT_SUPPORT" build-time environment variable, and if it is set, the platforms continue to function as expected. (BZ#1154232)

* The Softoken module did not correctly check the mechanism for user tokens. When both the client and the server worked in FIPS mode, the yum utility could not connect to OpenSSL-based servers, and the server returned the "decryption failed or bad record mac" error message. Softoken has been updated to allow user slots to have the full list of mechanisms just like the main slot, and yum is now able to connect to OpenSSL-based servers. (BZ#1131079)

* Certain changes to the nss-softokn.spec file were implemented using the dracut utility configuration syntax for Red Hat Enterprise Linux 6 instead of the Red Hat Enterprise Linux 7 syntax. Consequently, the user could not use the curl utility to download an HTTPS URL in the dracut environment. The spec file has been modified to use the correct syntax, and dracut users can now use curl in this situation as expected. (BZ#1169957)

In addition, this update adds the following enhancements:

* With this update, the nss-softokn module conforms to the FIPS-140 standard. (BZ#1004102, BZ#1004107)

* This update adds a mechanism that allows to derive a new symmetric key based on the encryption of some data with the original symmetric key. (BZ#1155340)

Users of nss, nss-softokn, nss-util, and nspr are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1545</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150364"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150386" severity="medium">
    <xccdf:title>RHBA-2015:0386: cups bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>CUPS provides a portable printing layer for Linux, UNIX, and similar operating systems. 

This update fixes the following bugs:

* When using the cupsEnumDests() API call, the libcups utility failed to take note of the client callback function. As a consequence, applications using this API could terminate unexpectedly. The cupsEnumDests() implementation has been fixed and callbacks now function as expected. (BZ#1072954) 

* Previously, the CUPS scheduler used an incorrect D-Bus interface when trying to add a colord profile, which led to colord profiles not working correctly. With this update, the correct D-Bus interface is used, and colord profiles now function as expected. (BZ#1087323)

* When handling an incoming Internet Printing Protocol (IPP) request with an associated document to follow, the CUPS scheduler did not check whether the client connection had data available to read before starting to handle the document data. Consequently, in some instances, a 10-second timeout could occur. The scheduler now checks for data availability before reading the document data, thus fixing this bug. (BZ#1110259) 

* When the CUPS scheduler read data from a client, it did not check for data availability in between reading the HTTP headers and the Internet Printing Protocol (IPP) request. This led to a race condition causing client requests to fail depending on the timing of the data packets. With this update, the scheduler checks for data availability, preventing the race condition from occurring. (BZ#1113045) 

* Previously, the manual page for the cupsd.conf(5) configuration file did not mention the ErrorPolicy directive. Text describing this directive has now been added to the manual page. (BZ#1120591) 

* Prior to this update, the cups utility was started before networking, and therefore it was not available in some configurations. A patch has been applied to fix this bug, and CUPS is now available throughout the network. (BZ#1144780) 

* A prior security update changed the /etc/cups/ppd/ directory not to be world-readable. However, the cupsGetPPD() function still assumed the files in the directory were world-readable. As a consequence, cupsGetPPD() returned a symbolic link to a file in /etc/cups/ppd/ to the caller even though the caller was not able to read it, which caused a variety of failures when printing. This update fixes cupsGetPPD3() to check for readability, and these failures thus no longer occur. (BZ#1153708)

* A prior fix for setting the value of the FINAL_CONTENT_TYPE variable caused unintended problems: the back end could not reliably determine the format of the input data and forced FINAL_CONTENT_TYPE to always be "printer/[queue name]". The incorrect fix has been reverted. Nevertheless, users who have files configured on both the local and remote ends of their queues will still encounter this problem, and thus need to make the local ends of their queues "raw". (BZ#1149245)

In addition, this update adds the following enhancement:

* Prior to this update, the commands required by the redhat-lsb-core package were provided by the cups packages, which itself has other requirements on other packages. To prevent redhat-lsb-core causing a larger dependency chain than needed, the CUPS client commands required by redhat-lsb-core have been moved into a new sub-package, cups-clients. (BZ#1115057) 

Users of cups are advised to upgrade to these updated packages, which fix these bugs and add this enhancement. After installing this update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2856</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5031</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150441" severity="low">
    <xccdf:title>RHBA-2015:0441: sssd bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) provides a set of daemons to manage access to remote directories and authentication mechanisms.

This update adds several enhancements that are described in more detail in the Red Hat Enterprise Linux 7.1 Release Notes, linked to in the References section, including:

* Added the "domains=" option to the pam_sss module.
* Added an SSSD plug-in to enable accessing a CIFS share.
(BZ#727466, BZ#922081)

This update fixes the following bugs:

* The sssd-ad(5) man page did not explain that when using multiple types of providers, such as an Active Directory (AD) provider and an LDAP provider, the user must fully configure each of the providers. The man page explains this now. (BZ#1075141)

* The system added the "sss" module to the nsswitch.conf file, even when SSSD was not running. The GNU C Library (glibc) calls returned incorrect error messages, which caused certain user space tools to not work properly. The "sssd_nss" module returns correct error codes, so that the user space tools handle them gracefully. (BZ#1124320)

* The hard-coded list of supported AD servers in SSSD did not include the Windows Server 2012R2 (WS2012R2) release. Clients connected to WS2012R2 printed a warning to the logs and were unable to use some AD-specific performance enhancements. To fix these problems, this update adds WS2012R2 to the list. (BZ#1134940)

* SSSD overwrote a variable containing password expiration data under certain circumstances, and did not sometimes display password expiration messages to the user. This update fixes the problem, and SSSD displays password expiration data as expected. (BZ#1144011)

* Several AD-specific codepaths in the LDAP provider assumed data structures and functions that were available only with a full AD provider. Looking up secondary groups using the LDAP provider failed. This update modifies the codepaths to allow using the "id_provider=ldap" setting with AD servers and disables the support for the tokenGroups attribute when using this configuration. Clients using "id_provider=ldap" with an AD server work seamlessly. (BZ#1146541)

* SSSD sometimes did not map some of the group security identifiers (SIDs) returned from the tokenGroups attribute, unless an SSSD client used the "id_provider=ad" setting. SSSD did not display all groups in the "id" output and could deny access to users. Support for tokenGroups is now disabled if "id_provider=ad" is not used, and SSSD reports the group membership correctly. (BZ#1161741)

* Failed attempts to convert a GID to a group name during certain access control checks, which is required for comparison with the "simple_allow_groups" list, could cause SSSD to incorrectly deny access. SSSD now continues to resolve the next groups when only allow rules are used, and the users can log in even if SSSD cannot perform the conversion for some of their groups. (BZ#1175408)

This update adds the following enhancements:

* The sssd service can now be run as a non-root user. Previously, sssd could only be run as root, which could potentially pose a security risk. To set sssd to run unprivileged, add the "user=sssd" option to the [sssd] section of the sssd.conf file. (BZ#1113783)

* SSSD is able use the group policy objects (GPOs) stored on an AD server for access control. Windows administrators can now use the GPOs to control access to Linux clients. (BZ#1115429)

* A new Kerberos plug-in helps to map Kerberos principals to local SSSD user names. It is no longer necessary to configure the .k5login file or the "auth_to_local" rules in the krb5.conf file to enable passwordless logins to IdM clients for AD users in a setup with AD trusts. (BZ#1135043)

Users of sssd are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0249</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150441"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150584" severity="low">
    <xccdf:title>RHBA-2015:0584: tboot bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tboot packages provide the Trusted Boot (tboot) open source pre-kernel/VMM
module. This module uses Intel Trusted Execution Technology (Intel TXT) to
initialize the launch of operating system kernels and virtual machines.

The tboot packages have been upgraded to upstream version 1.8.2, which provides
a number of bug fixes and enhancements over the previous version. (BZ#1147070)

Users of tboot are advised to upgrade to these updated packages, which fix these
bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5118</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150584"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150925" severity="low">
    <xccdf:title>RHBA-2015:0925: nss and nspr bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. 

The nss packages have been upgraded to upstream version 3.18.0, and the nspr packages have been upgraded to upstream version 4.10.8. The upgraded versions provide a number of bug fixes and enhancements over the previous versions. Notably, these upgrades allow users to upgrade to Mozilla Firefox 38 Extended Support Release. (BZ#1200905, BZ#1200921)

Users of nss, nss-softokn, nss-util, and nspr are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1569</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150925"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150926" severity="low">
    <xccdf:title>RHBA-2015:0926: nss, nss-util, and nspr bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

The nss and nss-util packages have been upgraded to upstream versions 3.18, and the nspr packages have been upgraded to upstream version 4.10.8. The upgraded versions provide a number of bug fixes and enhancements over the previous versions. Notably, these upgrades allow users to upgrade to Mozilla Firefox 38 Extended Support Release. (BZ#1205064, BZ#1205065, BZ#1207052)

This update also fixes the following bugs:

* Previously, a race condition in NSS in some cases caused heavily threaded applications, such as the ns-slapd daemon, to terminate unexpectedly when under load. This update fixes the underlying cause, and the described crash no longer occurs. (BZ#1182902)

* When using version 3.16.1-4 of the nss packages, NSS returned different cipher suites than the prior versions of NSS. This caused certain applications that add external constraints to the cipher suites, such as the Lightweight Directory Access Protocol server (LDAPS), to fail. With this update, the cipher suites table in the /nss/lib/ssl/ssl3con.c file has been adjusted to be compatible with the previous version of NSS, and the affected applications now work as expected. (BZ#1202488)

Users of nss, nss-util, and nspr are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1569</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150926"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20150965" severity="low">
    <xccdf:title>RHBA-2015:0965: nss, nss-util, and nspr bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

The nss and nss-util packages have been upgraded to upstream versions 3.18, and the nspr packages have been upgraded to upstream version 4.10.8. The upgraded versions provide a number of bug fixes and enhancements over the previous versions. Notably, these upgrades allow users to upgrade to Mozilla Firefox 38 Extended Support Release. (BZ#1211371, BZ#1211372, BZ#1211373)

Users of nss, nss-util, and nspr are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:0965</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1569</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20150965"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20151292" severity="low">
    <xccdf:title>RHBA-2015:1292: openldap bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open-source suite of Lightweight Directory Access Protocol (LDAP) applications and development tools. LDAP is a set of protocols used to access and maintain distributed directory information services over an IP network. The openldap packages contain configuration files, libraries, and documentation for OpenLDAP.

The openldap packages have been upgraded to upstream version 2.4.40, which provides a number of bug fixes and enhancements over the previous version. (BZ#1147983)

This update also fixes the following bugs:

* Previously, openldap did not correctly handle when multiple processes attempted to establish an encrypted connection at the same time. Consequently, utilities, such as the nslcd service, could terminate unexpectedly with a segmentation fault. Incorrect thread initialization code that caused this bug has been fixed. As a result, utilities no longer crash when processes establish multiple concurrent encrypted connections. (BZ#1144294)

* Previously, the server could terminate unexpectedly when processing SRV records due to invalid memory access. The error that caused the invalid memory access has been corrected, and the server no longer crashes when processing SRV records. (BZ#1164369)

* Prior to this update, user data was deleted after updating openldap when the slapd.conf file was used to store the configuration, but the slapd.d/ directory also existed. This update fixes incorrect logic in the post-installation script, and user data is no longer deleted in this situation. (BZ#1193519)

* The server sometimes terminated unexpectedly with a segmentation fault on IBM Power Systems due to a regression. A code optimization that caused this problem has been removed, preventing the segmentation fault from occurring. As a result, the server no longer crashes in this situation. (BZ#1202696)

In addition, this update adds the following enhancements:

* This update introduces the Check Password extension for OpenLDAP, required for PCI compliance. (BZ#1155390)

* Support for the TLS protocol version 1.1 and later has been added. (BZ#1160467)

Users of openldap are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:1292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20151292"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20151307" severity="medium">
    <xccdf:title>RHBA-2015:1307: netcf bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The netcf packages contain a library for modifying the network configuration of a system. Network configuration is expressed in a platform-independent XML format, which netcf translates into changes to the system's "native" network configuration files.

This update fixes the following bugs:

* Previously, when the XML configuration for an interface enabled dynamic host configuration protocol (DHCP) for IPv6, the netcf library erroneously set the variable named "DHCPV6" in the ifcfg configuration file instead of "DHCPV6C". The underlying source code has been patched, and netcf now passes the correct "DHCPV6C" option to ifcfg. (BZ#1113978)

* Prior to this update, when requested to configure an interface with an IPv4 netmask of 255.255.255.255, the netcf library logged an error as the
interface configuration was rejected. This update fixes the netmask for the 32-bit interface prefix, and netcf now configures IPv4 interfaces successfully. (BZ#1116314) 

* Due to a parsing error, the ifcfg files with comments starting anywhere beyond column 1 or multiple variables on a single line caused the netcf library to generate errors when attempting to list host interfaces. The parsing error has been fixed, and any tool using netcf now lists active interfaces as expected. (BZ#1208897) 

* When multiple static IPv6 addresses were specified in an interface configuration, an extra set of quotes appeared in the IPV6ADDR_SECONDARIES entry in the generated configuration file. This update removes extraneous single quotes from IPV6ADDR_SECONDARIES, thus fixing this bug. (BZ#1208894)

* Due to a denial of a service flaw in the netcf library, a specially crafted interface name previously caused applications using netcf, such as the libvirt daemon, to terminate unexpectedly. An upstream patch has been applied to fix this bug, and applications using netcf no longer crash in the aforementioned situation. (BZ#1165966) 

Users of netcf are advised to upgrade to these updated packages, which fix these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8119</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20151307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20151445" severity="low">
    <xccdf:title>RHBA-2015:1445: xorg-x11-server bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

This update fixes these bugs:

* The Shift and Caps Lock and Num Lock keys' functionality was reversed when a USB keyboard was unplugged while in Caps Lock or Num Lock mode. Unplugging the keyboard with Caps Lock or Num Lock enabled and later plugging it back in led to incorrect modifier state on the keyboard. Now, the correct modifier state is applied when a keyboard is attached. The discrepancy between the actual and logical status of modifiers no longer occurs. (BZ#963829)

* Connecting to a remote machine of different endianness architecture using the X Display Manager Control Protocol (XDMCP) could cause unexpected termination of the X server when the data length in the XkbSetGeometry request was erroneously swapped twice, and an incorrect value was produced. With this update, the data is swapped only once when appropriate, ensuring the use of correct data length. Connecting to remote machines no longer causes X server crashes in this situation. (BZ#1007006)

* Due to a regression, the "Always" mode of the Xorg server's backing store (-bs) option was not functional, and applications expecting the retention of window content when it was unmapped did not work. The mode has been implemented, and applications that require it now work. (BZ#1138353)

* The keyboard remained in Caps Lock or Num Lock mode even after the keys were pressed again to change input mode. Now, the Caps Lock and Num Lock functions no longer remain active after pressing the keys to deactivate them. (BZ#1161061)

* The Xephyr server's 8-bit pseudocolor emulation incorrectly maintained only one colormap for the entire server. When running Xephyr at 8 bpp with multiple screens, only one screen displayed correct colors. Xephyr has been amended to maintain one colormap per screen and now displays correct colors on all screens. (BZ#1164828)

* The X server package was missing requirements for basic drivers such as vesa, void, or evdev. With this update, installing the X server automatically pulls the basic required drivers as well. (BZ#1171121)

* The fix for CVE-2014-8092 (RHSA-2014:1983) introduced a type conversion invalid in C++, preventing a C++ application, such as TigerVNC, to be compiled using the X server source files. Now, the header file uses an explicit cast for the type conversion, and C++ applications using X server source files can be compiled. (BZ#1177687)

* The string format used in error messages was not supported by the X server. When connecting to an unwilling XDMCP server, an error, a backtrace, and termination of the X server occurred instead of displaying an error message. Now, the X server supports the string format, connecting to an unwilling XDMCP server no longer causes a crash, and an error message is displayed prior to exiting cleanly. (BZ#1184365)

* The X Window System failed to load on reboot when the Xinerama extension and the SELinux module in enforcing mode were enabled. It kept attempting to load the GUI and went on in a loop. Now, the X Window System loads as expected in this situation. (BZ#1199591)

* Passing a request containing zero height to the XPutImage() function could cause a "division by zero" error in the X server. Now, the X server checks the height value and avoids division by zero. The requests no longer cause errors. (BZ#1208094)

Enhancement:

* The xvfb-run script now accepts the "-a" argument to automatically select an unused display number. Users no longer have to choose one themselves, which was difficult and error-prone when running from automated scripts. The Xvfb server can be used for headless automation setups without the need to specify a display number explicitly. (BZ#1049297)

Users of xorg-x11-server are advised to upgrade to these updated packages, which fix these bugs and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:1445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3418</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20151445"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20151465" severity="low">
    <xccdf:title>RHBA-2015:1465: glibc bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.

This update fixes the following bug:

* A race condition in the malloc API family of functions could cause a deadlock leading to gluster NFS and Fuse mounts becoming unresponsive while running large amounts of I/O. The race condition in malloc has been removed and gluster NFS and Fuse mounts no longer hang in the described situation. (BZ#1244002) 

Users of glibc are advised to upgrade to these updated packages, which fix this bug.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:1465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5229</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20151465"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20151554" severity="medium">
    <xccdf:title>RHBA-2015:1554: 389-ds-base bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages include the LDAP server and command-line utilities for server administration. 

This update fixes the following bugs:

* Previously, the code of search requests for asynchronous simple paged
results was not thread-safe, which created a small window during which a conflict could occur in the simple paged result slot. As a consequence, the server could terminate unexpectedly. To fix this bug, the code is now thread-safe, and the crash no longer occurs in this situation. 
In addition, abandoning simple paged results request was previously not handled correctly if an abandon request was issued too quickly. Consequently, an internal search result object was in some cases not released. With this update, the search result request is safely released regardless of the timing of the abandon request. (BZ#1230037)

* Prior to this update, a helper function to check whether the cache size is valid or not was resetting the cash size to a very small value. Consequently, the helper function was applied and the Distinguished Name (DN) cache was applied at the server start-up timing, which reduced the cache size. With this update, the helper function provides only the validity check and no longer resets the cache size. As a result, the entry and DN cache sizes do not get affected by the helper function. (BZ#1230038)

* Previously, when AD users had multiple spaces inside the value of the RDN attribute, synchronizing the entry to the Directory Server failed. The underlying source code has been fixed, and Windows Synchronization (WinSync) plug-in in the Directory Server now works as expected. (BZ#1243718) 

Users of 389-ds-base are advised to upgrade to these updated packages, which fix these bugs. After installing this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:1554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3230</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20151554"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152092" severity="medium">
    <xccdf:title>RHBA-2015:2092: systemd bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelization capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.

This update fixes multiple bugs and adds numerous enhancements. Refer to the following Red Hat Knowledgebase article for information on the most significant of these changes: 

https://access.redhat.com/articles/1611383

Users of systemd are advised to upgrade to these updated packages, which fix these bugs and add these enhancements. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-7796</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152092"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152116" severity="medium">
    <xccdf:title>RHBA-2015:2116: GTK+ bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GTK+ packages contain the GIMP ToolKit (GTK+), a library for creating graphical user interfaces for the X Window System. 

This update contains a number of rebases to the latest upstream stable versions, which provides a number of bug fixes and enhancements over the previous versions. For more information on the changes, see the GNOME release notes and Red Hat Enterprise Linux 7.2 Release Notes.

The orc packages have been upgraded to version 0.4.22. (BZ#1174391)
The atk packages have been upgraded to version 2.14.0. (BZ#1174433)
The cairo packages have been upgraded to version 1.14.2. (BZ#1174435)
The pango packages have been upgraded to version 1.36.8. (BZ#1174436)
The gdk-pixbuf2 packages have been upgraded to version 2.31.1. (BZ#1174438)
The gobject-introspection packages have been upgraded to version 1.42.0. (BZ#1174439)
The glib-networking packages have been upgraded to version 2.42.2. (BZ#1174447)
The dconf packages have been upgraded to version 0.22.0. (BZ#1174448)
The gtksourceview3 packages have been upgraded to version 3.14.2. (BZ#1174500)
The json-glib packages have been upgraded to version 1.0.2. (BZ#1174501)
The webkitgtk3 packages have been upgraded to version 2.4.9. (BZ#1174556)
The glibmm24 packages have been upgraded to version 2.42.0. (BZ#1174565)
The harfbuzz packages have been upgraded to version 0.9.36. (BZ#1201148)
The libxklavier packages have been upgraded to version 5.4. (BZ#1202874)
The glib2 packages have been upgraded to version 2.42.2. (BZ#1203755)
The gtk2 packages have been upgraded to version 2.24.28. (BZ#1221171)

This update also fixes the following bugs:

* Previously, GTK+ was treating frame times from _NET_WM_FRAME_DRAWN and
_NET_WM_FRAME_TIMINGS as local monotonic times, but they are actually
extended-precision versions of the server time. This was causing rendering stalls when using GTK+ applications remotely. With this update, frame times are converted to monotonic times when the X server and client are not running on the same system, and GTK+ applications can be used remotely without rendering stalls. (BZ#1243646) 

* Previously, the glib2 packages were rebased to a version that deprecated the g_memmove() function. As a consequence, libgsf failed to build from source. This update replaces g_memmove() with memmove(), thus fixing this bug. (BZ#1132679)

* Prior to this update, the Python plug-in for GDB did not work with the version of GDB in Red Hat Enterprise Linux 7.1. As a consequence, GDB returned error messages when debugging glib2 applications. This update applies an upstream fix to use newer GDB APIs, and the Python GDB debugging aid for glib2 applications now works as expected. (BZ#1055733)

* The glib2 utility previously returned confusing warning messages when programs added GObject properties after the class was initialized. The functionality of adding a property after the class was initialized has been added back due to backward compatibility concerns, and error messages on properties thus no longer appear. (BZ#1168600)

* When selecting a file in the "Add attachment" window, Evolution previously terminated unexpectedly with a segmentation fault. This update fixes the gtk_tree_row_ref_deleted() function causing this bug, and attaching a file no longer leads to a crash. (BZ#1175941)

* Previously, the CUPS back end checked an incorrect port to connect to remote printers. Consequently, fetching printer information failed and the "Print" button became insensitive. This update makes sure CUPS checks the correct port, thus fixing this bug. (BZ#1221157, BZ#1154038)

Users of GTK+ are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-3190</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152116"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152142" severity="medium">
    <xccdf:title>RHBA-2015:2142: pcre bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library. 

This update fixes the following bugs:

* Previously, non-matched groups within capturing groups up to a forced match were not being properly reset by PCRE, causing the library to incorrectly match some groups. With this update, non-matched groups within capturing groups up to a forced match are being properly marked as non-matching. (BZ#1161597)

* Compiling zero-repeated groups with recursive back references no longer causes PCRE to crash. (BZ#1119356)

* A bug in PCRE was causing it to match the wrong substring in regular expressions with empty-matching possessive zero-repeat groups. This problem has been fixed and matching these groups now behaves as expected. (BZ#1119320)

* PCRE previously did not correctly evaluate regular expressions with literal quotations inside character class. For example, the expression "/[\Qa]\E]+/" was not matching the string "a", although it should. The problem has been fixed and regular expressions with literal quotations inside character class are now being evaluated correctly. (BZ#1111091)

* An error in first character optimization was causing PCRE to incorrectly evaluate regular expressions where a start-anchored character with more than once case follows circumflex in multi-line UTF-8 mode. This update resolves the problem and PCRE now properly evaluates these regular expressions. (BZ#1110621)

* Linking an application to the static PCRE library using the libpcre module for pkg-config was failing due to missing pthread symbols. The pkg-config modules for PCRE libraries have been updated to declare private libraries properly, and the "pkg-config --static --libs libpcre" command can now be used to link the static pcre library to an application. (BZ#1217111)

* The pcredemo.c file, which is described in the pcresample(3) man page as containing code examples for PCRE, was missing from the pcre-devel package. The example file has been added to the pcre-devel package and can now be found in the /usr/share/doc/pcre-devel-8.32/ directory. (BZ#1217118)

Users of pcre are advised to upgrade to these updated packages, which fix these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2327</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152142"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152161" severity="high">
    <xccdf:title>RHBA-2015:2161: libcap-ng bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libcap-ng library is designed to make programming with POSIX capabilities easier. It is shipped with utilities to analyze the POSIX capabilities of all running applications, as well as tools to set the file system-based capabilities.

The libcap-ng packages have been upgraded to upstream version 0.7.5, which provides a number of bug fixes and enhancements over the previous version. (BZ#1185610)

Users of libcap-ng are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2161</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3215</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152161"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152194" severity="medium">
    <xccdf:title>RHBA-2015:2194: httpd bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

This update fixes the following bugs:

* The httpd daemon did not reset an internal array for storing variables defined using the "Define" directive. Consequently, variables could be undefined after a graceful restart. httpd has been fixed to reset this internal array during a graceful restart, and variables are now correctly defined in this scenario. (BZ#1227219)

* The SSL_CLIENT_VERIFY environment variable was incorrectly handled when the "SSLVerifyClient optional_no_ca" and "SSLSessionCache" options were used. Consequently, when an SSL session was resumed, the SSL_CLIENT_VERIFY value was set to "SUCCESS" instead of the previously set "GENEROUS". SSL_CLIENT_VERIFY is now correctly set to GENEROUS in this scenario. (BZ#1170206)

* The mod_ssl module did not call the ERR_free_strings method during its cleanup. Consequently, during the httpd daemon's reload, mod_ssl leaked memory. Now, ERR_free_strings is called by mod_ssl during the httpd reload, and mod_ssl no longer leaks memory. (BZ#1181690)

* The status line of an HTTP response message from a server did not include the HTTP Reason-Phrase if the original response from the mod_proxy back-end server contained only a Status Code. Consequently, the server displayed only the Status Code to an HTTP client. HTTP clients now receive both the Status Code and Reason-Phrase. (BZ#1162159)

* The mod_authz_dbm module requires the mod_authz_owner module but this dependency was not reflected in the mod_authz_dbm code. Consequently, when the "Require dbm-file-group" directive was used and mod_authz_dbm was loaded before mod_authz_owner, the httpd daemon terminated unexpectedly with a segmentation fault. The mod_authz_dbm code now allows loading before the mod_authz_owner module, and httpd no loner crashes in this scenario. (BZ#1221575)

* The mod_proxy_fcgi module had a hardcoded 30-second timeout for a request. Consequently, it was impossible to change the timeout. mod_proxy_fcgi has been fixed to honor the Timeout or ProxyTimeout directives, and users are now able to configure the timeout of mod_proxy_fcgi. (BZ#1222328)

* The mod_ssl method used for enabling Next Protocol Negotiation (NPN) support returned incorrect exit status when NPN was disabled. Consequently, although NPN was disabled by the configuration, mod_ssl continued to send it. The mod_ssl method now returns the correct value in this scenario, and mod_ssl no longer sends NPN unless configured to do so. (BZ#1226015)

The update adds these enhancements:

* The default configuration of the mod_ssl module in the Apache HTTP Server no longer enables support for SSL cipher suites using the single IDEA or SEED encryption algorithms, which are known to be easily exploitable. (BZ#1118476)

* The mod_proxy_wstunnel module is now enabled by default and it includes support for SSL connections in the "wss://" scheme. Additionally, it is possible to use the "ws://" scheme in the "mod_rewrite" directives. This allows for using WebSockets as a target to "mod_rewrite" and enabling WebSockets in the proxy module. (BZ#1180745)

* Apache HTTP Server now supports Microsoft User Principal Name (UPN) in the SSLUserName directive. Users can now authenticate with their Common Access Card (CAC) or certificate with a UPN in it, and have their UPN used as authenticated user information, consumed by both the access control in Apache and using the REMOTE_USER environment variable or a similar mechanism in applications. As a result, users can now set "SSLUserName SSL_CLIENT_SAN_OTHER_msUPN_0" for authentication using UPN. (BZ#1242503)

Users of httpd are advised to upgrade to these updated packages, which fix these bugs and add these enhancements. After installing the updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2020-11985</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152194"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152197" severity="medium">
    <xccdf:title>RHBA-2015:2197: libreoffice bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.

The libreoffice packages have been upgraded to upstream version 4.3.7.2, which provides a number of bug fixes and enhancements over the previous version, most notably:

* The possibility to print comments in page margin has been added.

* Support for nested comments has been added.

* OpenXML interoperability has been improved.

* Accessibility support has been improved.

* The color picker has been improved.

* The start center has been improved.

* Initial HiDPI support has been added.

* The limitation on number of characters in a paragraph has been raised significantly.

(BZ#1205091)

For a complete list of bug fixes and enhancements provided by this upgrade, follow the link to the LibreOffice change log in the References section. 

Users of libreoffice are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1774</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152258" severity="medium">
    <xccdf:title>RHBA-2015:2258: samba bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and other information.

The samba packages have been upgraded to upstream version 4.2.3, which provides a number of bug fixes and enhancements over the previous version.
Most notably, the "wbinfo -u" and "wbinfo -g" commands now only enumerate the users in their own domain by default. To enumerate all users on all trusted domains, run the "wbinfo --domain='*' -u" or "wbinfo --domain='*' -g" command.
(BZ#1196140)

This update also fixes the following bugs:

* Accessing a printer published in Active Directory (AD) failed with error messages. Now, if Samba fails to find the printer in the Samba registry, it obtains the globally unique identifier (GUID) of the printer from AD and stores it in the registry. The printers work as expected. (BZ#1167325)

* When running Samba without the winbindd service, authentication with user name and password sometimes failed. Now, it is possible to run Samba without winbindd, although it is not recommended. (BZ#1202347)

* In long-running SMB sessions, re-authenticating sometimes caused the SMB server to terminate unexpectedly. Now, the server no longer crashes during the SMB session setup. Users can re-authenticate and then use the SMB file server as expected. (BZ#1223981)

* The windbindd service terminated unexpectedly with a segmentation fault when the alternative domain name was not defined and Winbind was offline. This update defines the values for the alternative domain name as well as certain other settings that were previously not set. Windbind now works as expected in offline mode. (BZ#1225719)

* Samba displayed the STATUS_ACCES_DENIED message when the client tried to reconnect after the session expired because of an invalid signing check. Samba now correctly verifies whether signing is required in this situation. Samba no longer displays the message, and the user is allowed to reconnect. (BZ#1228809)

* The dfree utility sometimes reported an incorrect amount of free space on a Samba share. Now, the smbd service no longer ignores the block size of dfree, thus fixing the calculation of available space. The dfree utility correctly reports the available space on a Samba share. (BZ#1238194)

* The "net ads keytab create" command sometimes terminated unexpectedly with a segmentation fault. Samba has been modified to initialize certain internal structures and free the cursor iterating the keytab. Now, "net ads keytab" no longer crashes. (BZ#1246166)

* The users were sometimes unable to access a Samba share that specified identical values for the force user and force group when the "winbind use default domain = yes" setting was used. With this update, the users can access a Samba share in the described situation as expected. (BZ#1253193)

* When the "map to guest = bad uid" setting was used, the user was sometimes denied permission to access a share as a guest user. Samba now handles "map to guest = bad uid" as expected, allowing users to access shares as guest users if they are not authenticated. (BZ#1255322)

* The Samba files server terminated unexpectedly when the "mangling method = hash" setting was used in the smb.conf file. Samba now fully initializes the hash module, preventing the file server from accessing invalid data structures, and no longer crashes in this situation. (BZ#1255326)

* When the user shared an XFS file system with disk quota, Samba displayed incorrect volume size on the client. With this update, Samba correctly displays the disk quota value as the volume size. (BZ#1258293)

Users of samba are advised to upgrade to these updated packages, which fix these bugs and add these enhancements. After installing this update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7540</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152258"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152287" severity="medium">
    <xccdf:title>RHBA-2015:2287: setroubleshoot bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The setroubleshoot packages contain a set of analysis plug-ins for use with the setroubleshoot utility. Each plug-in has the capacity to analyze SELinux Access Vector Cache (AVC) data, as well as system data, to provide user-friendly reports that describe how to interpret SELinux AVC denial messages.

The setroubleshoot packages have been upgraded to upstream version 3.2.24, which provides a number of bug fixes and enhancements over the previous version. Notably, setroubleshoot now runs under the setroubleshoot user instead of the root user. (BZ#1212422)

In addition, this update adds the following enhancement:

* With this update, Bugzilla bug reports generated by the setroubleshoot utility include a version of the selinux-policy package. (BZ#1163346)

Users of setroubleshoot are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-4445</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152287"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152395" severity="high">
    <xccdf:title>RHBA-2015:2395: redhat-upgrade-tool bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Red Hat Upgrade Tool is used for performing an in-place upgrade of the current system to the next major version of Red Hat Enterprise Linux. It determines what packages are needed for the upgrade and gathers them from the source or sources given. It also fetches and sets up the boot images needed to run the upgrade and sets up the system to perform the upgrade on the next system boot. Running the Red Hat Upgrade Tool requires running the Preupgrade Assistant as a prerequisite.

Users of redhat-upgrade-tool are advised to upgrade to this updated package, which fixes one bug.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3585</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152395"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152424" severity="medium">
    <xccdf:title>RHBA-2015:2424: sudo bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.

This update fixes the following bug:

* Previously, the umask_override entry in the sudoers(5) manual page also, incorrectly, contained information on the use_pty flag. With this update, information on the umask_override and usy_pty flags are in separate entries as expected. (BZ#1233607)

In addition, this update adds the following enhancement:

* The configuration of the sudo utility can now store the checksum of a command or script that is being permitted. When the command or script is run again, the checksum is compared to the stored checksum to verify that nothing has changed. If the command or binary is modified, the sudo utility refuses to run the command or logs a warning. This functionality makes it possible to correctly devolve responsibility and problem-solving activities if an incident occurs. (BZ#1183818)

Users of sudo are advised to upgrade to these updated packages, which fix these bugs and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9680</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152424"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20152457" severity="medium">
    <xccdf:title>RHBA-2015:2457: icedtea-web bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an implementation of Java Web Start, which is based on the netX project. It also contains a configuration tool for managing deployment settings for the plug-in and Web Start implementations. IcedTea-Web now also contains PolicyEditor - a simple tool to configure Java policies.

The icedtea-web packages have been upgraded to upstream version 1.6.1, which provides a number of bug fixes and enhancements over the previous version. Notable changes include the following:

* The IcedTea-Web documentation and man pages have been significantly expanded.
* IcedTea-Web now supports bash completion.
* The "Custom Policies" and "Run in Sandbox" features have been enhanced.
* An -html switch has been implemented for the Java Web Start (JavaWS) framework, which can serve as a replacement of the AppletViewer program.
* It is now possible to use IcedTea-Web to crate desktop and menu launchers for applets and JavaWS applications.

(BZ#1217153)

Users of icedtea-web are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2015:2457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20152457"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20162206" severity="medium">
    <xccdf:title>RHBA-2016:2206: evolution-data-server bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The evolution-data-server packages provide a unified back end for applications which interact with contacts, tasks and calendar information. Evolution Data Server was originally developed as a back end for the Evolution information management application, but is now used by various other applications.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

Users of evolution-data-server are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2016:2206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-10727</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20162206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20170651" severity="medium">
    <xccdf:title>RHBA-2017:0651: bind bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.

Users of bind are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:0651</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-2775</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20170651"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20171767" severity="medium">
    <xccdf:title>RHBA-2017:1767: bind bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.

Users of bind are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:1767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-2775</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20171767"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20171929" severity="medium">
    <xccdf:title>RHBA-2017:1929: openssl bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.

Users of openssl are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:1929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-7056</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20171929"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20171991" severity="low">
    <xccdf:title>RHBA-2017:1991: libtirpc bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtirpc packages contain SunLib's implementation of transport-independent remote procedure call (TI-RPC) documentation, which includes a library required by programs in the nfs-utils and rpcbind packages.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.

Users of libtirpc are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:1991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-14622</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20171991"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20172100" severity="medium">
    <xccdf:title>RHBA-2017:2100: GTK+ bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GTK+ packages contain the GIMP ToolKit (GTK+), a library for creating graphical user interfaces for the X Window System. 

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.

Users of GTK+ are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:2100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20172100"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20172117" severity="low">
    <xccdf:title>RHBA-2017:2117: dnsmasq bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.

Users of dnsmasq are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2017:2117</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-14513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20172117"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20180042" severity="high">
    <xccdf:title>RHBA-2018:0042: dracut bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.

This update fixes the following bug:

* Microcode on AMD family 16h processors was not updated early in the boot process. With this bug fix, the issue is addressed. (BZ#1526943)

Users of dracut are advised to upgrade to these updated packages, which fix this bug.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2018:0042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-5715</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20180042"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20183207" severity="medium">
    <xccdf:title>RHBA-2018:3207: NetworkManager bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.

Users of NetworkManager are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2018:3207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-1000135</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20183207"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20191992" severity="medium">
    <xccdf:title>RHBA-2019:1992: cloud-init bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cloud-init packages provide a set of init scripts for cloud instances. Cloud instances need special scripts to run during initialization to retrieve and install SSH keys, and to let the user run various scripts.

Users of cloud-init are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:1992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-0816</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20191992"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20192044" severity="low">
    <xccdf:title>RHBA-2019:2044: gnome bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNOME is the default desktop environment of Red Hat Enterprise Linux.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Users of gnome are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:2044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-5818</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-5819</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20192044"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20192261" severity="medium">
    <xccdf:title>RHBA-2019:2261: webkitgtk4 bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>WebKitGTK+ is a full-featured port of the WebKit portable web rendering engine to the GTK+ platform. These packages provide WebKitGTK+ for GTK+ 3.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Users of webkitgtk4 are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:2261</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-7285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-7292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8523</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20192261"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20192339" severity="low">
    <xccdf:title>RHBA-2019:2339: lldpad bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The lldpad packages provide the Linux user space daemon and configuration tool for Intel's Link Layer Discovery Protocol (LLDP) Agent with Enhanced Ethernet support.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Users of lldpad are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:2339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-10932</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20192339"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20192599" severity="medium">
    <xccdf:title>RHBA-2019:2599: krb5 bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system, which can improve the security of your network by eliminating the insecure practice of sending passwords over the network in unencrypted form. It allows clients and servers to authenticate to each other with the help of a trusted third party, the Kerberos key distribution center (KDC).

This update fixes the following bug:

* KDC and keytab can disagree on kvno after update (BZ#1732743)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:2599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-20217</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20192599"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20193384" severity="medium">
    <xccdf:title>RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:3384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8320</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8325</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20193384"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20193408" severity="low">
    <xccdf:title>RHBA-2019:3408: openjpeg2 bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:3408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-6616</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20193408"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20193416" severity="medium">
    <xccdf:title>RHBA-2019:3416: pki-core:10.6 and pki-deps:10:6 bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:3416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-12086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-12814</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20193416"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20193621" severity="medium">
    <xccdf:title>RHBA-2019:3621: libidn2 bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:3621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-18224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20193621"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20193674" severity="low">
    <xccdf:title>RHBA-2019:3674: openldap bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:3674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2020-15719</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20193674"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20194268" severity="high">
    <xccdf:title>RHBA-2019:4268: idm:DL1 bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Bug Fix(es):

* IPA upgrade fails for latest ipa package when adtrust is installed (BZ#1773516)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2019:4268</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-10195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-14867</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20194268"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20201376" severity="medium">
    <xccdf:title>RHBA-2020:1376: net-snmp bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

Bug Fix(es) and Enhancement(s):

* net-snmpd double free or corruption error (BZ#1802055)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2020:1376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20892</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20201376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20201628" severity="low">
    <xccdf:title>RHBA-2020:1628: pcp bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.2 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2020:1628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-3695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-3696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20201628"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20203527" severity="medium">
    <xccdf:title>RHBA-2020:3527: kernel-rt bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

This update fixes the following bug:

* kernel-rt: update to the latest RHEL7.8.z source tree (BZ#1868505)

The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2020:3527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-5108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20203527"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20210621" severity="medium">
    <xccdf:title>RHBA-2021:0621: microcode_ctl bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The microcode_ctl packages provide microcode updates for Intel and AMD
processors.

Bug Fix(es) and Enhancement(s):

* [rhel-8.3.0.z] [HPEMC 8.3.z REGRESSION] Regression in intel microcode as
of 20201110 (BZ#1907898)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2021:0621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2020-8696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20210621"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20210623" severity="medium">
    <xccdf:title>RHBA-2021:0623: microcode_ctl bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The microcode_ctl packages provide microcode updates for Intel and AMD
processors.

Bug Fix(es) and Enhancement(s):

* [HPEMC 7.9 REGRESSION]  Microcode_ctl  microcode_ctl (BZ#1905111)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2021:0623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2020-8696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20210623"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20213054" severity="medium">
    <xccdf:title>RHBA-2021:3054: opencryptoki bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The opencryptoki packages contain version 2.11 of the PKCS#11 API,
implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards.
These packages includes support for the IBM 4758 Cryptographic CoProcessor
(with the PKCS#11 firmware loaded), the IBM eServer Cryptographic
Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC
0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic
Function (FC 3863 on IBM System z). The opencryptoki packages also bring a
software token implementation that can be used without any cryptographic
hardware. These packages contain the Slot Daemon (pkcsslotd) and general
utilities.

Bug Fix(es) and Enhancement(s):

* RHEL8.5 - openCryptoki: Soft token does not check if an EC key is valid
(BZ#1979173)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2021:3054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-3798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20213054"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20214438" severity="low">
    <xccdf:title>RHBA-2021:4438: samba bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.5 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2021:4438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-43566</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20214438"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20220348" severity="medium">
    <xccdf:title>RHBA-2022:0348: container-tools:3.0 security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2022:0348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-20291</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20220348"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20221386" severity="medium">
    <xccdf:title>RHBA-2022:1386: .NET Core 3.1 on RHEL 8 bugfix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

Bug Fix(es) and Enhancement(s):

* Update .NET Core 3.1 to SDK 3.1.418 and Runtime 3.1.24 [None8.5.0.z] (BZ#2073450)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2022:1386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2022-0613</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20221386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20222065" severity="medium">
    <xccdf:title>RHBA-2022:2065: libtirpc bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2022:2065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-46828</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20222065"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20225747" severity="medium">
    <xccdf:title>RHBA-2022:5747: .NET 6.0 bugfix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>.NET Core is a managed-software framework. It implements a subset of the .NET
framework APIs and several new APIs, and it includes a CLR implementation.

Bug Fix(es) and Enhancement(s):

* Update .NET 6.0 to SDK 6.0.107 and Runtime 6.0.7 [rhel-8.6.0.z] (BZ#2105397)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2022:5747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2022-1650</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20225747"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhba-def-20225749" severity="medium">
    <xccdf:title>RHBA-2022:5749: .NET 6.0 bugfix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>.NET Core is a managed-software framework. It implements a subset of the .NET
framework APIs and several new APIs, and it includes a CLR implementation.

Bug Fix(es) and Enhancement(s):

* Update .NET 6.0 to SDK 6.0.107 and Runtime 6.0.7 [rhel-9.0.0.z] (BZ#2105398)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHBA-2022:5749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2022-1650</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhba:def:20225749"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20100272" severity="low">
    <xccdf:title>RHEA-2010:0272: valgrind bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Valgrind is a tool to help you find memory-management problems in your
programs. When a program is run under Valgrind's supervision, all reads and
writes of memory are checked, and calls to malloc/new/free/delete are
intercepted. As a result, Valgrind can detect a lot of problems that are
otherwise very hard to find/diagnose.

This update re-bases Valgrind to upstream version 3.5.0 (BZ#522330), and
applies several enhancements and fixes including the following:

* Valgrind now supports cmpxchg instructions. This allows Valgrind to
profile code that uses the Intel cmpxchg instruction. (BZ#476271)

* The rebase also adds emulation for the 0x67 address-size-override prefix
and support for multiple 0x66 operand size prefixes. This prevents
unexpected "unhandled instruction bytes" errors when using Valgrind to
profile programs that use these prefixes. (BZ#515768 and BZ#530165)

All Valgrind users should apply this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2010:0272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4865</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20100272"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20110039" severity="low">
    <xccdf:title>RHEA-2011:0039: subversion enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.

These updated subversion packages add the following enhancements:

* The Subversion package has been upgraded to version 1.6.11 and supports now merge tracking and interactive conflict resolution. (BZ#497036, BZ#488810)

* A SysV init script for the svnserve command is now available. (BZ#564073)

Users of subversion are advised to upgrade to these updated packages, which add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2011:0039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2448</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20110039"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20150369" severity="medium">
    <xccdf:title>RHEA-2015:0369: elfutils bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The elfutils packages contain a number of utility programs and libraries related to the creation and maintenance of executable code.

The elfutils packages have been upgraded to upstream version 0.160, which
provides a number of bug fixes and enhancements over the previous version. The
most notable enhancements are as follows:

* Support for ELFv2 application binary interface on the little-endian variant of IBM Power Systems has been added to elfutils.
* Support for unwinding on ARM 64-bit architecture has been added to elfutils.
* Support for DWZ multifiles in elfutils is now enabled by default and no longer experimental.
* A new option, "-F", "--force", has been added to the eu-unstrip utility for
combining files with nonmatching ELF headers.
* The eu-stack utility is now able to display DWARF debuginfo function names for frames and can use DWARF debuginfo to show inlined functions and frames.
* Several new functions have been added to the libdw library.
(BZ#1109245)

Users of elfutils are advised to upgrade to these updated packages, which fix
these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2015:0369</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0172</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20150369"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20151302" severity="low">
    <xccdf:title>RHEA-2015:1302: elfutils bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The elfutils packages contain a number of utility programs and libraries related to the creation and maintenance of executable code.

The elfutils packages have been upgraded to upstream version 0.161, which provides a number of bug fixes and enhancements over the previous version. The most notable new features are:

* The eu-stack utility supports showing inlined frames and it is now able to produce backtraces even for processes that might have some of their on-disk libraries updated or deleted. 

* Improved DWZ compressed DWARF multi-file support with new functions, "dwarf_getalt" and "dwarf_setalt", has been introduced.

* Support for ARM 64-bit architecture and Red Hat Enterprise Linux for POWER, little endian has been added. 

* The libdw library now supports LZMA-compressed (.ko.xz) kernel modules. 

* Support for ".debug_macro" has been added; new functions has been introduced: "dwarf_getmacros_off", "dwarf_macro_getsrcfiles", "dwarf_macro_getparamcnt", and "dwarf_macro_param". 

* New GNU extensions to the DWARF format are now recognized.

* New functions have been added to the libdw library: "dwarf_peel_type", "dwarf_cu_getdwarf", "dwarf_cu_die", "dwelf_elf_gnu_debuglink", "dwelf_dwarf_gnu_debugaltlink", "dwelf_elf_gnu_build_id".

(BZ#1167724)

Users of elfutils are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2015:1302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20151302"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20152126" severity="low">
    <xccdf:title>RHEA-2015:2126: elfutils bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The elfutils packages contain a number of utility programs and libraries related to the creation and maintenance of executable code.

The elfutils packages have been upgraded to upstream version 0.163, which provides a number of bug fixes and enhancements over the previous version. Notably:

* Previously, elfutils libraries and tools could crash on malformed ELF files or incorrect DWARF data. All known ways to crash the libraries and tools on such incorrect input data have been fixed. 

* The following changes and improvements have been made to the eu-addr2line tool:
- Input addresses are now always interpreted as hexadecimal numbers, never as octal or decimal numbers. 
- A new option, "-a", "--addresses", to print address before each entry. 
- A new option, "-C", "--demangle", to show demangled symbols. 
- A new option, "--pretty-print", to print all information on one line.
As a result, it is possible to use eu-addr2line as a drop-in replacement for binutils addr2line.

* This update introduces the following improvements to the libdw library:
- A new header file elfutils/known-dwarf.h.
- The preliminary DWARF5 constants "DW_AT_noreturn", "DW_LANG_C11", "DW_LANG_C_plus_plus_11", "DW_LANG_C_plus_plus_14", "DW_TAG_atomic_type", "DW_LANG_Fortran03", and "DW_LANG_Fortran08", plus the GNU extension "DW_AT_GNU_deleted" have been added to the elfutils/dwarf.h file.
- A new function, dwarf_peel_type(), for handling qualified types.
- The dwarf_getmacros function now serves both the .debug_macro and .debug_macinfo section data transparently.
- New interfaces, "dwarf_getmacros_off", "dwarf_macro_getsrcfiles", "dwarf_macro_getparamcnt", and "dwarf_macro_param", are available for more generalized inspection of macros and their parameters.

(BZ#1224169, BZ#1223462)

Users of elfutils are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2015:2126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20152126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20180705" severity="medium">
    <xccdf:title>RHEA-2018:0705: tcpdump bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tcpdump packages contain the tcpdump utility for monitoring network traffic. The tcpdump utility can capture and display the packet headers on a particular network interface or on all interfaces.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.5 Release Notes linked from the References section.

Users of tcpdump are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2018:0705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-11108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-11541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-11542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-11543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-11544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12894</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12895</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12897</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12899</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12900</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12901</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12985</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12987</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12989</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12993</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-12999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13032</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13034</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13035</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13036</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13037</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13041</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13043</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13046</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13047</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13048</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13050</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-13725</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20180705"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20192270" severity="low">
    <xccdf:title>RHEA-2019:2270: openjpeg2 bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenJPEG is an open-source JPEG 2000 library.

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Users of openjpeg2 are advised to upgrade to these updated packages.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:2270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-6616</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20192270"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20193280" severity="medium">
    <xccdf:title>RHEA-2019:3280: nss, nss-softokn, nss-util and nspr bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications.
Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

The nss, nss-softokn and nss-util packages have been upgraded to upstream versions 3.44, and the nspr packages have been upgraded to upstream version 4.21. The upgraded versions provide a number of bug fixes and enhancements over the previous versions. Notably, these upgrades allow users to upgrade to Mozilla Firefox 68 Extended Support Release. (BZ#1684609, BZ#1743623, BZ#1743625, BZ#1743628)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:3280</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-17007</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20193280"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20193845" severity="high">
    <xccdf:title>RHEA-2019:3845: microcode_ctl bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The microcode_ctl packages provide microcode updates for Intel x86 processors.

With this update, the Intel microcode version has been updated to microcode-20191112.

Users of microcode_ctl are advised to upgrade to these updated packages, which add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:3845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-0117</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20193845"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20193846" severity="high">
    <xccdf:title>RHEA-2019:3846: microcode_ctl bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The microcode_ctl packages provide microcode updates for Intel x86 processors.

This update adds the following enhancement:

* Update Intel microcode version to microcode-20191112 (BZ#1769889)

Users of microcode_ctl are advised to upgrade to these updated packages, which
add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:3846</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-0117</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20193846"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20193847" severity="high">
    <xccdf:title>RHEA-2019:3847: microcode_ctl bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The microcode_ctl packages provide microcode updates for Intel x86 processors.

This update adds the following enhancement:

* Update Intel microcode version to microcode-20191112 (BZ#1755017)

Users of microcode_ctl are advised to upgrade to these updated packages, which
add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:3847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-0117</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20193847"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20194262" severity="medium">
    <xccdf:title>RHEA-2019:4262: webkit2gtk3 enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>This update adds the following enhancement:

* Update WebKitGTK to 2.24.4 (BZ#1755824).

Users of webkit2gtk3 are advised to upgrade to this updated package, which adds this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2019:4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8644</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8649</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8684</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8719</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8763</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8765</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-8822</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20194262"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20200330" severity="low">
    <xccdf:title>RHEA-2020:0330: nodejs:12 enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The following packages have been upgraded to a later upstream version: nodejs (12.14.1). (BZ#1791067)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2020:0330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-16775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-16776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-16777</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20200330"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20200343" severity="medium">
    <xccdf:title>RHEA-2020:0343: libpq bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2020:0343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-10164</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20200343"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20204505" severity="medium">
    <xccdf:title>RHEA-2020:4505: python-rtslib bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.3 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2020:4505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2020-14019</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20204505"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20211580" severity="medium">
    <xccdf:title>RHEA-2021:1580: libarchive bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2021:1580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-14166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-14501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2017-14502</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20211580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20211906" severity="medium">
    <xccdf:title>RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2021:1906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20394</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20396</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-20398</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20211906"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhea-def-20225139" severity="medium">
    <xccdf:title>RHEA-2022:5139: nodejs:12 bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Node.js is a software development platform for building fast and scalable
network applications in the JavaScript programming language.

Bug Fix(es) and Enhancement(s):

* nodejs:12/nodejs: rebase to last upstream release (BZ#2084651)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHEA-2022:5139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-22959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-22960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-37701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-37712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-3918</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-44531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-44532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2021-44533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2022-21824</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhea:def:20225139"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060016" severity="medium">
    <xccdf:title>RHSA-2006:0016: initscripts security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The initscripts package contains the basic system scripts used to boot
your Red Hat system, change runlevels, and shut the system down cleanly.
Initscripts also contains the scripts that activate and deactivate most
network interfaces.

A bug was found in the way initscripts handled various environment
variables when the /sbin/service command is run. It is possible for a local
user with permissions to execute /sbin/service via sudo to execute
arbitrary commands as the 'root' user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) assigned the name CVE-2005-3629 to
this issue.

The following issues have also been fixed in this update:

* extraneous characters were logged on bootup

* fsck was attempted on file systems marked with _netdev in rc.sysinit
  before they were available

* the dynamically-linked /sbin/multipath was called instead of the correct
  /sbin/multiplath.static

Additionally, this update includes support for partitioned multipath
devices and a technology preview of static IP over InifiniBand.

All users of initscripts should upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3629</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060044" severity="low">
    <xccdf:title>RHSA-2006:0044: openssh security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

An arbitrary command execution flaw was discovered in the way scp copies
files locally. It is possible for a local attacker to create a file with a
carefully crafted name that could execute arbitrary commands as the user
running scp to copy files locally. The Common Vulnerabilities and Exposures
project (cve.mitre.org) assigned the name CVE-2006-0225 to this issue. 

The following issue has also been fixed in this update:

* If the sshd service was stopped using the sshd init script while the
  main sshd daemon was not running, the init script would kill other sshd
  processes, such as the running sessions.  For example, this could happen
  when the 'service sshd stop' command was issued twice.

Additionally, this update implements auditing of user logins through the
system audit service.

All users of openssh should upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0225</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060044"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060052" severity="medium">
    <xccdf:title>RHSA-2006:0052: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A denial of service flaw was found in the way squid processes certain NTLM
authentication requests. It is possible for a remote attacker to crash the
Squid server by sending a specially crafted NTLM authentication request.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CVE-2005-2917 to this issue.

The following issues have also been fixed in this update: 

* An error introduced in squid-2.5.STABLE6-3.4E.12 can crash Squid when a
  user visits a site that has a bit longer DNS record.

* An error introduced in the old package prevented Squid from returning
  correct information about large file systems. The new package is compiled
  with the IDENT lookup support so that users who want to use it do not
  have to recompile it.

* Some authentication helpers needed SETUID rights but did not have them.
  If administrators wanted to use cache administrator, they had to change
  the SETUID bit manually. The updated package sets this bit so the new
  package can be updated without manual intervention from administrators.

* Squid could not handle a reply from an HTTP server when the reply began
  with the new-line character. 

* An issue was discovered when a reply from an HTTP server was not
  HTTP 1.0 or 1.1 compliant.

* The updated package keeps user-defined error pages when the package
  is updated and it adds new ones.
 
All users of squid should upgrade to this updated package, which resolves
these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2917</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060052"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060101" severity="high">
    <xccdf:title>RHSA-2006:0101: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues
described below:

- a flaw in network IGMP processing that a allowed a remote user on the
local network to cause a denial of service (disabling of multicast reports)
if the system is running multicast applications (CVE-2002-2185, moderate)

- a flaw which allowed a local user to write to firmware on read-only
opened /dev/cdrom devices (CVE-2004-1190, moderate) 

- a flaw in gzip/zlib handling internal to the kernel that may allow a
local user to cause a denial of service (crash) (CVE-2005-2458, low) 

- a flaw in procfs handling during unloading of modules that allowed a
local user to cause a denial of service or potentially gain privileges
(CVE-2005-2709, moderate)

- a flaw in the SCSI procfs interface that allowed a local user to cause a
denial of service (crash) (CVE-2005-2800, moderate)

- a flaw in 32-bit-compat handling of the TIOCGDEV ioctl that allowed
a local user to cause a denial of service (crash) (CVE-2005-3044, important)

- a race condition when threads share memory mapping that allowed local
users to cause a denial of service (deadlock) (CVE-2005-3106, important)

- a flaw when trying to mount a non-hfsplus filesystem using hfsplus that
allowed local users to cause a denial of service (crash) (CVE-2005-3109,
moderate)

- a minor info leak with the get_thread_area() syscall that allowed
a local user to view uninitialized kernel stack data (CVE-2005-3276, low) 

- a flaw in mq_open system call that allowed a local user to cause a denial
of service (crash) (CVE-2005-3356, important)

- a flaw in set_mempolicy that allowed a local user on some 64-bit
architectures to cause a denial of service (crash) (CVE-2005-3358, important)

- a flaw in the auto-reap of child processes that allowed a local user to
cause a denial of service (crash) (CVE-2005-3784, important)

- a flaw in the IPv6 flowlabel code that allowed a local user to cause a
denial of service (crash) (CVE-2005-3806, important)

- a flaw in network ICMP processing that allowed a local user to cause
a denial of service (memory exhaustion) (CVE-2005-3848, important)

- a flaw in file lease time-out handling that allowed a local user to cause
a denial of service (log file overflow) (CVE-2005-3857, moderate) 

- a flaw in network IPv6 xfrm handling that allowed a local user to
cause a denial of service (memory exhaustion) (CVE-2005-3858, important) 

- a flaw in procfs handling that allowed a local user to read kernel memory
(CVE-2005-4605, important)

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2002-2185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-1190</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3106</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3109</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3276</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3356</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3358</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3857</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4605</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060101"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060129" severity="medium">
    <xccdf:title>RHSA-2006:0129: spamassassin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug was found in SpamAssassin.  An attacker could
construct a message in such a way that would cause SpamAssassin to crash. 
If a number of these messages are sent, it could lead to a denial of
service, potentially preventing the delivery or filtering of email. The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CVE-2005-3351 to this issue.

The following issues have also been fixed in this update:

* service spamassassin restart sometimes fails
* Content Boundary "--" throws off message parser
* sa-learn: massive memory usage on large messages
* High memory usage with many newlines
* service spamassassin messages not translated
* Numerous other bug fixes that improve spam filter accuracy and safety

Users of SpamAssassin should upgrade to this updated package containing
version 3.0.5, which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0129</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3351</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060129"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060132" severity="medium">
    <xccdf:title>RHSA-2006:0132: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 3 (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

This is the third regular kernel update to Red Hat Enterprise Linux 4.

New features introduced in this update include:

- Open InfiniBand (OpenIB) support

- Serial Attached SCSI support

- NFS access control lists, asynchronous I/O

- IA64 multi-core support and sgi updates 

- Large SMP CPU limits increased using the largesmp kernel: Up to 512 CPUs
  in ia64, 128 in ppc64, and 64 in AMD64 and Intel EM64T

- Improved read-ahead performance

- Common Internet File System (CIFS) update

- Error Detection and Correction (EDAC) modules

- Unisys support

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4. 

The following security bug was fixed in this update:

- dm-crypt did not clear a structure before freeing it, which could allow
local users to discover information about cryptographic keys (CVE-2006-0095)

The following device drivers have been upgraded to new versions:

cciss: 2.6.8 to 2.6.8-rh1
ipmi_devintf: 33.4 to 33.11
ipmi_msghandler: 33.4 to 33.11
ipmi_poweroff: 33.4 to 33.11
ipmi_si: 33.4 to 33.11
ipmi_watchdog: 33.4 to 33.11
mptbase: 3.02.18 to 3.02.60.01rh
e1000: 6.0.54-k2-NAPI to 6.1.16-k2-NAPI
ixgb: 1.0.95-k2-NAPI to 1.0.100-k2-NAPI
tg3: 3.27-rh to 3.43-rh
aacraid: 1.1.2-lk2 to 1.1-5[2412]
ahci: 1.01 to 1.2
ata_piix: 1.03 to 1.05
iscsi_sfnet: 4:0.1.11-1 to 4:0.1.11-2
libata: 1.11 to 1.20
qla2100: 8.01.00b5-rh2 to 8.01.02-d3
qla2200: 8.01.00b5-rh2 to 8.01.02-d3
qla2300: 8.01.00b5-rh2 to 8.01.02-d3
qla2322: 8.01.00b5-rh2 to 8.01.02-d3
qla2xxx: 8.01.00b5-rh2 to 8.01.02-d3
qla6312: 8.01.00b5-rh2 to 8.01.02-d3
sata_nv: 0.6 to 0.8
sata_promise: 1.01 to 1.03
sata_svw: 1.06 to 1.07
sata_sx4: 0.7 to 0.8
sata_vsc: 1.0 to 1.1
cifs: 1.20 to 1.34

Added drivers:

bnx2: 1.4.25
dell_rbu: 0.7
hangcheck-timer: 0.9.0
ib_mthca: 0.06
megaraid_sas: 00.00.02.00
qla2400: 8.01.02-d3
typhoon: 1.5.7

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0095</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060159" severity="medium">
    <xccdf:title>RHSA-2006:0159: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular and freely-available Web server.

A memory leak in the worker MPM could allow remote attackers to cause a
denial of service (memory consumption) via aborted connections, which
prevents the memory for the transaction pool from being reused for other
connections.  The Common Vulnerabilities and Exposures project assigned the
name CVE-2005-2970 to this issue.  This vulnerability only affects users
who are using the non-default worker MPM.

A flaw in mod_imap when using the Referer directive with image maps was
discovered.  With certain site configurations, a remote attacker could
perform a cross-site scripting attack if a victim can be forced to visit a
malicious URL using certain web browsers.  (CVE-2005-3352)

A NULL pointer dereference flaw in mod_ssl was discovered affecting server
configurations where an SSL virtual host is configured with access control
and a custom 400 error document.  A remote attacker could send a carefully
crafted request to trigger this issue which would lead to a crash.  This
crash would only be a denial of service if using the non-default worker
MPM.  (CVE-2005-3357)

Users of httpd should update to these erratum packages which contain
backported patches to correct these issues along with some additional bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3357</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060159"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060160" severity="medium">
    <xccdf:title>RHSA-2006:0160: tetex security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input and creates a typesetter-independent .dvi
(DeVice Independent) file as output.

Several flaws were discovered in the teTeX PDF parsing library. An attacker
could construct a carefully crafted PDF file that could cause teTeX to
crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3191,
CVE-2005-3192, CVE-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626,
CVE-2005-3627 and CVE-2005-3628 to these issues.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3191</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3624</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3628</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060160"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060163" severity="high">
    <xccdf:title>RHSA-2006:0163: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Chris Evans discovered several flaws in the way CUPS processes PDF files.
An attacker could construct a carefully crafted PDF file that could cause
CUPS to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3624,
CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627 to these issues.

All users of CUPS should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3624</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3627</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060164" severity="high">
    <xccdf:title>RHSA-2006:0164: mod_auth_pgsql security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_auth_pgsql package is an httpd module that allows user
authentication against information stored in a PostgreSQL database.

Several format string flaws were found in the way mod_auth_pgsql logs
information.  It may be possible for a remote attacker to execute arbitrary
code as the 'apache' user if mod_auth_pgsql is used for user
authentication. The Common Vulnerabilities and Exposures project assigned
the name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have mod_auth_pgsql
installed and configured to perform user authentication against a
PostgreSQL database.

All users of mod_auth_pgsql should upgrade to these updated packages, which
contain a backported patch to resolve this issue.

This issue does not affect the mod_auth_pgsql package supplied with Red Hat
Enterprise Linux 2.1.

Red Hat would like to thank iDefense for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3656</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060177" severity="high">
    <xccdf:title>RHSA-2006:0177: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gpdf is a GNOME based viewer for Portable Document Format (PDF) files.

Chris Evans discovered several flaws in the way gpdf processes PDF files.
An attacker could construct a carefully crafted PDF file that could cause
gpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3624,
CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627 to these issues.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3624</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3627</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060177"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060178" severity="medium">
    <xccdf:title>RHSA-2006:0178: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A shell command injection flaw was found in ImageMagick's "display"
command. It is possible to execute arbitrary commands by tricking a user
into running "display" on a file with a specially crafted name. The Common
Vulnerabilities and Exposures project (cve.mitre.org) assigned the name
CVE-2005-4601 to this issue.

A format string flaw was discovered in the way ImageMagick handles
filenames. It may be possible to execute arbitrary commands by tricking a
user into running a carefully crafted ImageMagick command. (CVE-2006-0082)

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0082</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060178"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060184" severity="high">
    <xccdf:title>RHSA-2006:0184: kdelibs security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>kdelibs contains libraries for the K Desktop Environment (KDE).

A heap overflow flaw was discovered affecting kjs, the JavaScript
interpreter engine used by Konqueror and other parts of KDE.  An attacker
could create a malicious web site containing carefully crafted JavaScript
code that would trigger this flaw and possibly lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project assigned the
name CVE-2006-0019 to this issue.

NOTE: this issue does not affect KDE in Red Hat Enterprise Linux 3 or 2.1.

Users of KDE should upgrade to these updated packages, which contain a
backported patch from the KDE security team correcting this issue as well
as two bug fixes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0019</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060184"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060194" severity="medium">
    <xccdf:title>RHSA-2006:0194: gd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gd package contains a graphics library used for the dynamic creation of
images such as PNG and JPEG.

Several buffer overflow flaws were found in the way gd allocates memory. 
An attacker could create a carefully crafted image that could execute
arbitrary code if opened by a victim using a program linked against the gd
library.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
assigned the name CVE-2004-0941 to these issues.

Users of gd should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-0941</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060194"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060197" severity="medium">
    <xccdf:title>RHSA-2006:0197: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming language.

An integer overflow flaw was found in Python's PCRE library that could be
triggered by a maliciously crafted regular expression. On systems that
accept arbitrary regular expressions from untrusted users, this could be
exploited to execute arbitrary code with the privileges of the application
using the library.  The Common Vulnerabilities and Exposures project
assigned the name CVE-2005-2491 to this issue.

Users of Python should upgrade to these updated packages, which contain a
backported patch that is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2491</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060200" severity="high">
    <xccdf:title>RHSA-2006:0200: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. 

Igor Bukanov discovered a bug in the way Firefox's Javascript interpreter
derefernces objects.  If a user visits a malicious web page, Firefox could
crash or execute arbitrary code as the user running Firefox. The Common
Vulnerabilities and Exposures project assigned the name CVE-2006-0292 to
this issue.

moz_bug_r_a4 discovered a bug in Firefox's XULDocument.persist() function.
A malicious web page could inject arbitrary RDF data into a user's
localstore.rdf file, which can cause Firefox to execute arbitrary
javascript when a user runs Firefox.  (CVE-2006-0296)

A denial of service bug was found in the way Firefox saves history
information. If a user visits a web page with a very long title, it is
possible Firefox will crash or take a very long time the next time it is
run. (CVE-2005-4134)

This update also fixes a bug when using XSLT to transform documents.
Passing DOM Nodes as parameters to functions expecting an xsl:param could
cause Firefox to throw an exception. 

Users of Firefox are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0296</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060200"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060201" severity="high">
    <xccdf:title>RHSA-2006:0201: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

A heap based buffer overflow bug was discovered in Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0301 to this issue.

Users of Xpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.

Red Hat would like to thank Dirk Mueller for reporting this issue and
providing a patch.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0301</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060201"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060204" severity="medium">
    <xccdf:title>RHSA-2006:0204: mailman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is software to help manage email discussion lists.

A flaw in handling of UTF8 character encodings was found in Mailman.  An
attacker could send a carefully crafted email message to a mailing list run
by Mailman which would cause that particular mailing list to stop working.
The Common Vulnerabilities and Exposures project assigned the name
CVE-2005-3573 to this issue.

A flaw in date handling was found in Mailman version 2.1.4 through 2.1.6. 
An attacker could send a carefully crafted email message to a mailing list
run by Mailman which would cause the Mailman server to crash.  (CVE-2005-4153).

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4153</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060204"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060205" severity="medium">
    <xccdf:title>RHSA-2006:0205: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap based buffer overflow bug was found in the way libpng strips alpha
channels from a PNG image. An attacker could create a carefully crafted PNG
image file in such a way that it could cause an application linked with
libpng to crash or execute arbitrary code when the file is opened by a
victim. The Common Vulnerabilities and Exposures project has assigned the
name CVE-2006-0481 to this issue.

Please note that the vunerable libpng function is only used by TeTeX and
XEmacs on Red Hat Enterprise Linux 4.

All users of libpng are advised to update to these updated packages which
contain a backported patch that is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0481</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060205"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060206" severity="high">
    <xccdf:title>RHSA-2006:0206: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer.

A heap based buffer overflow bug was discovered in kpdf. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0301 to this issue.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0301</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060207" severity="high">
    <xccdf:title>RHSA-2006:0207: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU TLS Library provides support for cryptographic algorithms and
protocols such as TLS. GNU TLS includes Libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Several flaws were found in the way libtasn1 decodes DER.  An attacker
could create a carefully crafted invalid X.509 certificate in such a way
that could trigger this flaw if parsed by an application that uses GNU TLS.
This could lead to a denial of service (application crash).  It is not
certain if this issue could be escalated to allow arbitrary code execution. 
The Common Vulnerabilities and Exposures project assigned the name
CVE-2006-0645 to this issue.

In Red Hat Enterprise Linux 4, the GNU TLS library is only used by the
Evolution client when connecting to an Exchange server or when publishing
calendar information to a WebDAV server.

Users are advised to upgrade to these updated packages, which contain a
backported patch from the GNU TLS maintainers to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0645</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060207"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060232" severity="medium">
    <xccdf:title>RHSA-2006:0232: tar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive.

Jim Meyering discovered a buffer overflow bug in the way GNU tar extracts
malformed archives. By tricking a user into extracting a malicious tar
archive, it is possible to execute arbitrary code as the user running tar.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CVE-2006-0300 to this issue.

Users of tar should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0300</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060232"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060262" severity="high">
    <xccdf:title>RHSA-2006:0262: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a PDF file viewer.

Marcelo Ricardo Leitner discovered that a kpdf security fix, CVE-2005-3627,
was incomplete.  Red Hat issued kdegraphics packages with this incomplete
fix in RHSA-2005:868.  An attacker could construct a carefully crafted PDF
file that could cause kpdf to crash or possibly execute arbitrary code when
opened.  The Common Vulnerabilities and Exposures project assigned the name
CVE-2006-0746 to this issue.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0746</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060262"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060264" severity="high">
    <xccdf:title>RHSA-2006:0264: sendmail security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sendmail is a Mail Transport Agent (MTA) used to send mail between machines.

A flaw in the handling of asynchronous signals was discovered in Sendmail.
A remote attacker may be able to exploit a race condition to execute
arbitrary code as root.  The Common Vulnerabilities and Exposures project
assigned the name CVE-2006-0058 to this issue.

By default on Red Hat Enterprise Linux 3 and 4, Sendmail is configured to
only accept connections from the local host.  Therefore, only users who have
configured Sendmail to listen to remote hosts would be able to be remotely
exploited by this vulnerability.

Users of Sendmail are advised to upgrade to these erratum packages, which
contain a backported patch from the Sendmail team to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0264</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0058</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060264"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060266" severity="high">
    <xccdf:title>RHSA-2006:0266: gnupg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

Tavis Ormandy discovered a bug in the way GnuPG verifies cryptographically
signed data with detached signatures. It is possible for an attacker to
construct a cryptographically signed message which could appear to come
from a third party.  When a victim processes a GnuPG message with a
malformed detached signature, GnuPG ignores the malformed signature,
processes and outputs the signed data, and exits with status 0, just as it
would if the signature had been valid.  In this case, GnuPG's exit status
would not indicate that no signature verification had taken place. This
issue would primarily be of concern when processing GnuPG results via an
automated script. The Common Vulnerabilities and Exposures project assigned
the name CVE-2006-0455 to this issue.

Tavis Ormandy also discovered a bug in the way GnuPG verifies
cryptographically signed data with inline signatures. It is possible for an
attacker to inject unsigned data into a signed message in such a way that
when a victim processes the message to recover the data, the unsigned data
is output along with the signed data, giving the appearance of having been
signed.  This issue is mitigated in the GnuPG shipped with Red Hat
Enterprise Linux as the --ignore-crc-error option must be passed to the gpg
executable for this attack to be successful. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0049 to this issue.

Note that neither of these issues affect the way RPM or up2date verify RPM
package files, nor is RPM vulnerable to either of these issues.

All users of GnuPG are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0455</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060266"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060267" severity="medium">
    <xccdf:title>RHSA-2006:0267: ipsec-tools security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon.  If a
victim's machine has racoon configured in a non-recommended insecure
manner, it is possible for a remote attacker to crash the racoon daemon. 
(CVE-2005-3732)

Users of ipsec-tools should upgrade to these updated packages, which contain
backported patches, and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0267</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3732</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060267"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060271" severity="high">
    <xccdf:title>RHSA-2006:0271: freeradius security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network. 

A bug was found in the way FreeRADIUS authenticates users via the MSCHAP V2
protocol. It is possible for a remote attacker to authenticate as a victim
by sending a malformed MSCHAP V2 login request to the FreeRADIUS server.
(CVE-2006-1354)

Please note that FreeRADIUS installations not using the MSCHAP V2 protocol
for authentication are not vulnerable to this issue.

A bug was also found in the way FreeRADIUS logs SQL errors from the
sql_unixodbc module. It may be possible for an attacker to cause FreeRADIUS
to crash or execute arbitrary code if they are able to manipulate the SQL
database FreeRADIUS is connecting to. (CVE-2005-4744)

Users of FreeRADIUS should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1354</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060271"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060272" severity="medium">
    <xccdf:title>RHSA-2006:0272: openmotif security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface. 

A number of buffer overflow flaws were discovered in OpenMotif's libUil
library. It is possible for an attacker to execute arbitrary code as a
victim who has been tricked into executing a program linked against
OpenMotif, which then loads a malicious User Interface Language (UIL) file.
(CVE-2005-3964)

Users of OpenMotif are advised to upgrade to these erratum packages, which
contain a backported security patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060272"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060276" severity="medium">
    <xccdf:title>RHSA-2006:0276: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

The phpinfo() PHP function did not properly sanitize long strings.  An
attacker could use this to perform cross-site scripting attacks against
sites that have publicly-available PHP scripts that call phpinfo(). 
(CVE-2006-0996)

The html_entity_decode() PHP function was found to not be binary safe. An
attacker could use this flaw to disclose a certain part of the memory.  In
order for this issue to be exploitable the target site would need to have a
PHP script which called the "html_entity_decode()" function with untrusted
input from the user and displayed the result.  (CVE-2006-1490)

The error handling output was found to not properly escape HTML output in
certain cases.  An attacker could use this flaw to perform cross-site
scripting attacks against sites where both display_errors and html_errors
are enabled.  (CVE-2006-0208)

An input validation error was found in the "mb_send_mail()" function.  An
attacker could use this flaw to inject arbitrary headers in a mail sent via
a script calling the "mb_send_mail()" function where the "To" parameter can
be controlled by the attacker.  (CVE-2005-3883)

A buffer overflow flaw was discovered in uw-imap, the University of
Washington's IMAP Server.  php-imap is compiled against the static c-client
libraries from imap and therefore needed to be recompiled against the fixed
version.  This issue only affected Red Hat Enterprise Linux 3.
(CVE-2005-2933).

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0276</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2003-1303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1490</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060276"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060280" severity="medium">
    <xccdf:title>RHSA-2006:0280: dia security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dia drawing program is designed to draw various types of diagrams.

infamous41md discovered three buffer overflow bugs in Dia's xfig file
format importer. If an attacker is able to trick a Dia user into opening a
carefully crafted xfig file, it may be possible to execute arbitrary code
as the user running Dia. (CVE-2006-1550)

Users of Dia should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0280</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1550</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060280"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060283" severity="medium">
    <xccdf:title>RHSA-2006:0283: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP4.

A bug was found in the way SquirrelMail presents the right frame to the
user. If a user can be tricked into opening a carefully crafted URL, it is
possible to present the user with arbitrary HTML data. (CVE-2006-0188)

A bug was found in the way SquirrelMail filters incoming HTML email. It is
possible to cause a victim's web browser to request remote content by
opening a HTML email while running a web browser that processes certain
types of invalid style sheets. Only Internet Explorer is known to process
such malformed style sheets. (CVE-2006-0195)

A bug was found in the way SquirrelMail processes a request to select an
IMAP mailbox. If a user can be tricked into opening a carefully crafted
URL, it is possible to execute arbitrary IMAP commands as the user viewing
their mail with SquirrelMail. (CVE-2006-0377)

Users of SquirrelMail are advised to upgrade to this updated package, which
contains SquirrelMail version 1.4.6 and is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0377</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060283"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060328" severity="high">
    <xccdf:title>RHSA-2006:0328: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several bugs were found in the way Firefox processes malformed javascript.
A malicious web page could modify the content of a different open web page,
possibly stealing sensitive information or conducting a cross-site
scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Firefox processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-1727,
CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Firefox processes malformed web pages.
A carefully crafted malicious web page could cause the execution of
arbitrary code as the user running Firefox. (CVE-2006-0748, CVE-2006-0749,
CVE-2006-1724, CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739,
CVE-2006-1790) 

A bug was found in the way Firefox displays the secure site icon. If a
browser is configured to display the non-default secure site modal warning
dialog, it may be possible to trick a user into believing they are viewing
a secure site. (CVE-2006-1740)

A bug was found in the way Firefox allows javascript mutation events on
"input" form elements. A malicious web page could be created in such a way
that when a user submits a form, an arbitrary file could be uploaded to the
attacker. (CVE-2006-1729)

Users of Firefox are advised to upgrade to these updated packages
containing Firefox version 1.0.8 which corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0328</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1790</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060328"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060329" severity="high">
    <xccdf:title>RHSA-2006:0329: mozilla security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found in the way Mozilla processes malformed javascript.
A malicious web page could modify the content of a different open web
page, possibly stealing sensitive information or conducting a cross-site
scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Mozilla processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-1727,
CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Mozilla processes malformed web pages. 
A carefully crafted malicious web page could cause the execution of
arbitrary code as the user running Mozilla. (CVE-2006-0748, CVE-2006-0749,
CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Mozilla displays the secure site icon. If a
browser is configured to display the non-default secure site modal warning
dialog, it may be possible to trick a user into believing they are viewing
a secure site. (CVE-2006-1740)

A bug was found in the way Mozilla allows javascript mutation events on
"input" form elements. A malicious web page could be created in such a way
that when a user submits a form, an arbitrary file could be uploaded to the
attacker. (CVE-2006-1729)

A bug was found in the way Mozilla executes in-line mail forwarding. If a
user can be tricked into forwarding a maliciously crafted mail message as
in-line content, it is possible for the message to execute javascript with
the permissions of "chrome". (CVE-2006-0884)

Users of Mozilla are advised to upgrade to these updated packages
containing Mozilla version 1.7.13 which corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1790</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060329"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060330" severity="high">
    <xccdf:title>RHSA-2006:0330: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several bugs were found in the way Thunderbird processes malformed
javascript. A malicious HTML mail message could modify the content of a
different open HTML mail message, possibly stealing sensitive information
or conducting a cross-site scripting attack. Please note that JavaScript
support is disabled by default in Thunderbird. (CVE-2006-1731,
CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Thunderbird processes certain 
javascript actions. A malicious HTML mail message could execute arbitrary 
javascript instructions with the permissions of 'chrome', allowing the 
page to steal sensitive information or install browser malware. Please 
note that JavaScript support is disabled by default in Thunderbird. 
(CVE-2006-0292, CVE-2006-0296, CVE-2006-1727, CVE-2006-1728, CVE-2006-1733,
CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Thunderbird processes malformed HTML
mail messages.  A carefully crafted malicious HTML mail message could 
cause the execution of arbitrary code as the user running Thunderbird.
(CVE-2006-0748, CVE-2006-0749, CVE-2006-1724, CVE-2006-1730, CVE-2006-1737,
CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Thunderbird processes certain inline content 
in HTML mail messages. It may be possible for a remote attacker to send a
carefully crafted mail message to the victim, which will fetch remote
content, even if Thunderbird is configured not to fetch remote content.
(CVE-2006-1045)

A bug was found in the way Thunderbird executes in-line mail forwarding. If
a user can be tricked into forwarding a maliciously crafted mail message as
in-line content, it is possible for the message to execute javascript with
the permissions of "chrome". (CVE-2006-0884)

Users of Thunderbird are advised to upgrade to these updated packages
containing Thunderbird version 1.0.8, which is not vulnerable to these 
issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1790</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060330"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060354" severity="low">
    <xccdf:title>RHSA-2006:0354: elfutils security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The elfutils packages contain a number of utility programs and libraries
related to the creation and maintenance of executable code.

The elfutils packages that originally shipped with Red Hat Enterprise Linux 4
were GPL-licensed versions which lacked some functionality. Previous
updates provided fully functional versions of elfutils only under the OSL
license. This update provides a fully functional, GPL-licensed version of
elfutils. 

In the OSL-licensed elfutils versions provided in previous updates, some
tools could sometimes crash when given corrupted input files.  (CVE-2005-1704)

Also, when the eu-strip tool was used to create separate debuginfo files
from relocatable objects such as kernel modules (.ko), the resulting
debuginfo files (.ko.debug) were sometimes corrupted.  Both of these
problems are fixed in the new version.

Users of elfutils should upgrade to these updated packages, which resolve
these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0354</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060354"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060393" severity="low">
    <xccdf:title>RHSA-2006:0393: ntp security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a reference time source.

The NTP daemon (ntpd), when run with the -u option and using a string to
specify the group, uses the group ID of the user instead of the group,
which causes ntpd to run with different privileges than intended.
(CVE-2005-2496)

The following issues have also been addressed in this update: 
- The init script had several problems
- The script executed on upgrade could fail
- The man page for ntpd indicated the wrong option for specifying a chroot
directory
- The ntp daemon could crash with the message "Exiting: No more memory!"
- There is a new option for syncing the hardware clock after a successful
run of ntpdate

Users of ntp should upgrade to these updated packages, which resolve these
issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2496</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060393"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060425" severity="high">
    <xccdf:title>RHSA-2006:0425: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

An integer overflow flaw was discovered in libtiff. An attacker could
create a carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2025)

A double free flaw was discovered in libtiff. An attacker could create a
carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2026)

Several denial of service flaws were discovered in libtiff. An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to crash. (CVE-2006-2024,
CVE-2006-2120)

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2120</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060425"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060427" severity="medium">
    <xccdf:title>RHSA-2006:0427: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for object-oriented programming. 

A bug was found in the way Ruby creates its xmlrpc and http servers. The
servers use a non blocking socket, which enables a remote user to cause a
denial of service condition if they are able to transmit a large volume of
information from the network server. (CVE-2006-1931)

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1931</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060427"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060451" severity="high">
    <xccdf:title>RHSA-2006:0451: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces such as GNOME and KDE are designed upon. 

A buffer overflow flaw in the X.org server RENDER extension was discovered.
A malicious authorized client could exploit this issue to cause a denial of
service (crash) or potentially execute arbitrary code with root privileges
on the X.org server. (CVE-2006-1526)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.

This issue does not affect Red Hat Enterprise Linux 2.1 or 3.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1526</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060451"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060486" severity="medium">
    <xccdf:title>RHSA-2006:0486: mailman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is software to help manage email discussion lists.

A flaw was found in the way Mailman handles MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which would cause that particular mailing list
to stop working. (CVE-2006-0052)

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0052</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060486"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060493" severity="high">
    <xccdf:title>RHSA-2006:0493: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues
described below:

* a flaw in the IPv6 implementation that allowed a local user to cause a
denial of service (infinite loop and crash) (CVE-2005-2973, important)

* a flaw in the bridge implementation that allowed a remote user to
cause forwarding of spoofed packets via poisoning of the forwarding
table with already dropped frames (CVE-2005-3272, moderate)

* a flaw in the atm module that allowed a local user to cause a denial
of service (panic) via certain socket calls (CVE-2005-3359, important)

* a flaw in the NFS client implementation that allowed a local user to
cause a denial of service (panic) via O_DIRECT writes (CVE-2006-0555,
important)

* a difference in "sysretq" operation of EM64T (as opposed to Opteron)
processors that allowed a local user to cause a denial of service
(crash) upon return from certain system calls (CVE-2006-0741 and
CVE-2006-0744, important)

* a flaw in the keyring implementation that allowed a local user to
cause a denial of service (OOPS) (CVE-2006-1522, important)

* a flaw in IP routing implementation that allowed a local user to cause
a denial of service (panic) via a request for a route for a multicast IP
(CVE-2006-1525, important)

* a flaw in the SCTP-netfilter implementation that allowed a remote user
to cause a denial of service (infinite loop) (CVE-2006-1527, important)

* a flaw in the sg driver that allowed a local user to cause a denial of
service (crash) via a dio transfer to memory mapped (mmap) IO space
(CVE-2006-1528, important)

* a flaw in the threading implementation that allowed a local user to
cause a denial of service (panic) (CVE-2006-1855, important)

* two missing LSM hooks that allowed a local user to bypass the LSM by
using readv() or writev() (CVE-2006-1856, moderate)

* a flaw in the virtual memory implementation that allowed local user to
cause a denial of service (panic) by using the lsof command
(CVE-2006-1862, important)

* a directory traversal vulnerability in smbfs that allowed a local user
to escape chroot restrictions for an SMB-mounted filesystem via "..\\"
sequences (CVE-2006-1864, moderate)

* a flaw in the ECNE chunk handling of SCTP that allowed a remote user
to cause a denial of service (panic) (CVE-2006-2271, moderate)

* a flaw in the handling of COOKIE_ECHO and HEARTBEAT control chunks of
SCTP that allowed a remote user to cause a denial of service (panic)
(CVE-2006-2272, moderate)

* a flaw in the handling of DATA fragments of SCTP that allowed a remote
user to cause a denial of service (infinite recursion and crash)
(CVE-2006-2274, moderate)

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2973</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3359</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1855</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1856</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2274</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060493"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060500" severity="medium">
    <xccdf:title>RHSA-2006:0500: freetype security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, and portable font engine.

Chris Evans discovered several integer underflow and overflow flaws in the
FreeType font engine. If a user loads a carefully crafted font file with a
program linked against FreeType, it could cause the application to crash or
execute arbitrary code as the user. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2006-0747,
CVE-2006-1861, CVE-2006-3467)

A NULL pointer dereference flaw was found in the FreeType font engine. An
application linked against FreeType can crash upon loading a malformed font
file. (CVE-2006-2661)

Users of FreeType should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2661</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3467</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060500"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060515" severity="high">
    <xccdf:title>RHSA-2006:0515: sendmail security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sendmail is a Mail Transport Agent (MTA) used to send mail between machines.

A flaw in the handling of multi-part MIME messages was discovered in
Sendmail.  A remote attacker could create a carefully crafted message that
could crash the sendmail process during delivery (CVE-2006-1173).  By
default on Red Hat Enterprise Linux, Sendmail is configured to only accept
connections from the local host. Therefore, only users who have configured
Sendmail to listen to remote hosts would be remotely vulnerable to this issue.

Users of Sendmail are advised to upgrade to these erratum packages, which
contain a backported patch from the Sendmail team to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1173</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060515"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060525" severity="medium">
    <xccdf:title>RHSA-2006:0525: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga manages the TCP/IP based routing protocol. It takes a multi-server
and multi-thread approach to resolve the current complexity of the Internet.

An information disclosure flaw was found in the way Quagga interprets RIP
REQUEST packets. RIPd in Quagga will respond to RIP REQUEST packets for RIP
versions that have been disabled or that have authentication enabled,
allowing a remote attacker to acquire information about the local network.
(CVE-2006-2223)

A route injection flaw was found in the way Quagga interprets RIPv1
RESPONSE packets when RIPv2 authentication is enabled. It is possible for a
remote attacker to inject arbitrary route information into the RIPd routing
tables. This issue does not affect Quagga configurations where only RIPv2
is specified. (CVE-2006-2224)

A denial of service flaw was found in Quagga's telnet interface. If an
attacker is able to connect to the Quagga telnet interface, it is possible
to cause Quagga to consume vast quantities of CPU resources by issuing a
malformed 'sh' command. (CVE-2006-2276)

Users of Quagga should upgrade to these updated packages, which contain
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2276</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060525"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060526" severity="high">
    <xccdf:title>RHSA-2006:0526: postgresql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A bug was found in the way PostgreSQL's PQescapeString function escapes
strings when operating in a multibyte character encoding. It is possible
for an attacker to provide an application a carefully crafted string
containing invalidly-encoded characters, which may be improperly escaped,
allowing the attacker to inject malicious SQL. While this update fixes how
PQescapeString operates, the PostgreSQL server has also been modified to
prevent such an attack occurring through unpatched clients. 
(CVE-2006-2313, CVE-2006-2314).  More details about this issue are
available in the linked PostgreSQL technical documentation.

An integer signedness bug was found in the way PostgreSQL generated
password salts. The actual salt size is only half the size of the expected
salt, making the process of brute forcing password hashes slightly easier.
This update will not strengthen already existing passwords, but all newly
assigned passwords will have the proper salt length. (CVE-2006-0591)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 7.4.13, which corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2314</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060526"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060539" severity="high">
    <xccdf:title>RHSA-2006:0539: vixie-cron security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A privilege escalation flaw was found in the way Vixie Cron runs programs;
vixie-cron does not properly verify an attempt to set the current process
user id succeeded. It was possible for a malicious local users who
exhausted certain limits to execute arbitrary commands as root via cron.
(CVE-2006-2607)

All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0539</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2607</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060539"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060541" severity="medium">
    <xccdf:title>RHSA-2006:0541: dia security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dia drawing program is designed to draw various types of diagrams.

Several format string flaws were found in the way dia displays certain
messages. If an attacker is able to trick a Dia user into opening a
carefully crafted file, it may be possible to execute arbitrary code as the
user running Dia. (CVE-2006-2453, CVE-2006-2480)

Users of Dia should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060541"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060543" severity="medium">
    <xccdf:title>RHSA-2006:0543: spamassassin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A flaw was found with the way the Spamassassin spamd daemon processes the
virtual pop username passed to it. If a site is running spamd with both the
--vpopmail and --paranoid flags, it is possible for a remote user with the
ability to connect to the spamd daemon to execute arbitrary commands as
the user running the spamd daemon. (CVE-2006-2447)

Note: None of the IMAP or POP servers shipped with Red Hat Enterprise Linux
4 support vpopmail delivery.  Running spamd with the --vpopmail and
--paranoid flags is uncommon and not the default startup option as shipped
with Red Hat Enterprise Linux 4.

Spamassassin, as shipped in Red Hat Enterprise Linux 4, performs RBL
lookups against visi.com to help determine if an email is spam. However,
this DNS RBL has recently disappeared, resulting in mail filtering delays
and timeouts.

Users of SpamAssassin should upgrade to these updated packages containing
version 3.0.6 and backported patches, which are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060543"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060544" severity="high">
    <xccdf:title>RHSA-2006:0544: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was found in the way the MySQL mysql_real_escape() function escaped
strings when operating in a multibyte character encoding.  An attacker
could provide an application a carefully crafted string containing
invalidly-encoded characters which may be improperly escaped, leading to
the injection of malicious SQL commands. (CVE-2006-2753)

An information disclosure flaw was found in the way the MySQL server
processed malformed usernames. An attacker could view a small portion
of server memory by supplying an anonymous login username which was not
null terminated. (CVE-2006-1516)

An information disclosure flaw was found in the way the MySQL server
executed the COM_TABLE_DUMP command. An authenticated malicious user could
send a specially crafted packet to the MySQL server which returned
random unallocated memory. (CVE-2006-1517)

A log file obfuscation flaw was found in the way the mysql_real_query()
function creates log file entries. An attacker with the the ability to call
the mysql_real_query() function against a mysql server can obfuscate the
entry the server will write to the log file.  However, an attacker needed
to have complete control over a server in order to attempt this attack.
(CVE-2006-0903)

This update also fixes numerous non-security-related flaws, such as
intermittent authentication failures.

All users of mysql are advised to upgrade to these updated packages
containing MySQL version 4.1.20, which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4380</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060544"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060547" severity="medium">
    <xccdf:title>RHSA-2006:0547: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP4.

A local file disclosure flaw was found in the way SquirrelMail loads
plugins. In SquirrelMail 1.4.6 or earlier, if register_globals is on and
magic_quotes_gpc is off, it became possible for an unauthenticated remote
user to view the contents of arbitrary local files the web server has
read-access to. This configuration is neither default nor safe, and
configuring PHP with the register_globals set on is dangerous and not
recommended.  (CVE-2006-2842) 

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2842</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060547"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060548" severity="high">
    <xccdf:title>RHSA-2006:0548: kdebase security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include the KDE Display Manager (KDM).

Ludwig Nussel discovered a flaw in KDM. A malicious local KDM user could
use a symlink attack to read an arbitrary file that they would not normally
have permissions to read. (CVE-2006-2449)

Note: this issue does not affect the version of KDM as shipped with Red Hat
Enterprise Linux 2.1 or 3.

All users of KDM should upgrade to these updated packages which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2449</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060548"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060568" severity="medium">
    <xccdf:title>RHSA-2006:0568: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A directory traversal vulnerability was found in PHP.  Local users could
bypass open_basedir restrictions allowing remote attackers to create files
in arbitrary directories via the tempnam() function.  (CVE-2006-1494)

The wordwrap() PHP function did not properly check for integer overflow in
the handling of the "break" parameter. An attacker who could control the
string passed to the "break" parameter could cause a heap overflow.
(CVE-2006-1990) 

A flaw was found in the zend_hash_del() PHP function.  For PHP scripts that
rely on the use of the unset() function, a remote attacker could force
variable initialization to be bypassed.  This would be a security issue
particularly for installations that enable the "register_globals" setting.
"register_globals" is disabled by default in Red Hat Enterprise Linux.
(CVE-2006-3017)

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3017</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060568"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060571" severity="medium">
    <xccdf:title>RHSA-2006:0571: gnupg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

An integer overflow flaw was found in GnuPG.  An attacker could create a
carefully crafted message packet with a large length that could cause GnuPG
to crash or possibly overwrite memory when opened. (CVE-2006-3082)

All users of GnuPG are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3082</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060571"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060573" severity="high">
    <xccdf:title>RHSA-2006:0573: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A Sun security specialist reported an issue with the application framework.
An attacker could put macros into document locations that could cause
OpenOffice.org to execute them when the file was opened by a victim.
(CVE-2006-2198)

A bug was found in the OpenOffice.org Java virtual machine implementation.
An attacker could write a carefully crafted Java applet that can break
through the "sandbox" and have full access to system resources with the
current user privileges. (CVE-2006-2199)

A buffer overflow bug was found in the OpenOffice.org file processor. An
attacker could create a carefully crafted XML file that could cause
OpenOffice.org to write data to an arbitrary location in memory when the
file was opened by a victim. (CVE-2006-3117)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3117</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060573"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060574" severity="high">
    <xccdf:title>RHSA-2006:0574: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

During security research, Red Hat discovered a behavioral flaw in core dump
handling.  A local user could create a program that would cause a core file
to be dumped into a directory they would not normally have permissions to
write to.  This could lead to a denial of service (disk consumption), or
allow the local user to gain root privileges.  (CVE-2006-2451)

Prior to applying this update, users can remove the ability to escalate
privileges using this flaw by configuring core files to dump to an absolute
location.  By default, core files are created in the working directory of
the faulting application, but this can be overridden by specifying an
absolute location for core files in /proc/sys/kernel/core_pattern.  To
avoid a potential denial of service, a separate partition for the core
files should be used.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2451</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060574"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060575" severity="high">
    <xccdf:title>RHSA-2006:0575: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 4 (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>New features introduced in this update include:

* Device Mapper mirroring support

* IDE diskdump support

* x86, AMD64 and Intel EM64T: Multi-core scheduler support enhancements

* Itanium: perfmon support for Montecito

* much improved support for IBM x460

* AMD PowerNow! patches to support Opteron Rev G

* Vmalloc support &gt; 64MB

The following device drivers have been upgraded to new versions:

ipmi: 33.11 to 33.13
ib_mthca: 0.06 to 0.08
bnx2: 1.4.30 to 1.4.38
bonding: 2.6.1 to 2.6.3
e100: 3.4.8-k2-NAPI to 3.5.10-k2-NAPI
e1000: 6.1.16-k3-NAPI to 7.0.33-k2-NAPI
sky2: 0.13 to 1.1
tg3: 3.43-rh to 3.52-rh
ipw2100: 1.1.0 to git-1.1.4
ipw2200: 1.0.0 to git-1.0.10
3w-9xxx: 2.26.02.001 to 2.26.04.010
ips: 7.10.18 to 7.12.02
iscsi_sfnet: 4:0.1.11-2 to 4:0.1.11-3
lpfc: 0:8.0.16.18 to 0:8.0.16.27
megaraid_sas: 00.00.02.00 to 00.00.02.03-RH1
qla2xxx: 8.01.02-d4 to 8.01.04-d7
qla6312: 8.01.02-d4 to 8.01.04-d7
sata_promise: 1.03 to 1.04
sata_vsc: 1.1 to 1.2
ibmvscsic: 1.5.5 to 1.5.6
ipr: 2.0.11.1 to 2.0.11.2

Added drivers:

dcdbas: 5.6.0-2
sata_mv: 0.6
sata_qstor: 0.05
sata_uli: 0.5
skge: 1.1
stex: 2.9.0.13
pdc_adma: 0.03

This update includes fixes for the security issues:

* a flaw in the USB devio handling of device removal that allowed a
local user to cause a denial of service (crash) (CVE-2005-3055,
moderate)

* a flaw in the ACL handling of nfsd that allowed a remote user to
bypass ACLs for readonly mounted NFS file systems (CVE-2005-3623,
moderate)

* a flaw in the netfilter handling that allowed a local user with
CAP_NET_ADMIN rights to cause a buffer overflow (CVE-2006-0038, low)

* a flaw in the IBM S/390 and IBM zSeries strnlen_user() function that
allowed a local user to cause a denial of service (crash) or to retrieve
random kernel data (CVE-2006-0456, important)

* a flaw in the keyctl functions that allowed a local user to cause a
denial of service (crash) or to read sensitive kernel memory
(CVE-2006-0457, important)

* a flaw in unaligned accesses handling on Itanium processors that
allowed a local user to cause a denial of service (crash)
(CVE-2006-0742, important)

* a flaw in SELinux ptrace logic that allowed a local user with ptrace
permissions to change the tracer SID to a SID of another process
(CVE-2006-1052, moderate)

* an info leak on AMD-based x86 and x86_64 systems that allowed a local
user to retrieve the floating point exception state of a process run by a
different user (CVE-2006-1056, important)

* a flaw in IPv4 packet output handling that allowed a remote user to
bypass the zero IP ID countermeasure on systems with a disabled firewall
(CVE-2006-1242, low)

* a minor info leak in socket option handling in the network code
(CVE-2006-1343, low)

* a flaw in the HB-ACK chunk handling of SCTP that allowed a remote user to
cause a denial of service (crash) (CVE-2006-1857, moderate)

* a flaw in the SCTP implementation that allowed a remote user to cause a
denial of service (deadlock) (CVE-2006-2275, moderate)

* a flaw in the socket buffer handling that allowed a remote user to cause
a denial of service (panic) (CVE-2006-2446, important)

* a flaw in the signal handling access checking on PowerPC that allowed a
local user to cause a denial of service (crash) or read arbitrary kernel
memory on 64-bit systems (CVE-2006-2448, important)

* a flaw in the netfilter SCTP module when receiving a chunkless packet
that allowed a remote user to cause a denial of service (crash)
(CVE-2006-2934, important)

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1857</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2934</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060575"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060577" severity="medium">
    <xccdf:title>RHSA-2006:0577: mutt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mutt is a text-mode mail user agent.

A buffer overflow flaw was found in the way Mutt processes an overly
long namespace from a malicious imap server.  In order to exploit this
flaw a user would have to use Mutt to connect to a malicious IMAP server.
(CVE-2006-3242)

Users of Mutt are advised to upgrade to these erratum packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3242</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060577"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060582" severity="low">
    <xccdf:title>RHSA-2006:0582: kdebase security fix (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include the file manager Konqueror.

Ilja van Sprundel discovered a lock file handling flaw in kcheckpass.  If
the directory /var/lock is writable by a user who is allowed to run
kcheckpass, that user could gain root privileges.  In Red Hat Enterprise
Linux, the /var/lock directory is not writable by users and therefore this
flaw could only have been exploited if the permissions on that directory
have been badly configured.  A patch to block this issue has been included
in this update.  (CVE-2005-2494)

The following bugs have also been addressed:

- kstart --tosystray does not send the window to the system tray in Kicker

- When the customer enters or selects URLs in Firefox's address field, the
desktop freezes for a couple of seconds

- fish kioslave is broken on 64-bit systems

All users of kdebase should upgrade to these updated packages, which
contain patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060582"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060591" severity="high">
    <xccdf:title>RHSA-2006:0591: samba security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service bug was found in the way the smbd daemon tracks active
connections to shares. It was possible for a remote attacker to cause the
smbd daemon to consume a large amount of system memory by sending carefully
crafted smb requests. (CVE-2006-3403)

Users of Samba are advised to upgrade to these packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3403</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060591"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060597" severity="medium">
    <xccdf:title>RHSA-2006:0597: libwmf security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Libwmf is a library for reading and converting Windows MetaFile vector
graphics (WMF).  Libwmf is used by packages such as The GIMP and ImageMagick.

An integer overflow flaw was discovered in libwmf.  An attacker could
create a carefully crafted WMF flaw that could execute arbitrary code if
opened by a victim.  (CVE-2006-3376).

Users of libwmf should update to these packages which contain a backported
security patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3376</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060597"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060598" severity="medium">
    <xccdf:title>RHSA-2006:0598: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Henning Makholm discovered a buffer overflow bug in The GIMP XCF file
loader. An attacker could create a carefully crafted image that could
execute arbitrary code if opened by a victim.  (CVE-2006-3404)

Please note that this issue did not affect the gimp packages in Red Hat
Enterprise Linux 2.1, or 3.

Users of The GIMP should update to these erratum packages which contain a
backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3404</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060598"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060600" severity="medium">
    <xccdf:title>RHSA-2006:0600: mailman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage email discussion lists.

A flaw was found in the way Mailman handled MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which caused that particular mailing list
to stop working.  (CVE-2006-2941)

Several cross-site scripting (XSS) issues were found in Mailman.  An
attacker could exploit these issues to perform cross-site scripting attacks
against the Mailman administrator.  (CVE-2006-3636)

Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.

Users of Mailman should upgrade to these updated packages, which contain
backported patches to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2941</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060600"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060602" severity="medium">
    <xccdf:title>RHSA-2006:0602: wireshark security update (was ethereal) (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ethereal is a program for monitoring network traffic.

In May 2006, Ethereal changed its name to Wireshark.  This update
deprecates the Ethereal packages in Red Hat Enterprise Linux 2.1, 3, and 4
in favor of the supported Wireshark packages.

Several denial of service bugs were found in Ethereal's protocol
dissectors. It was possible for Ethereal to crash or stop responding if it
read a malformed packet off the network.  (CVE-2006-3627, CVE-2006-3629,
CVE-2006-3631)

Several buffer overflow bugs were found in Ethereal's ANSI MAP, NCP NMAS,
and NDPStelnet dissectors. It was possible for Ethereal to crash or execute
arbitrary code if it read a malformed packet off the network.
(CVE-2006-3630, CVE-2006-3632)

Several format string bugs were found in Ethereal's Checkpoint FW-1, MQ,
XML, and NTP dissectors. It was possible for Ethereal to crash or execute
arbitrary code if it read a malformed packet off the network. (CVE-2006-3628)

Users of Ethereal should upgrade to these updated packages containing
Wireshark version 0.99.2, which is not vulnerable to these issues</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3629</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3630</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3631</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3632</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060602"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060603" severity="high">
    <xccdf:title>RHSA-2006:0603: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) files.

Tavis Ormandy of Google discovered a number of flaws in libtiff during a
security audit.  An attacker could create a carefully crafted TIFF file in
such a way that it was possible to cause an application linked with libtiff
to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460,
CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465)

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3465</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060603"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060604" severity="medium">
    <xccdf:title>RHSA-2006:0604: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for object-oriented programming. 

A number of flaws were found in the safe-level restrictions in Ruby.  It
was possible for an attacker to create a carefully crafted malicious script
that can allow the bypass of certain safe-level restrictions. (CVE-2006-3694)

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3694</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060604"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060605" severity="high">
    <xccdf:title>RHSA-2006:0605: perl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a flaw in sperl, the Perl setuid wrapper, which
can cause debugging information to be logged to arbitrary files. By setting
an environment variable, a local user could cause sperl to create, as root,
files with arbitrary filenames, or append the debugging information to
existing files. (CVE-2005-0155)

A fix for this issue was first included in the update RHSA-2005:103
released in February 2005.  However the patch to correct this issue was
dropped from the update RHSA-2005:674 made in October 2005.  This
regression has been assigned CVE-2006-3813.

Users of Perl are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3813</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060605"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060609" severity="high">
    <xccdf:title>RHSA-2006:0609: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Seamonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

The Mozilla Foundation has discontinued support for the Mozilla Suite. This
update deprecates the Mozilla Suite in Red Hat Enterprise Linux 4 in
favor of the supported Seamonkey Suite.

This update also resolves a number of outstanding Mozilla security issues:

Several flaws were found in the way Seamonkey processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787, CVE-2006-3807, CVE-2006-3809,
CVE-2006-3812)

Several denial of service flaws were found in the way Seamonkey processed
certain web content. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running Seamonkey.
(CVE-2006-2779, CVE-2006-2780, CVE-2006-3801, CVE-2006-3677, CVE-2006-3113,
CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3811)

Two flaws were found in the way Seamonkey-mail displayed malformed
inline vcard attachments. If a victim viewed an email message containing
a carefully crafted vcard it was possible to execute arbitrary code as the
user running Mozilla-mail. (CVE-2006-2781, CVE-2006-3804)

A cross-site scripting flaw was found in the way Seamonkey processed
Unicode Byte-Order-Mark (BOM) markers in UTF-8 web pages. A malicious web
page could execute a script within the browser that a web input sanitizer
could miss due to a malformed "script" tag. (CVE-2006-2783)

Several flaws were found in the way Seamonkey processed certain javascript
actions. A malicious web page could conduct a cross-site scripting attack
or steal sensitive information (such as cookies owned by other domains).
(CVE-2006-3802, CVE-2006-3810)

A form file upload flaw was found in the way Seamonkey handled javascript
input object mutation. A malicious web page could upload an arbitrary local
file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Seamonkey called the
crypto.signText() javascript function. A malicious web page could crash the
browser if the victim had a client certificate loaded. (CVE-2006-2778)

Two HTTP response smuggling flaws were found in the way Seamonkey processed
certain invalid HTTP response headers. A malicious web site could return
specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A flaw was found in the way Seamonkey processed Proxy AutoConfig scripts. A
malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3808)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page, it was possible
to execute arbitrary code as the user running Mozilla. (CVE-2006-2788)

Users of Mozilla are advised to upgrade to this update, which contains
Seamonkey version 1.0.3 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3812</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060609"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060610" severity="high">
    <xccdf:title>RHSA-2006:0610: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

The Mozilla Foundation has discontinued support for the Mozilla Firefox
1.0 branch. This update deprecates the Mozilla Firefox 1.0 branch in
Red Hat Enterprise Linux 4 in favor of the supported Mozilla Firefox
1.5 branch.

This update also resolves a number of outstanding Firefox security issues:

Several flaws were found in the way Firefox processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787, CVE-2006-3807, CVE-2006-3809,
CVE-2006-3812)

Several denial of service flaws were found in the way Firefox processed
certain web content. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running Firefox.
(CVE-2006-2779, CVE-2006-2780, CVE-2006-3801, CVE-2006-3677, CVE-2006-3113,
CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3811)

A cross-site scripting flaw was found in the way Firefox processed
Unicode Byte-Order-Mark (BOM) markers in UTF-8 web pages. A malicious web
page could execute a script within the browser that a web input sanitizer
could miss due to a malformed "script" tag. (CVE-2006-2783)

Several flaws were found in the way Firefox processed certain javascript
actions. A malicious web page could conduct a cross-site scripting attack
or steal sensitive information (such as cookies owned by other domains).
(CVE-2006-3802, CVE-2006-3810)

A form file upload flaw was found in the way Firefox handled javascript
input object mutation. A malicious web page could upload an arbitrary local
file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Firefox called the
crypto.signText() javascript function. A malicious web page could crash the
browser if the victim had a client certificate loaded. (CVE-2006-2778)

Two HTTP response smuggling flaws were found in the way Firefox processed
certain invalid HTTP response headers. A malicious web site could return
specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A flaw was found in the way Firefox processed Proxy AutoConfig scripts. A
malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3808)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page, it was possible
to execute arbitrary code as the user running Firefox. (CVE-2006-2788)

Users of Firefox are advised to upgrade to this update, which contains
Firefox version 1.5.0.5 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0610</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3812</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060610"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060611" severity="high">
    <xccdf:title>RHSA-2006:0611: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

The Mozilla Foundation has discontinued support for the Mozilla Thunderbird
1.0 branch. This update deprecates the Mozilla Thunderbird 1.0 branch in
Red Hat Enterprise Linux 4 in favor of the supported Mozilla Thunderbird
1.5 branch.

This update also resolves a number of outstanding Thunderbird security issues:

Several flaws were found in the way Thunderbird processed certain
javascript actions. A malicious mail message could execute arbitrary
javascript instructions with the permissions of "chrome", allowing the page
to steal sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787, CVE-2006-3807, CVE-2006-3809)

Several denial of service flaws were found in the way Thunderbird processed
certain mail messages. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running Thunderbird.
(CVE-2006-2779, CVE-2006-2780, CVE-2006-3801, CVE-2006-3677,
CVE-2006-3113, CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3811)

Several flaws were found in the way Thunderbird processed certain
javascript actions. A malicious mail message could conduct a cross-site
scripting attack or steal sensitive information (such as cookies owned by
other domains). (CVE-2006-3802, CVE-2006-3810)

A form file upload flaw was found in the way Thunderbird handled javascript
input object mutation. A malicious mail message could upload an arbitrary
local file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Thunderbird called the
crypto.signText() javascript function. A malicious mail message could crash
the browser if the victim had a client certificate loaded. (CVE-2006-2778)

A flaw was found in the way Thunderbird processed Proxy AutoConfig scripts.
A malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install client malware. (CVE-2006-3808)

Note: Please note that JavaScript support is disabled by default in
Thunderbird. The above issues are not exploitable with JavaScript disabled. 

Two flaws were found in the way Thunderbird displayed malformed inline
vcard attachments. If a victim viewed an email message containing a
carefully crafted vcard it was possible to execute arbitrary code as the
user running Thunderbird. (CVE-2006-2781, CVE-2006-3804)

A cross site scripting flaw was found in the way Thunderbird processed
Unicode Byte-order-Mark (BOM) markers in UTF-8 mail messages. A malicious
web page could execute a script within the browser that a web input
sanitizer could miss due to a malformed "script" tag. (CVE-2006-2783)

Two HTTP response smuggling flaws were found in the way Thunderbird
processed certain invalid HTTP response headers. A malicious web site could
return specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page, it was possible
to crash Thunderbird. (CVE-2006-2788)

Users of Thunderbird are advised to upgrade to this update, which contains
Thunderbird version 1.5.0.5 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0611</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060611"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060612" severity="high">
    <xccdf:title>RHSA-2006:0612: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found where some bundled Kerberos-aware applications would fail
to check the result of the setuid() call. On Linux 2.6 kernels, the
setuid() call can fail if certain user limits are hit. A local attacker
could manipulate their environment in such a way to get the applications to
continue to run as root, potentially leading to an escalation of
privileges.  (CVE-2006-3083).

Users are advised to update to these erratum packages which contain a
backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3083</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060612"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060615" severity="medium">
    <xccdf:title>RHSA-2006:0615: gnupg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

An integer overflow flaw was found in GnuPG. An attacker could create a
carefully crafted message packet with a large length that could cause GnuPG
to crash or possibly overwrite memory when opened. (CVE-2006-3746)

All users of GnuPG are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3746</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060615"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060617" severity="high">
    <xccdf:title>RHSA-2006:0617: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the proc file system that allowed a local user to use a
suid-wrapper for scripts to gain root privileges (CVE-2006-3626, Important)

* a flaw in the SCTP implementation that allowed a local user to cause a
denial of service (panic) or to possibly gain root privileges
(CVE-2006-3745, Important)

* a flaw in NFS exported ext2/ext3 partitions when handling invalid inodes
that allowed a remote authenticated user to cause a denial of service
(filesystem panic) (CVE-2006-3468, Important)

* a flaw in the restore_all code path of the 4/4GB split support of
non-hugemem kernels that allowed a local user to cause a denial of service
(panic) (CVE-2006-2932, Important)

* a flaw in IPv4 netfilter handling for the unlikely use of SNMP NAT
processing that allowed a remote user to cause a denial of service (crash)
or potential memory corruption (CVE-2006-2444, Moderate)

* a flaw in the DVD handling of the CDROM driver that could be used
together with a custom built USB device to gain root privileges
(CVE-2006-2935, Moderate)

* a flaw in the handling of O_DIRECT writes that allowed a local user
to cause a denial of service (memory consumption) (CVE-2004-2660, Low)

* a flaw in the SCTP chunk length handling that allowed a remote user to
cause a denial of service (crash) (CVE-2006-1858, Low)

* a flaw in the input handling of the ftdi_sio driver that allowed a local
user to cause a denial of service (memory consumption) (CVE-2006-2936, Low)

In addition a bugfix was added to enable a clean reboot for the IBM Pizzaro
machines.

Red Hat would like to thank Wei Wang of McAfee Avert Labs and Kirill
Korotaev for reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0617</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-2660</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2932</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2936</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3745</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060617"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060619" severity="medium">
    <xccdf:title>RHSA-2006:0619: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server available for free.

A bug was found in Apache where an invalid Expect header sent to the server
was returned to the user in an unescaped error message.  This could
allow an attacker to perform a cross-site scripting attack if a victim was
tricked into connecting to a site and sending a carefully crafted Expect
header.  (CVE-2006-3918)

While a web browser cannot be forced to send an arbitrary Expect
header by a third-party attacker, it was recently discovered that
certain versions of the Flash plugin can manipulate request headers.
If users running such versions can be persuaded to load a web page
with a malicious Flash applet, a cross-site scripting attack against
the server may be possible.

On Red Hat Enterprise Linux 3 and 4 systems, due to an unrelated issue in
the handling of malformed Expect headers, the page produced by the
cross-site scripting attack will only be returned after a timeout expires
(2-5 minutes by default) if not first canceled by the user.

Users of httpd should update to these erratum packages, which contain a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3918</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060619"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060633" severity="medium">
    <xccdf:title>RHSA-2006:0633: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Tavis Ormandy discovered several integer and buffer overflow flaws in the
way ImageMagick decodes XCF, SGI, and Sun bitmap graphic files. An attacker
could execute arbitrary code on a victim's machine if they were able to
trick the victim into opening a specially crafted image file.
(CVE-2006-3743, CVE-2006-3744, CVE-2006-4144)

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3743</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4144</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060633"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060634" severity="high">
    <xccdf:title>RHSA-2006:0634: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

An integer overflow flaw in the way the X.org server processes PCF files
was discovered. A malicious authorized client could exploit this issue to
cause a denial of service (crash) or potentially execute arbitrary code
with root privileges on the X.org server. (CVE-2006-3467)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3467</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060634"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060658" severity="low">
    <xccdf:title>RHSA-2006:0658: wireshark security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic.

Bugs were found in Wireshark's SCSI and SSCOP protocol dissectors. Ethereal
could crash or stop responding if it read a malformed packet off the
network. (CVE-2006-4330, CVE-2006-4333)

An off-by-one bug was found in the IPsec ESP decryption preference parser.
Ethereal could crash or stop responding if it read a malformed packet off
the network. (CVE-2006-4331)

Users of Wireshark or Ethereal should upgrade to these updated packages
containing Wireshark version 0.99.3, which is not vulnerable to these
issues.   These packages also fix a bug in the PAM configuration of the
Wireshark packages which prevented non-root users starting a capture.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4331</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4333</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060658"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060661" severity="high">
    <xccdf:title>RHSA-2006:0661: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and protocols.

Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5
signatures.  Where an RSA key with exponent 3 is used it may be possible
for an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly
verified by implementations that do not check for excess data in the RSA
exponentiation result of the signature.  

The Google Security Team discovered that OpenSSL is vulnerable to this
attack.  This issue affects applications that use OpenSSL to verify X.509
certificates as well as other uses of PKCS #1 v1.5.  (CVE-2006-4339)

This errata also resolves a problem where a customized ca-bundle.crt file
was overwritten when the openssl package was upgraded.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue.

Note: After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0661</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4339</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060661"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060663" severity="low">
    <xccdf:title>RHSA-2006:0663: ncompress security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ncompress package contains file compression and decompression
utilities, which are compatible with the original UNIX compress utility (.Z
file extensions).

Tavis Ormandy of the Google Security Team discovered a lack of bounds
checking in ncompress. An attacker could create a carefully crafted file
that could execute arbitrary code if uncompressed by a victim. (CVE-2006-1168)

In addition, two bugs that affected Red Hat Enterprise Linux 4 ncompress
packages were fixed:

* The display statistics and compression results in verbose mode were not
shown when operating on zero length files.

* An attempt to compress zero length files resulted in an unexpected return
code.

Users of ncompress are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0663</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1168</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060663"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060665" severity="high">
    <xccdf:title>RHSA-2006:0665: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported two integer overflow flaws in the way the X.org server
processed CID font files. A malicious authorized client could exploit this
issue to cause a denial of service (crash) or potentially execute arbitrary
code with root privileges on the X.org server. (CVE-2006-3739, CVE-2006-3740)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0665</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3740</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060665"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060667" severity="medium">
    <xccdf:title>RHSA-2006:0667: gzip security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gzip package contains the GNU gzip data compression program.

Tavis Ormandy of the Google Security Team discovered two denial of service
flaws in the way gzip expanded archive files. If a victim expanded a
specially crafted archive, it could cause the gzip executable to hang or
crash. (CVE-2006-4334, CVE-2006-4338)

Tavis Ormandy of the Google Security Team discovered several code execution
flaws in the way gzip expanded archive files. If a victim expanded a
specially crafted archive, it could cause the gzip executable to crash or
execute arbitrary code. (CVE-2006-4335, CVE-2006-4336, CVE-2006-4337)

Users of gzip should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0667</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4334</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4335</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4338</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060667"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060668" severity="medium">
    <xccdf:title>RHSA-2006:0668: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

A dynamic variable evaluation flaw was found in SquirrelMail.  Users who
have an account on a SquirrelMail server and are logged in could use this
flaw to overwrite variables which may allow them to read or write other
users' preferences or attachments.  (CVE-2006-4019)

Users of SquirrelMail should upgrade to this erratum package, which
contains SquirrelMail 1.4.8 to correct this issue.  This package also
contains a number of additional patches to correct various bugs.

Note: After installing this update, users are advised to restart their httpd
service to ensure that the new version functions correctly.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0668</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4019</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060668"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060669" severity="medium">
    <xccdf:title>RHSA-2006:0669: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A response-splitting issue was discovered in the PHP session handling.  If
a remote attacker can force a carefully crafted session identifier to be
used, a cross-site-scripting or response-splitting attack could be
possible.  (CVE-2006-3016)

A buffer overflow was discovered in the PHP sscanf() function.  If a script
used the sscanf() function with positional arguments in the format string,
a remote attacker sending a carefully crafted request could execute
arbitrary code as the 'apache' user.  (CVE-2006-4020)

An integer overflow was discovered in the PHP wordwrap() and str_repeat()
functions.  If a script running on a 64-bit server used either of these
functions on untrusted user data, a remote attacker sending a carefully
crafted request might be able to cause a heap overflow.  (CVE-2006-4482)

A buffer overflow was discovered in the PHP gd extension.  If a script was
set up to process GIF images from untrusted sources using the gd extension,
a remote attacker could cause a heap overflow.  (CVE-2006-4484)

An integer overflow was discovered in the PHP memory allocation handling. 
On 64-bit platforms, the "memory_limit" setting was not enforced correctly,
which could allow a denial of service attack by a remote user.  (CVE-2006-4486)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.  These packages also contain a
fix for a bug where certain input strings to the metaphone() function could
cause memory corruption.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060669"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060675" severity="high">
    <xccdf:title>RHSA-2006:0675: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Two flaws were found in the way Firefox processed certain regular
expressions.  A malicious web page could crash the browser or possibly
execute arbitrary code as the user running Firefox.  (CVE-2006-4565,
CVE-2006-4566)

A number of flaws were found in Firefox.  A malicious web page could crash
the browser or possibly execute arbitrary code as the user running Firefox.
 (CVE-2006-4571)

A flaw was found in the handling of Javascript timed events.  A malicious
web page could crash the browser or possibly execute arbitrary code as the
user running Firefox. (CVE-2006-4253)

Daniel Bleichenbacher recently described an implementation error in RSA
signature verification.  For RSA keys with exponent 3 it is possible for an
attacker to forge a signature that would be incorrectly verified by the NSS
library. Firefox as shipped trusts several root Certificate Authorities
that use exponent 3.  An attacker could have created a carefully crafted
SSL certificate which be incorrectly trusted when their site was visited by
a victim. (CVE-2006-4340)

A flaw was found in the Firefox auto-update verification system.  An
attacker who has the ability to spoof a victim's DNS could get Firefox to
download and install malicious code. In order to exploit this issue an
attacker would also need to get a victim to previously accept an
unverifiable certificate. (CVE-2006-4567)

Firefox did not properly prevent a frame in one domain from injecting
content into a sub-frame that belongs to another domain, which facilitates
website spoofing and other attacks (CVE-2006-4568)

Firefox did not load manually opened, blocked popups in the right domain
context, which could lead to cross-site scripting attacks.  In order to
exploit this issue an attacker would need to find a site which would frame
their malicious page and convince the user to manually open a blocked
popup. (CVE-2006-4569)

Users of Firefox are advised to upgrade to this update, which contains
Firefox version 1.5.0.7 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4253</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4340</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4571</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060675"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060676" severity="high">
    <xccdf:title>RHSA-2006:0676: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Two flaws were found in the way SeaMonkey processed certain regular
expressions.  A malicious web page could crash the browser or possibly
execute arbitrary code as the user running SeaMonkey.  (CVE-2006-4565,
CVE-2006-4566)

A flaw was found in the handling of Javascript timed events. A malicious
web page could crash the browser or possibly execute arbitrary code as the
user running SeaMonkey. (CVE-2006-4253)

Daniel Bleichenbacher recently described an implementation error in RSA
signature verification.  For RSA keys with exponent 3 it is possible for an
attacker to forge a signature that would be incorrectly verified by the NSS
library. SeaMonkey as shipped trusts several root Certificate Authorities
that use exponent 3.  An attacker could have created a carefully crafted
SSL certificate which be incorrectly trusted when their site was visited by
a victim. (CVE-2006-4340)

SeaMonkey did not properly prevent a frame in one domain from injecting
content into a sub-frame that belongs to another domain, which facilitates
website spoofing and other attacks (CVE-2006-4568)

A flaw was found in SeaMonkey Messenger triggered when a HTML message
contained a remote image pointing to a XBL script.  An attacker could have
created a carefully crafted message which would execute Javascript if
certain actions were performed on the email by the recipient, even if
Javascript was disabled. (CVE-2006-4570)

A number of flaws were found in SeaMonkey.  A malicious web page could
crash the browser or possibly execute arbitrary code as the user running
SeaMonkey.  (CVE-2006-4571)

Users of SeaMonkey or Mozilla are advised to upgrade to this update, which
contains SeaMonkey version 1.0.5 that corrects these issues.

For users of Red Hat Enterprise Linux 2.1 this SeaMonkey update obsoletes
Galeon.  Galeon was a web browser based on the Mozilla Gecko layout engine.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4253</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4340</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4570</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4571</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060676"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060677" severity="high">
    <xccdf:title>RHSA-2006:0677: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Two flaws were found in the way Thunderbird processed certain regular
expressions.  A malicious HTML email could cause a crash or possibly
execute arbitrary code as the user running Thunderbird.  (CVE-2006-4565,
CVE-2006-4566)

A flaw was found in the Thunderbird auto-update verification system.  An
attacker who has the ability to spoof a victim's DNS could get Firefox to
download and install malicious code. In order to exploit this issue an
attacker would also need to get a victim to previously accept an
unverifiable certificate. (CVE-2006-4567)

A flaw was found in the handling of Javascript timed events.  A malicious
HTML email could crash the browser or possibly execute arbitrary code as
the user running Thunderbird. (CVE-2006-4253)

Daniel Bleichenbacher recently described an implementation error in RSA
signature verification.  For RSA keys with exponent 3 it is possible for an
attacker to forge a signature that which would be incorrectly verified by
the NSS library.  (CVE-2006-4340)

A flaw was found in Thunderbird that triggered when a HTML message
contained a remote image pointing to a XBL script.  An attacker could have
created a carefully crafted message which would execute Javascript if
certain actions were performed on the email by the recipient, even if
Javascript was disabled.  (CVE-2006-4570)

A number of flaws were found in Thunderbird.  A malicious HTML email could
cause a crash or possibly execute arbitrary code as the user running
Thunderbird.  (CVE-2006-4571)

Users of Thunderbird are advised to upgrade to this update, which contains
Thunderbird version 1.5.0.7 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4253</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4340</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4570</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4571</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060677"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060680" severity="high">
    <xccdf:title>RHSA-2006:0680: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS Library provides support for cryptographic algorithms and
protocols such as TLS. GnuTLS includes libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5
signatures. Where an RSA key with exponent 3 is used it may be possible for
an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly
verified by implementations that do not check for excess data in the RSA
exponentiation result of the signature.

The core GnuTLS team discovered that GnuTLS is vulnerable to a variant of
the Bleichenbacker attack. This issue affects applications that use GnuTLS
to verify X.509 certificates as well as other uses of PKCS #1 v1.5.
(CVE-2006-4790)

In Red Hat Enterprise Linux 4, the GnuTLS library is only used by the
Evolution client when connecting to an Exchange server or when publishing
calendar information to a WebDAV server.

Users are advised to upgrade to these updated packages, which contain a
backported patch from the GnuTLS maintainers to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4790</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060680"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060689" severity="high">
    <xccdf:title>RHSA-2006:0689: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the SCTP support that allowed a local user to cause a denial of
service (crash) with a specific SO_LINGER value. (CVE-2006-4535, Important)

* a flaw in the hugepage table support that allowed a local user to cause a
denial of service (crash). (CVE-2005-4811, Important)

* a flaw in the mprotect system call that allowed setting write permission
for a read-only attachment of shared memory. (CVE-2006-2071, Moderate)

* a flaw in HID0[31] (en_attn) register handling on PowerPC 970 systems
that allowed a local user to cause a denial of service. (crash)
(CVE-2006-4093, Moderate)

* a flaw in the perfmon support of Itanium systems that allowed a local
user to cause a denial of service by consuming all file descriptors.
(CVE-2006-3741, Moderate)

* a flaw in the ATM subsystem. On systems with installed ATM hardware and
configured ATM support, a remote user could cause a denial of service
(panic) by accessing socket buffers memory after freeing them.
(CVE-2006-4997, Moderate)

* a flaw in the DVB subsystem. On systems with installed DVB hardware and
configured DVB support, a remote user could cause a denial of service
(panic) by sending a ULE SNDU packet with length of 0. (CVE-2006-4623, Low)

* an information leak in the network subsystem that possibly allowed a
local user to read sensitive data from kernel memory. (CVE-2006-0039, Low)

In addition, two bugfixes for the IPW-2200 wireless driver were included.
The first one ensures that wireless management applications correctly
identify IPW-2200 controlled devices, while the second fix ensures that
DHCP requests using the IPW-2200 operate correctly.

Red Hat would like to thank Olof Johansson, Stephane Eranian and Solar
Designer for reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4997</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060689"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060695" severity="high">
    <xccdf:title>RHSA-2006:0695: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and protocols.

Tavis Ormandy and Will Drewry of the Google Security Team discovered a
buffer overflow in the SSL_get_shared_ciphers() utility function.  An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer (CVE-2006-3738).  Few applications make use
of this vulnerable function and generally it is used only when applications
are compiled for debugging.

Tavis Ormandy and Will Drewry of the Google Security Team discovered a 
flaw in the SSLv2 client code.  When a client application used OpenSSL to
create an SSLv2 connection to a malicious server, that server could cause
the client to crash.  (CVE-2006-4343)

Dr S. N. Henson of the OpenSSL core team and Open Network Security recently
developed an ASN.1 test suite for NISCC (www.niscc.gov.uk) which uncovered
denial of service vulnerabilities: 

* Certain public key types can take disproportionate amounts of time to
process, leading to a denial of service.  (CVE-2006-2940)

* During parsing of certain invalid ASN.1 structures an error condition was
mishandled.  This can result in an infinite loop which consumed system
memory (CVE-2006-2937).  This issue does not affect the OpenSSL version
distributed in Red Hat Enterprise Linux 2.1.

These vulnerabilities can affect applications which use OpenSSL to parse
ASN.1 data from untrusted sources, including SSL servers which enable
client authentication and S/MIME applications.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues.

Note: After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4343</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060695"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060697" severity="high">
    <xccdf:title>RHSA-2006:0697: openssh security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

Mark Dowd discovered a signal handler race condition in the OpenSSH sshd
server. A remote attacker could possibly leverage this flaw to cause a
denial of service (crash). (CVE-2006-5051) The OpenSSH project believes the
likelihood of successful exploitation leading to arbitrary code execution
appears remote. However, the Red Hat Security Response Team have not yet
been able to verify this claim due to lack of upstream vulnerability
information. We are therefore including a fix for this flaw and have rated
it important security severity in the event our continued investigation
finds this issue to be exploitable.

Tavis Ormandy of the Google Security Team discovered a denial of service
bug in the OpenSSH sshd server. A remote attacker can send a specially
crafted SSH-1 request to the server causing sshd to consume a large
quantity of CPU resources. (CVE-2006-4924)

All users of openssh should upgrade to these updated packages, which
contain backported patches that resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0697</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4924</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5051</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060697"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060713" severity="high">
    <xccdf:title>RHSA-2006:0713: python security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming language.

A flaw was discovered in the way that the Python repr() function handled
UTF-32/UCS-4 strings.  If an application written in Python used the repr()
function on untrusted data, this could lead to a denial of service or
possibly allow the execution of arbitrary code with the privileges of the
Python application.  (CVE-2006-4980)

In addition, this errata fixes a regression in the SimpleXMLRPCServer
backport for Red Hat Enterprise Linux 3 that was introduced with RHSA-2005:109.

Users of Python should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4980</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060713"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060719" severity="medium">
    <xccdf:title>RHSA-2006:0719: nss_ldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>nss_ldap is a set of C library extensions that allow X.500 and LDAP
directory servers to be used as primary sources for aliases, ethers,
groups, hosts, networks, protocols, users, RPCs, services, and shadow
passwords.

A flaw was found in the way nss_ldap handled a PasswordPolicyResponse
control sent by an LDAP server. If an LDAP server responded to an
authentication request with a PasswordPolicyResponse control, it was
possible for an application using nss_ldap to improperly authenticate
certain users. (CVE-2006-5170)

This flaw was only exploitable within applications which did not properly
process nss_ldap error messages. Only xscreensaver is currently known to
exhibit this behavior.

All users of nss_ldap should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0719</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5170</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060719"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060720" severity="high">
    <xccdf:title>RHSA-2006:0720: kdelibs security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs package provides libraries for the K Desktop Environment (KDE).
 Qt is a GUI software toolkit for the X Window System.

An integer overflow flaw was found in the way Qt handled pixmap images. 
The KDE khtml library uses Qt in such a way that untrusted parameters could
be passed to Qt, triggering the overflow.  An attacker could for example
create a malicious web page that when viewed by a victim in the Konqueror
browser would cause Konqueror to crash or possibly execute arbitrary code
with the privileges of the victim.  (CVE-2006-4811)

Users of KDE should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060720"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060725" severity="medium">
    <xccdf:title>RHSA-2006:0725: qt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

An integer overflow flaw was found in the way Qt handled certain pixmap
images. If an application linked against Qt created a pixmap image in a
certain way, it could lead to a denial of service or possibly allow the
execution of arbitrary code. (CVE-2006-4811)

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060725"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060726" severity="medium">
    <xccdf:title>RHSA-2006:0726: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic.

Several flaws were found in Wireshark's HTTP, WBXML, LDAP, and XOT protocol
dissectors. Wireshark could crash or stop responding if it read a malformed
packet off the network. (CVE-2006-4805, CVE-2006-5468, CVE-2006-5469,
CVE-2006-5740)

A single NULL byte heap based buffer overflow was found in Wireshark's MIME
Multipart dissector. Wireshark could crash or possibly execute arbitrary
arbitrary code as the user running Wireshark. (CVE-2006-4574)

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.4, which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0726</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5740</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060726"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060727" severity="medium">
    <xccdf:title>RHSA-2006:0727: texinfo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Texinfo is a documentation system that can produce both online information
and printed output from a single source file.

A buffer overflow flaw was found in Texinfo's texindex command. An attacker
could construct a carefully crafted Texinfo file that could cause texindex
to crash or possibly execute arbitrary code when opened. (CVE-2006-4810)

A flaw was found in the way Texinfo's texindex command creates temporary
files. A local user could leverage this flaw to overwrite files the user
executing texindex has write access to. (CVE-2005-3011)

Users of Texinfo should upgrade to these updated packages which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4810</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060727"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060729" severity="medium">
    <xccdf:title>RHSA-2006:0729: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for object-oriented programming.

A flaw was discovered in the way Ruby's CGI module handles certain
multipart/form-data MIME data. If a remote attacker sends a specially
crafted multipart-form-data request, it is possible to cause the ruby
CGI script to enter an infinite loop, causing a denial of service.
(CVE-2006-5467)

Users of Ruby should upgrade to these updated packages which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5467</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060729"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060730" severity="high">
    <xccdf:title>RHSA-2006:0730: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

The Hardened-PHP Project discovered an overflow in the PHP htmlentities()
and htmlspecialchars() routines.  If a PHP script used the vulnerable
functions to parse UTF-8 data, a remote attacker sending a carefully
crafted request could trigger the overflow and potentially execute
arbitrary code as the 'apache' user. (CVE-2006-5465) 

Users of PHP should upgrade to these updated packages which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5465</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060730"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060733" severity="high">
    <xccdf:title>RHSA-2006:0733: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause Firefox to crash or execute
arbitrary code as the user running Firefox. (CVE-2006-5463, CVE-2006-5747,
CVE-2006-5748)

Several flaws were found in the way Firefox renders web pages. A malicious
web page could cause the browser to crash or possibly execute arbitrary
code as the user running Firefox. (CVE-2006-5464) 

A flaw was found in the way Firefox verifies RSA signatures. For RSA keys
with exponent 3 it is possible for an attacker to forge a signature that
would be incorrectly verified by the NSS library. Firefox as shipped trusts
several root Certificate Authorities that use exponent 3. An attacker could
have created a carefully crafted SSL certificate which be incorrectly
trusted when their site was visited by a victim. This flaw was previously
thought to be fixed in Firefox 1.5.0.7, however Ulrich Kuehn discovered the
fix was incomplete (CVE-2006-5462)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.8 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5748</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060733"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060734" severity="high">
    <xccdf:title>RHSA-2006:0734: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause SeaMonkey to crash or
execute arbitrary code as the user running SeaMonkey. (CVE-2006-5463,
CVE-2006-5747, CVE-2006-5748)

Several flaws were found in the way SeaMonkey renders web pages. A
malicious web page could cause the browser to crash or possibly execute
arbitrary code as the user running SeaMonkey. (CVE-2006-5464)

A flaw was found in the way SeaMonkey verifies RSA signatures. For RSA keys
with exponent 3 it is possible for an attacker to forge a signature that
would be incorrectly verified by the NSS library. SeaMonkey as shipped
trusts several root Certificate Authorities that use exponent 3. An
attacker could have created a carefully crafted SSL certificate which be
incorrectly trusted when their site was visited by a victim. This flaw was
previously thought to be fixed in SeaMonkey 1.0.5, however Ulrich Kuehn
discovered the fix was incomplete (CVE-2006-5462)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contains SeaMonkey version 1.0.6 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5748</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060734"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060735" severity="high">
    <xccdf:title>RHSA-2006:0735: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processes certain malformed
Javascript code. A malicious HTML mail message could cause the execution of
Javascript code in such a way that could cause Thunderbird to crash or
execute arbitrary code as the user running Thunderbird. (CVE-2006-5463,
CVE-2006-5747, CVE-2006-5748)

Several flaws were found in the way Thunderbird renders HTML mail messages.
A malicious HTML mail message could cause the mail client to crash or
possibly execute arbitrary code as the user running Thunderbird.
(CVE-2006-5464)

A flaw was found in the way Thunderbird verifies RSA signatures. For RSA
keys with exponent 3 it is possible for an attacker to forge a signature
that would be incorrectly verified by the NSS library. Thunderbird as
shipped trusts several root Certificate Authorities that use exponent 3. An
attacker could have created a carefully crafted SSL certificate which would
be incorrectly trusted when their site was visited by a victim. This flaw
was previously thought to be fixed in Thunderbird 1.5.0.7, however Ulrich
Kuehn discovered the fix was incomplete (CVE-2006-5462)

Users of Thunderbird are advised to upgrade to this update, which contains
Thunderbird version 1.5.0.8 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5748</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060735"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060738" severity="low">
    <xccdf:title>RHSA-2006:0738: openssh security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

An authentication flaw was found in OpenSSH's privilege separation monitor.
If it ever becomes possible to alter the behavior of the unprivileged
process when OpenSSH is using privilege separation, an attacker may then be
able to login without possessing proper credentials. (CVE-2006-5794)

Please note that this flaw by itself poses no direct threat to OpenSSH
users. Without another security flaw that could allow an attacker to alter
the behavior of OpenSSH's unprivileged process, this flaw cannot be
exploited. There are currently no known flaws to exploit this behavior. 
However, we have decided to issue this erratum to fix this flaw to reduce
the security impact if an unprivileged process flaw is ever found.

Users of openssh should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5794</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060738"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060742" severity="high">
    <xccdf:title>RHSA-2006:0742: elinks security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Elinks is a text mode Web browser used from the command line that supports
rendering modern web pages.

An arbitrary file access flaw was found in the Elinks SMB protocol handler.
A malicious web page could have caused Elinks to read or write files with
the permissions of the user running Elinks. (CVE-2006-5925)

All users of Elinks are advised to upgrade to this updated package, which
resolves this issue by removing support for the SMB protocol from Elinks.

Note: this issue did not affect the Elinks package shipped with Red Hat
Enterprise Linux 3, or the Links package shipped with Red Hat Enterprise
Linux 2.1.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5925</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060742"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060746" severity="low">
    <xccdf:title>RHSA-2006:0746: mod_auth_kerb security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>mod_auth_kerb is module for the Apache HTTP Server designed to
provide Kerberos authentication over HTTP.

An off by one flaw was found in the way mod_auth_kerb handles certain
Kerberos authentication messages. A remote client could send a specially
crafted authentication request which could crash an httpd child process
(CVE-2006-5989).

A bug in the handling of multiple realms configured using the
"KrbAuthRealms" directive has also been fixed.

All users of mod_auth_kerb should upgrade to these updated packages, which
contain backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5989</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060746"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060749" severity="medium">
    <xccdf:title>RHSA-2006:0749: tar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive. 

Teemu Salmela discovered a path traversal flaw in the way GNU tar extracted
archives. A malicious user could create a tar archive that could write to
arbitrary files to which the user running GNU tar has write access.
(CVE-2006-6097)

Users of tar should upgrade to this updated package, which contains a
replacement backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6097</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060749"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060754" severity="high">
    <xccdf:title>RHSA-2006:0754: gnupg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

Tavis Ormandy discovered a stack overwrite flaw in the way GnuPG decrypts
messages. An attacker could create carefully crafted message that could cause
GnuPG to execute arbitrary code if a victim attempts to decrypt the message.
(CVE-2006-6235)

A heap based buffer overflow flaw was found in the way GnuPG constructs
messages to be written to the terminal during an interactive session. An
attacker could create a carefully crafted message which with user interaction
could cause GnuPG to execute arbitrary code with the permissions of the
user running GnuPG. (CVE-2006-6169)

All users of GnuPG are advised to upgrade to this updated package, which
contains a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0754</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060754"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060758" severity="high">
    <xccdf:title>RHSA-2006:0758: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause Firefox to crash or execute
arbitrary code as the user running Firefox. (CVE-2006-6498, CVE-2006-6501,
CVE-2006-6502, CVE-2006-6503, CVE-2006-6504)

Several flaws were found in the way Firefox renders web pages. A malicious
web page could cause the browser to crash or possibly execute arbitrary
code as the user running Firefox. (CVE-2006-6497)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.9 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0758</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6504</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060758"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060759" severity="high">
    <xccdf:title>RHSA-2006:0759: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause SeaMonkey to crash or
execute arbitrary code as the user running SeaMonkey. (CVE-2006-6498,
CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504)

Several flaws were found in the way SeaMonkey renders web pages. A
malicious web page could cause the browser to crash or possibly execute
arbitrary code as the user running SeaMonkey. (CVE-2006-6497)

A heap based buffer overflow flaw was found in the way SeaMonkey Mail
parses the Content-Type mail header. A malicious mail message could cause
the SeaMonkey Mail client to crash or possibly execute arbitrary code as
the user running SeaMonkey Mail. (CVE-2006-6505)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain SeaMonkey version 1.0.7 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0759</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6505</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060759"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20060760" severity="high">
    <xccdf:title>RHSA-2006:0760: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause Thunderbird to crash or
execute arbitrary code as the user running Thunderbird.  JavaScript support
is disabled by default in Thunderbird; this issue is not exploitable
without enabling JavaScript. (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502,
CVE-2006-6503, CVE-2006-6504)

Several flaws were found in the way Thunderbird renders web pages. A
malicious web page could cause the browser to crash or possibly execute
arbitrary code as the user running Thunderbird. (CVE-2006-6497)

A heap based buffer overflow flaw was found in the way Thunderbird parses
the Content-Type mail header. A malicious mail message could cause the
Thunderbird client to crash or possibly execute arbitrary code as the user
running Thunderbird. (CVE-2006-6505) 

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.9 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2006:0760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6505</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20060760"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070001" severity="high">
    <xccdf:title>RHSA-2007:0001: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Several integer overflow bugs were found in the OpenOffice.org WMF file
processor. An attacker could create a carefully crafted WMF file that could
cause OpenOffice.org to execute arbitrary code when the file was opened by
a victim. (CVE-2006-5870)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix for this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5870</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070001"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070003" severity="high">
    <xccdf:title>RHSA-2007:0003: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported three integer overflow flaws in the X.org Render and DBE
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the X.org server. (CVE-2006-6101, CVE-2006-6102, CVE-2006-6103)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6103</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070008" severity="medium">
    <xccdf:title>RHSA-2007:0008: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-BUS is a system for sending messages between applications. It is used
both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Kimmo Hämäläinen discovered a flaw in the way D-BUS processes certain
messages. It is possible for a local unprivileged D-BUS process to disrupt
the ability of another D-BUS process to receive messages. (CVE-2006-6107)

Users of dbus are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6107</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070011" severity="medium">
    <xccdf:title>RHSA-2007:0011: libgsf security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNOME Structured File Library is a utility library for reading and
writing structured file formats.

A heap based buffer overflow flaw was found in the way GNOME Structured
File Library processes and certain OLE documents. If an person opened a
specially crafted OLE file, it could cause the client application to crash or
execute arbitrary code. (CVE-2006-4514)

Users of GNOME Structured File Library should upgrade to these updated
packages, which contain a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4514</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070011"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070014" severity="high">
    <xccdf:title>RHSA-2007:0014: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below: 

* a flaw in the get_fdb_entries function of the network bridging support
that allowed a local user to cause a denial of service (crash) or allow a
potential privilege escalation (CVE-2006-5751, Important)

* an information leak in the _block_prepare_write function that allowed a
local user to read kernel memory (CVE-2006-4813, Important)

* an information leak in the copy_from_user() implementation on s390 and
s390x platforms that allowed a local user to read kernel memory
(CVE-2006-5174, Important)

* a flaw in the handling of /proc/net/ip6_flowlabel that allowed a local
user to cause a denial of service (infinite loop) (CVE-2006-5619, Important)

* a flaw in the AIO handling that allowed a local user to cause a denial of
 service (panic) (CVE-2006-5754, Important)

* a race condition in the mincore system core that allowed a local user to
cause a denial of service (system hang) (CVE-2006-4814, Moderate)

* a flaw in the ELF handling on ia64 and sparc architectures which
triggered a cross-region memory mapping and allowed a local user to cause a
denial of service (CVE-2006-4538, Moderate)

* a flaw in the dev_queue_xmit function of the network subsystem that
allowed a local user to cause a denial of service (data corruption)
(CVE-2006-6535, Moderate)

* a flaw in the handling of CAPI messages over Bluetooth that allowed a
remote system to cause a denial of service or potential code execution.
This flaw is only exploitable if a privileged user establishes a connection
to a malicious remote device (CVE-2006-6106, Moderate)

* a flaw in the listxattr system call that allowed a local user to cause a
denial of service (data corruption) or potential privilege escalation. To
successfully exploit this flaw the existence of a bad inode is required
first (CVE-2006-5753, Moderate)

* a flaw in the __find_get_block_slow function that allowed a local
privileged user to cause a denial of service (CVE-2006-5757, Low)

* various flaws in the supported filesystems that allowed a local
privileged user to cause a denial of service (CVE-2006-5823, CVE-2006-6053,
CVE-2006-6054, CVE-2006-6056, Low)

In addition to the security issues described above, fixes for the following
bugs were included:

* initialization error of the tg3 driver with some BCM5703x network card

* a memory leak in the audit subsystem

* x86_64 nmi watchdog timeout is too short

* ext2/3 directory reads fail intermittently

Red Hat would like to thank Dmitriy Monakhov and Kostantin Khorenko for
reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architecture and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5754</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5757</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6106</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6535</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070014"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070015" severity="medium">
    <xccdf:title>RHSA-2007:0015: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Several security flaws were discovered in the way ImageMagick decodes DCM,
PALM, and SGI graphic files.  An attacker may be able to execute arbitrary
code on a victim's machine if they were able to trick the victim into
opening a specially crafted image file (CVE-2006-5456, CVE-2006-5868).

A heap overflow flaw was found in ImageMagick.  An attacker may be able to
execute arbitrary code on a victim's machine if they were able to trick the
victim into opening a specially crafted file (CVE-2006-2440).  This issue
only affected the version of ImageMagick distributed with Red Hat
Enterprise Linux 4.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2440</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5868</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070015"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070018" severity="medium">
    <xccdf:title>RHSA-2007:0018: fetchmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Fetchmail is a remote mail retrieval and forwarding utility.

A denial of service flaw was found when Fetchmail was run in multidrop
mode.  A malicious mail server could send a message without headers which
would cause Fetchmail to crash (CVE-2005-4348).  This issue did not affect
the version of Fetchmail shipped with Red Hat Enterprise Linux 2.1 or 3.

A flaw was found in the way Fetchmail used TLS encryption to connect to
remote hosts.  Fetchmail provided no way to enforce the use of TLS
encryption and would not authenticate POP3 protocol connections properly
(CVE-2006-5867).  This update corrects this issue by enforcing TLS
encryption when the "sslproto" configuration directive is set to "tls1".  

Users of Fetchmail should update to these packages, which contain 
backported patches to correct these issues.

Note: This update may break configurations which assumed that Fetchmail
would use plain-text authentication if TLS encryption is not supported by
the POP3 server even if the "sslproto" directive is set to "tls1".  If you
are using a custom configuration that depended on this behavior you will
need to modify your configuration appropriately after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5867</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070018"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070019" severity="medium">
    <xccdf:title>RHSA-2007:0019: gtk2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System.

A bug was found in the way the gtk2 GdkPixbufLoader() function processed
invalid input.   Applications linked against gtk2 could crash if they
loaded a malformed image file. (CVE-2007-0010)

Users of gtk2 are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0010</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070019"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070022" severity="medium">
    <xccdf:title>RHSA-2007:0022: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

Several cross-site scripting bugs were discovered in SquirrelMail.  An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL.  (CVE-2006-6142) 

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct these issues. 

Notes:
- After installing this update, users are advised to restart their
httpd service to ensure that the updated version functions correctly.
- config.php should NOT be modified, please modify config_local.php instead.
- Known Bug: The configuration generator may potentially produce bad
options that interfere with the operation of this application.  Applying
specific config changes to config_local.php manually is recommended.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6142</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070022"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070033" severity="high">
    <xccdf:title>RHSA-2007:0033: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

iDefense reported an integer overflow flaw in libwpd, a library used
internally to OpenOffice.org for handling Word Perfect documents.  An
attacker could create a carefully crafted Word Perfect file that could
cause OpenOffice.org to crash or possibly execute arbitrary code if the
file was opened by a victim. (CVE-2007-1466)

John Heasman discovered a stack overflow in the StarCalc parser in
OpenOffice.org.  An attacker could create a carefully crafted StarCalc file
that could cause OpenOffice.org to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way OpenOffice.org handled hyperlinks.  An
attacker could create an OpenOffice.org document which could run commands
if a victim opened the file and clicked on a malicious hyperlink. 
(CVE-2007-0239)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.

Red Hat would like to thank Fridrich Štrba for alerting us to the issue
CVE-2007-1466 and providing a patch, and John Heasman for
CVE-2007-0238.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0239</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1466</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070033"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070044" severity="medium">
    <xccdf:title>RHSA-2007:0044: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses.  On
servers that had enabled DNSSEC validation, this could allow an remote
attacker to cause a denial of service.  (CVE-2007-0494)

For users of Red Hat Enterprise Linux 3, the previous BIND update caused an
incompatible change to the default configuration that resulted in rndc not
sharing the key with the named daemon. This update corrects this bug and
restores the behavior prior to that update.

Updating the bind package in Red Hat Enterprise Linux 3 could result in
nonfunctional configuration in case the bind-libs package was not updated.
This update corrects this bug by adding the correct dependency on bind-libs.

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070044"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070055" severity="high">
    <xccdf:title>RHSA-2007:0055: libwpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libwpd is a library for reading and converting Word Perfect documents.

iDefense reported several overflow bugs in libwpd.  An attacker could
create a carefully crafted Word Perfect file that could cause an
application linked with libwpd, such as OpenOffice, to crash or possibly
execute arbitrary code if the file was opened by a victim. (CVE-2007-0002)

All users are advised to upgrade to these updated packages, which contain a
backported fix for this issue.

Red Hat would like to thank Fridrich Štrba for alerting us to these issues
and providing a patch.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1466</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070055"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070057" severity="medium">
    <xccdf:title>RHSA-2007:0057: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses. On
servers that had enabled DNSSEC validation, this could allow a remote
attacker to cause a denial of service. (CVE-2007-0494)

A use-after-free flaw was found in BIND. On servers that have recursion
enabled, this could allow a remote attacker to cause a denial of service. 
(CVE-2007-0493)

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070057"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070060" severity="medium">
    <xccdf:title>RHSA-2007:0060: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources.
(CVE-2007-0452)

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0452</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070060"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070061" severity="medium">
    <xccdf:title>RHSA-2007:0061: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources
(CVE-2007-0452).

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0452</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070061"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070064" severity="medium">
    <xccdf:title>RHSA-2007:0064: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw was found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit this issue (CVE-2007-0555).

A denial of service flaw was found affecting the PostgreSQL server running
on Red Hat Enterprise Linux 4 systems. An authenticated user could execute
an SQL command which could crash the PostgreSQL server. (CVE-2006-5540)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 7.4.16 or 7.3.18, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070064"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070065" severity="medium">
    <xccdf:title>RHSA-2007:0065: bluez-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The bluez-utils package contains Bluetooth daemons and utilities.

A flaw was found in the Bluetooth HID daemon (hidd). A remote attacker
would have been able to inject keyboard and mouse events via a Bluetooth
connection without any authorization. (CVE-2006-6899)

Note that Red Hat Enterprise Linux does not come with the Bluetooth HID
daemon enabled by default.

Users of bluez-utils are advised to upgrade to these updated packages, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6899</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070065"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070066" severity="low">
    <xccdf:title>RHSA-2007:0066: wireshark security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's LLT, IEEE 802.11,
http, and tcp protocol dissectors. It was possible for Wireshark to crash
or stop responding if it read a malformed packet off the network.
(CVE-2007-0456, CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.5, which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0459</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070066"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070068" severity="medium">
    <xccdf:title>RHSA-2007:0068: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

Two flaws were found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit these issues (CVE-2007-0555,
CVE-2007-0556).

Several denial of service flaws were found in the PostgreSQL server.  An
authenticated user could execute certain SQL commands which could crash the
PostgreSQL server (CVE-2006-5540, CVE-2006-5541, CVE-2006-5542).

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 8.1.8 which corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0556</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070068"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070069" severity="high">
    <xccdf:title>RHSA-2007:0069: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

John Heasman discovered a stack overflow in the StarCalc parser in
OpenOffice.  An attacker could create a carefully crafted StarCalc file
that could cause OpenOffice.org to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way OpenOffice.org handled hyperlinks.  An
attacker could create an OpenOffice.org document which could run commands
if a victim opened the file and clicked on a malicious hyperlink. 
(CVE-2007-0239)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0239</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070069"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070074" severity="high">
    <xccdf:title>RHSA-2007:0074: spamassassin security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

A flaw was found in the way SpamAssassin processes HTML email containing
URIs. A carefully crafted mail message could cause SpamAssassin to consume
significant resources. If a number of these messages are sent, this could
lead to a denial of service, potentially delaying or preventing the
delivery  of email.
(CVE-2007-0451)

Users of SpamAssassin should upgrade to these updated packages which
contain version 3.1.8 which is not vulnerable to these issues.  

This is an upgrade from SpamAssassin version 3.0.6 to 3.1.8, which contains
many bug fixes and spam detection enhancements. Further details are
available in the SpamAssassin 3.1 changelog and upgrade guide.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0451</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070074"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070075" severity="high">
    <xccdf:title>RHSA-2007:0075: spamassassin security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

A flaw was found in the way SpamAssassin processes HTML email containing
URIs. A carefully crafted mail message could cause SpamAssassin to consume
significant resources. If a number of these messages are sent, this could
lead to a denial of service, potentially delaying or preventing the
delivery  of email. (CVE-2007-0451)

Users of SpamAssassin should upgrade to these updated packages which
contain version 3.1.8 which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0451</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070075"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070076" severity="high">
    <xccdf:title>RHSA-2007:0076: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A number of buffer overflow flaws were found in the PHP session extension,
the str_replace() function, and the imap_mail_compose() function.
If very long strings under the control of an attacker are passed to the
str_replace() function then an integer overflow could occur in memory
allocation.  If a script uses the imap_mail_compose() function to create a
new MIME message based on an input body from an untrusted source, it could
result in a heap overflow.  An attacker who is able to access a PHP
application affected by any these issues could trigger these flaws and
possibly execute arbitrary code as the 'apache' user. (CVE-2007-0906)

If unserializing untrusted data on 64-bit platforms, the zend_hash_init()
function can be forced to enter an infinite loop, consuming CPU resources
for a limited length of time, until the script timeout alarm aborts
execution of the script. (CVE-2007-0988)

If the wddx extension is used to import WDDX data from an untrusted source,
certain WDDX input packets may allow a random portion of heap memory to be
exposed. (CVE-2007-0908)

If the odbc_result_all() function is used to display data from a database,
and the contents of the database table are under the control of an
attacker, a format string vulnerability is possible which could lead to the
execution of arbitrary code.  (CVE-2007-0909)

A one byte memory read will always occur before the beginning of a buffer,
which could be triggered for example by any use of the header() function in
a script.  However it is unlikely that this would have any effect.
(CVE-2007-0907)

Several flaws in PHP could allows attackers to "clobber" certain
super-global variables via unspecified vectors. (CVE-2007-0910)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.

Red Hat would like to thank Stefan Esser for his help diagnosing these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0909</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1825</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070076"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070077" severity="high">
    <xccdf:title>RHSA-2007:0077: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A malicious web page could execute JavaScript code in such
a way that may result in SeaMonkey crashing or executing arbitrary code as
the user running SeaMonkey. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way SeaMonkey
processed certain malformed web pages. A malicious web page could display
misleading information which may result in a user unknowingly divulging
sensitive information such as a password. (CVE-2006-6077, CVE-2007-0995,
CVE-2007-0996)

A flaw was found in the way SeaMonkey cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way SeaMonkey displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way SeaMonkey displayed blocked popup windows.
If a user can be convinced to open a blocked popup, it is possible to read
arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
SeaMonkey. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way SeaMonkey handled the "location.hostname" value
during certain browser domain checks. This flaw could allow a malicious web
site to set domain cookies for an arbitrary site, or possibly perform an
XSS attack. (CVE-2007-0981)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain SeaMonkey version 1.0.8 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070077"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070078" severity="high">
    <xccdf:title>RHSA-2007:0078: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML mail message could execute JavaScript
code in such a way that may result in Thunderbird crashing or executing
arbitrary code as the user running Thunderbird. JavaScript support is
disabled by default in Thunderbird; these issues are not exploitable unless
the user has enabled JavaScript. (CVE-2007-0775, CVE-2007-0777, CVE-2007-1092)

A flaw was found in the way Thunderbird processed text/enhanced and
text/richtext formatted mail message. A specially crafted mail message
could execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2007-1282)

Several cross-site scripting (XSS) flaws were found in the way Thunderbird
processed certain malformed HTML mail messages. A malicious HTML mail
message could display misleading information which may result in a user
unknowingly divulging sensitive information such as a password.
(CVE-2006-6077, CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Thunderbird cached web content on the local
disk. A malicious HTML mail message may be able to inject arbitrary HTML
into a browsing session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious HTML mail message could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Thunderbird displayed blocked popup
windows. If a user can be convinced to open a blocked popup, it is possible
to read arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Thunderbird. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Thunderbird handled the "location.hostname"
value during certain browser domain checks. This flaw could allow a
malicious HTML mail message to set domain cookies for an arbitrary site, or
possibly perform an XSS attack. (CVE-2007-0981)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.10 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070078"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070079" severity="high">
    <xccdf:title>RHSA-2007:0079: Firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A malicious web page could execute JavaScript code in such
a way that may result in Firefox crashing or executing arbitrary code as
the user running Firefox. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way Firefox
processed certain malformed web pages. A malicious web page could display
misleading information which may result in a user unknowingly divulging
sensitive information such as a password. (CVE-2006-6077, CVE-2007-0995,
CVE-2007-0996)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Firefox displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Firefox displayed blocked popup windows. If
a user can be convinced to open a blocked popup, it is possible to read
arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Firefox. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Firefox handled the "location.hostname" value
during certain browser domain checks. This flaw could allow a malicious web
site to set domain cookies for an arbitrary site, or possibly perform an
XSS attack. (CVE-2007-0981)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.10 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1092</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070079"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070082" severity="high">
    <xccdf:title>RHSA-2007:0082: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A number of buffer overflow flaws were found in the PHP session extension;
the str_replace() function; and the imap_mail_compose() function. If very
long strings were passed to the str_replace() function, an integer
overflow could occur in memory allocation. If a script used the
imap_mail_compose() function to create a new MIME message based on an
input body from an untrusted source, it could result in a heap overflow.
An attacker with access to a PHP application affected by any these issues
could trigger the flaws and possibly execute arbitrary code as the
'apache' user. (CVE-2007-0906)

When unserializing untrusted data on 64-bit platforms, the
zend_hash_init() function could be forced into an infinite loop, consuming
CPU resources for a limited time, until the script timeout alarm aborted
execution of the script. (CVE-2007-0988)

If the wddx extension was used to import WDDX data from an untrusted
source, certain WDDX input packets could expose a random portion of heap
memory. (CVE-2007-0908)

If the odbc_result_all() function was used to display data from a
database, and the database table contents were under an attacker's
control, a format string vulnerability was possible which could allow
arbitrary code execution. (CVE-2007-0909)

A one byte memory read always occurs before the beginning of a buffer.
This could be triggered, for example, by any use of the header() function
in a script. However it is unlikely that this would have any effect.
(CVE-2007-0907)

Several flaws in PHP could allow attackers to "clobber" certain
super-global variables via unspecified vectors. (CVE-2007-0910)

An input validation bug allowed a remote attacker to trigger a denial of
service attack by submitting an input variable with a deeply-nested-array.
(CVE-2007-1285)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0909</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1825</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070082"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070085" severity="high">
    <xccdf:title>RHSA-2007:0085: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for two security issues:

* a flaw in the key serial number collision avoidance algorithm of the
keyctl subsystem that allowed a local user to cause a denial of service
(CVE-2007-0006, Important)

* a flaw in the file watch implementation of the audit subsystems that
allowed a local user to cause a denial of service (panic). To exploit this
flaw a privileged user must have previously created a watch for a file 
(CVE-2007-0001, Moderate)

In addition to the security issues described above, a fix for the SCTP
subsystem to address a system crash which may be experienced in Telco
environments has been included.

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels to
the packages associated with their machine architecture and configurations
as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0006</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070085"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070086" severity="high">
    <xccdf:title>RHSA-2007:0086: gnomemeeting security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnomeMeeting is a tool to communicate with video and audio over the Internet.

A format string flaw was found in the way GnomeMeeting processes certain
messages. If a user is running GnomeMeeting, a remote attacker who can
connect to GnomeMeeting could trigger this flaw and potentially execute
arbitrary code with the privileges of the user. (CVE-2007-1007)

Users of GnomeMeeting should upgrade to these updated packages which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1007</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070086"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070087" severity="high">
    <xccdf:title>RHSA-2007:0087: ekiga security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ekiga is a tool to communicate with video and audio over the Internet.

Format string flaws were found in the way Ekiga processes certain messages.
If a user is running Ekiga, a remote attacker who can connect to Ekiga
could trigger this flaw and potentially execute arbitrary code with the
privileges of the user. (CVE-2007-0999, CVE-2007-1006)

Users of Ekiga should upgrade to these updated packages which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1006</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070087"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070095" severity="high">
    <xccdf:title>RHSA-2007:0095: krb5 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the username handling of the MIT krb5 telnet daemon
(telnetd).  A remote attacker who can access the telnet port of a target
machine could log in as root without requiring a password.  (CVE-2007-0956)

Note that the krb5 telnet daemon is not enabled by default in any version
of Red Hat Enterprise Linux.  In addition, the default firewall rules block
remote access to the telnet port.  This flaw does not affect the telnet
daemon distributed in the telnet-server package.

For users who have enabled the krb5 telnet daemon and have it accessible
remotely, this update should be applied immediately.  

Whilst we are not aware at this time that the flaw is being actively
exploited, we have confirmed that the flaw is very easily exploitable.

This update also fixes two additional security issues:

Buffer overflows were found which affect the Kerberos KDC and the kadmin
server daemon.  A remote attacker who can access the KDC could exploit this
bug to run arbitrary code with the privileges of the KDC or kadmin server
processes.  (CVE-2007-0957)

A double-free flaw was found in the GSSAPI library used by the kadmin
server daemon.  Red Hat Enterprise Linux 4 and 5 contain checks within
glibc that detect double-free flaws. Therefore, on Red Hat Enterprise Linux
4 and 5 successful exploitation of this issue can only lead to a denial of
service.  Applications which use this library in earlier releases of Red
Hat Enterprise Linux may also be affected.  (CVE-2007-1216)

All users are advised to update to these erratum packages which contain a
backported fix to correct these issues.

Red Hat would like to thank MIT and iDefense for reporting these
vulnerabilities.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1216</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070095"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070097" severity="high">
    <xccdf:title>RHSA-2007:0097: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Flaws were found in the way Firefox executed malformed JavaScript code. A
malicious web page could cause Firefox to crash or allow arbitrary code 
to be executed as the user running Firefox. (CVE-2007-0775, CVE-2007-0777)

Cross-site scripting (XSS) flaws were found in Firefox.  A malicious web
page could display misleading information, allowing a user to unknowingly
divulge sensitive information, such as a password. (CVE-2006-6077, 
CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Firefox processed JavaScript contained in
certain tags.  A malicious web page could cause Firefox to execute
JavaScript code with the privileges of the user running Firefox.
(CVE-2007-0994)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may have been able to inject arbitrary HTML into a
browsing session if the user reloaded a targeted site. (CVE-2007-0778)

Certain web content could overlay Firefox user interface elements such as
the hostname and security indicators.  A malicious web page could trick a
user into thinking they were visiting a different site. (CVE-2007-0779)

Two flaws were found in Firefox's displaying of blocked popup windows. If a
user could be convinced to open a blocked popup, it was possible to read
arbitrary local files, or conduct a cross-site scripting attack against the
user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Firefox. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Firefox handled the "location.hostname" value.
 A malicious web page could set domain cookies for an arbitrary site, or
possibly perform a cross-site scripting attack. (CVE-2007-0981)
	
Users of Firefox are advised to upgrade to this erratum package, containing
Firefox version 1.5.0.10 which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0996</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070097"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070099" severity="high">
    <xccdf:title>RHSA-2007:0099: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the key serial number collision avoidance algorithm of the
keyctl subsystem that allowed a local user to cause a denial of service
(CVE-2007-0006, Important)

* a flaw in the Omnikey CardMan 4040 driver that allowed a local user to
execute arbitrary code with kernel privileges. In order to exploit this
issue, the Omnikey CardMan 4040 PCMCIA card must be present and the local
user must have access rights to the character device created by the driver.
(CVE-2007-0005, Moderate)

* a flaw in the core-dump handling that allowed a local user to create core
dumps from unreadable binaries via PT_INTERP. (CVE-2007-0958, Low)

In addition to the security issues described above, a fix for a kernel
panic in the powernow-k8 module, and a fix for a kernel panic when booting
the Xen domain-0 on system with large memory installations have been included.

Red Hat would like to thank Daniel Roethlisberger for reporting an issue
fixed in this erratum.

Red Hat Enterprise Linux 5 users are advised to upgrade their kernels to
the packages associated with their machine architecture and configurations
as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0099</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0958</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070099"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070106" severity="high">
    <xccdf:title>RHSA-2007:0106: gnupg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

Gerardo Richarte discovered that a number of applications that make use of
GnuPG are prone to a vulnerability involving incorrect verification of
signatures and encryption.  An attacker could add arbitrary content to a
signed message in such a way that a receiver of the message would not be
able to distinguish between the properly signed parts of a message and the
forged, unsigned, parts.  (CVE-2007-1263)

Whilst this is not a vulnerability in GnuPG itself, the GnuPG team have
produced a patch to protect against messages with multiple plaintext
packets.  Users should update to these erratum packages which contain the
backported patch for this issue.

Red Hat would like to thank Core Security Technologies for reporting this
issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0106</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1263</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070106"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070107" severity="high">
    <xccdf:title>RHSA-2007:0107: gnupg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GnuPG is a utility for encrypting data and creating digital signatures.

Gerardo Richarte discovered that a number of applications that make use of
GnuPG are prone to a vulnerability involving incorrect verification of
signatures and encryption.  An attacker could add arbitrary content to a
signed message in such a way that a receiver of the message would not be
able to distinguish between the properly signed parts of a message and the
forged, unsigned, parts.  (CVE-2007-1263)

Whilst this is not a vulnerability in GnuPG itself, the GnuPG team have
produced a patch to protect against messages with multiple plaintext
packets.  Users should update to these erratum packages which contain the
backported patch for this issue.

Red Hat would like to thank Core Security Technologies for reporting this
issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0107</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1263</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070107"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070108" severity="high">
    <xccdf:title>RHSA-2007:0108: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML mail message could execute JavaScript
code in such a way that may result in Thunderbird crashing or executing
arbitrary code as the user running Thunderbird. JavaScript support is
disabled by default in Thunderbird; these issues are not exploitable unless
the user has enabled JavaScript. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way Thunderbird
processed certain malformed HTML mail messages. A malicious HTML mail
message could display misleading information which may result in a user
unknowingly divulging sensitive information such as a password.
(CVE-2006-6077, CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Thunderbird processed text/enhanced and
text/richtext formatted mail message. A specially crafted mail message
could execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2007-1282)

A flaw was found in the way Thunderbird cached web content on the local
disk. A malicious HTML mail message may be able to inject arbitrary HTML
into a browsing session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious HTML mail message could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Thunderbird displayed blocked popup
windows. If a user can be convinced to open a blocked popup, it is possible
to read arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Thunderbird. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Thunderbird handled the "location.hostname"
value during certain browser domain checks. This flaw could allow a
malicious HTML mail message to set domain cookies for an arbitrary site, or
possibly perform an XSS attack. (CVE-2007-0981)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.10 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070108"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070114" severity="high">
    <xccdf:title>RHSA-2007:0114: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Xen package contains the tools for managing the virtual machine monitor
in Red Hat Enterprise Linux virtualization.

A flaw was found affecting the VNC server code in QEMU.  On a
fullyvirtualized guest VM, where qemu monitor mode is enabled, a user who
had access to the VNC server could gain the ability to read arbitrary files
as root in the host filesystem.  (CVE-2007-0998)

In addition to disabling qemu monitor mode, the following bugs were also fixed:

* Fix IA64 fully virtualized (VTi) shadow page table mode initialization.

* Fix network bonding in balanced-rr mode.  Without this update, a network
path loss could result in packet loss.

Users of Xen should update to these erratum packages containing backported
patches which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0998</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070114"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070123" severity="medium">
    <xccdf:title>RHSA-2007:0123: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A bug was found in the way CUPS handled SSL negotiation.  A remote user
capable of connecting to the CUPS daemon could cause a denial of service to
other CUPS users.  (CVE-2007-0720)

All users of CUPS should upgrade to these updated packages, which contain
a backported patch introducing a timeout, which prevents connections being
kept open for an arbitrarily long time.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070123"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070124" severity="medium">
    <xccdf:title>RHSA-2007:0124: file security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The file command is used to identify a particular file according to the
type of data contained by the file.

An integer underflow flaw was found in the file utility.  An attacker could
create a carefully crafted file which, if examined by a victim using the
file utility, could lead to arbitrary code execution. (CVE-2007-1536)

This issue did not affect the version of the file utility distributed with
Red Hat Enterprise Linux 2.1 or 3.

Users should upgrade to this erratum package, which contain a backported
patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0124</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1536</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070124"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070126" severity="high">
    <xccdf:title>RHSA-2007:0126: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported an integer overflow flaw in the X.org XC-MISC
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with the
privileges of the X.org server. (CVE-2007-1003)

iDefense reported two integer overflows in the way X.org handled various
font files. A malicious local user could exploit these issues to
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-1351, CVE-2007-1352)

An integer overflow flaw was found in the X.org XGetPixel() function.
Improper use of this function could cause an application calling it to
function improperly, possibly leading to a crash or arbitrary code
execution. (CVE-2007-1667)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070127" severity="high">
    <xccdf:title>RHSA-2007:0127: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported an integer overflow flaw in the X.org X11 server XC-MISC
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the X.org server. (CVE-2007-1003)

Users of the X.org X11 server should upgrade to these updated packages,
which contain a backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1003</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070127"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070131" severity="medium">
    <xccdf:title>RHSA-2007:0131: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A denial of service flaw was found in the way Squid processed the TRACE
request method. It was possible for an attacker behind the Squid proxy
to issue a malformed TRACE request, crashing the Squid daemon child
process. As long as these requests were sent, it would prevent
legitimate usage of the proxy server. (CVE-2007-1560)

This flaw does not affect the version of Squid shipped in Red Hat
Enterprise Linux 2.1, 3, or 4.

Users of Squid should upgrade to this updated package, which contains a
backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1560</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070131"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070132" severity="high">
    <xccdf:title>RHSA-2007:0132: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported two integer overflows in the way X.org handled various
font files. A malicious local user could exploit these issues to
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-1351, CVE-2007-1352)

Users of X.org libXfont should upgrade to these updated packages, which
contain a backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1352</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070150" severity="medium">
    <xccdf:title>RHSA-2007:0150: freetype security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality,  portable font engine.

An integer overflow flaw was found in the way the FreeType font engine
processed BDF font files. If a user loaded a carefully crafted font file
with a program linked against FreeType, it could cause the application to
crash or execute arbitrary code. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2007-1351)

This flaw did not affect the version of FreeType shipped in Red Hat
Enterprise Linux 2.1.

Users of FreeType should upgrade to these updated packages, which contain
a backported patch to correct this issue.

Red Hat would like to thank iDefense for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1351</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070150"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070152" severity="medium">
    <xccdf:title>RHSA-2007:0152: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was found in the way MySQL handled case sensitive database names. A
user with the ability to create databases could gain unauthorized access to
other databases hosted by the MySQL server. (CVE-2006-4226)

This flaw does not affect the version of MySQL distributed with Red Hat
Enterprise Linux 2.1, 3, or 5.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain a backported patch which fixes this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4226</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070152"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070153" severity="medium">
    <xccdf:title>RHSA-2007:0153: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A flaw was found in the way the mbstring extension set global variables. A
script which used the mb_parse_str() function to set global variables could
be forced to enable the register_globals configuration option, possibly
resulting in global variable injection. (CVE-2007-1583)

A heap based buffer overflow flaw was discovered in PHP's gd extension. A
script that could be forced to process WBMP images from an untrusted source
could result in arbitrary code execution. (CVE-2007-1001)

A buffer over-read flaw was discovered in PHP's gd extension. A script that
could be forced to write arbitrary string using a JIS font from an
untrusted source could cause the PHP interpreter to crash. (CVE-2007-0455)

A flaw was discovered in the way PHP's mail() function processed header
data. If a script sent mail using a Subject header containing a string from
an untrusted source, a remote attacker could send bulk e-mail to unintended
recipients. (CVE-2007-1718)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1718</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070153"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070155" severity="high">
    <xccdf:title>RHSA-2007:0155: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A denial of service flaw was found in the way PHP processed a deeply nested
array. A remote attacker could cause the PHP interpreter to crash by
submitting an input variable with a deeply nested array. (CVE-2007-1285) 

A flaw was found in the way PHP's unserialize() function processed data. If
a remote attacker was able to pass arbitrary data to PHP's unserialize()
function, they could possibly execute arbitrary code as the apache user.
(CVE-2007-1286)

A flaw was found in the way the mbstring extension set global variables. A
script which used the mb_parse_str() function to set global variables could
be forced to enable the register_globals configuration option, possibly
resulting in global variable injection. (CVE-2007-1583)

A double free flaw was found in PHP's session_decode() function. If a
remote attacker was able to pass arbitrary data to PHP's session_decode()
function, they could possibly execute arbitrary code as the apache user.
(CVE-2007-1711)

A flaw was discovered in the way PHP's mail() function processed header
data. If a script sent mail using a Subject header containing a string from
an untrusted source, a remote attacker could send bulk e-mail to unintended
recipients. (CVE-2007-1718)

A heap based buffer overflow flaw was discovered in PHP's gd extension. A
script that could be forced to process WBMP images from an untrusted source
could result in arbitrary code execution. (CVE-2007-1001)

A buffer over-read flaw was discovered in PHP's gd extension. A script that
could be forced to write arbitrary string using a JIS font from an
untrusted source could cause the PHP interpreter to crash. (CVE-2007-0455)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1718</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070155"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070157" severity="medium">
    <xccdf:title>RHSA-2007:0157: xorg-x11-apps and libX11 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

An integer overflow flaw was found in the X.org XGetPixel() function.
Improper use of this function could cause an application calling it to
function improperly, possibly leading to a crash or arbitrary code
execution. (CVE-2007-1667)

Users of the X.org X11 server should upgrade to these updated packages,
which contain a backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070157"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070158" severity="medium">
    <xccdf:title>RHSA-2007:0158: evolution security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in the way Evolution parsed the category field
in a memo. If a user tried to save and then view a carefully crafted memo,
arbitrary code may be executed as the user running Evolution. (CVE-2007-1002)

This flaw did not affect the versions of Evolution shipped with Red Hat
Enterprise Linux 2.1, 3, or 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Red Hat would like to thank Ulf Härnhammar of Secunia Research for
reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1002</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070158"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070169" severity="high">
    <xccdf:title>RHSA-2007:0169: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the IPv6 socket option handling that allowed a local user to
read arbitrary kernel memory (CVE-2007-1000, Important).

* a flaw in the IPv6 socket option handling that allowed a local user to
cause a denial of service (CVE-2007-1388, Important).

* a flaw in the utrace support that allowed a local user to cause a denial
of service (CVE-2007-0771, Important).

In addition to the security issues described above, a fix for a memory leak
in the audit subsystem and a fix for a data corruption bug on s390 systems
have been included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these erratum
packages, which are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1388</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070169"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070203" severity="low">
    <xccdf:title>RHSA-2007:0203: unzip security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The unzip utility is used to list, test, or extract files from a zip archive.

A race condition was found in Unzip. Local users could use this flaw to
modify permissions of arbitrary files via a hard link attack on a file
while it was being decompressed (CVE-2005-2475)

A buffer overflow was found in Unzip command line argument handling.
If a user could be tricked into running Unzip with a specially crafted long
file name, an attacker could execute arbitrary code with that user's
privileges. (CVE-2005-4667)

As well, this update adds support for files larger than 2GB.

All users of unzip should upgrade to these updated packages, which
contain backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070203"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070208" severity="low">
    <xccdf:title>RHSA-2007:0208: w3c-libwww security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>w3c-libwww is a general-purpose web library.

Several buffer overflow flaws in w3c-libwww were found. If a client
application that uses w3c-libwww connected to a malicious HTTP server, it
could trigger an out of bounds memory access, causing the client
application to crash (CVE-2005-3183).

This updated version of w3c-libwww also fixes an issue when computing MD5
sums on a 64 bit machine.

Users of w3c-libwww should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070208"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070220" severity="medium">
    <xccdf:title>RHSA-2007:0220: gcc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95
GNU compilers and related support libraries.

Jürgen Weigert discovered a directory traversal flaw in fastjar. An
attacker could create a malicious JAR file which, if unpacked using
fastjar, could write to any files the victim had write access to.
(CVE-2006-3619)

These updated packages also fix several bugs, including:

* two debug information generator bugs

* two internal compiler errors

In addition to this, protoize.1 and unprotoize.1 manual pages have been
added to the package and __cxa_get_exception_ptr@@CXXABI_1.3.1 symbol has
been added into libstdc++.so.6.

For full details regarding all fixed bugs, refer to the package changelog
as well as the specified list of bug reports from bugzilla.

All users of gcc should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0220</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3619</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070220"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070229" severity="low">
    <xccdf:title>RHSA-2007:0229: gdb security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GDB, the GNU debugger, allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and then printing
their data.

Various buffer overflows and underflows were found in the DWARF expression
computation stack in GDB. If a user loaded an executable containing
malicious debugging information into GDB, an attacker might be able to
execute arbitrary code with the privileges of the user. (CVE-2006-4146)

This updated package also addresses the following issues:

* Fixed bogus 0x0 unwind of the thread's topmost function clone(3).

* Fixed deadlock accessing invalid address; for corrupted backtraces.

* Fixed a race which occasionally left the detached processes stopped.

* Fixed 'gcore' command for 32bit debugged processes on 64bit hosts.

* Added support for TLS 'errno' for threaded programs missing its '-debuginfo' package..

* Suggest TLS 'errno' resolving by hand if no threading was found..

* Added a fix to prevent stepping into asynchronously invoked signal handlers.

* Added a fix to avoid false warning on shared objects bfd close on Itanium.

* Fixed segmentation fault on the source display by ^X 1.

* Fixed object names keyboard completion.

* Added a fix to avoid crash of 'info threads' if stale threads exist.

* Fixed a bug where shared libraries occasionally failed to load .

* Fixed handling of exec() called by a threaded debugged program.

* Fixed rebuilding requirements of the gdb package itself on multilib systems.

* Fixed source directory pathname detection for the edit command.

All users of gdb should upgrade to this updated package, which contains
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0229</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4146</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070229"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070235" severity="low">
    <xccdf:title>RHSA-2007:0235: util-linux security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux package contains a collection of basic system utilities.

A flaw was found in the way the login process handled logins which did not
require authentication. Certain processes which conduct their own
authentication could allow a remote user to bypass intended access policies
which would normally be enforced by the login process. (CVE-2006-7108)

This update also fixes the following bugs:

* The partx, addpart and delpart commands were not documented.

* The "umount -l" command did not work on hung NFS mounts with cached data.

* The mount command did not mount NFS V3 share where sec=none was specified.

* The mount command did not read filesystem LABEL from unpartitioned disks.

* The mount command did not recognize labels on VFAT filesystems.

* The fdisk command did not support 4096 sector size for the "-b" option.

* The mount man page did not list option "mand" or information about
/etc/mtab limitations.

All users of util-linux should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070235"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070244" severity="low">
    <xccdf:title>RHSA-2007:0244: busybox security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Busybox is a single binary which includes versions of a large number of
system commands, including a shell. This package can be useful for
recovering from certain types of system failures.

BusyBox did not use a salt when generating passwords. This made it
easier for local users to guess passwords from a stolen password file. 
(CVE-2006-1058)

All users of busybox are advised to upgrade to these updated packages,
which contain a patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1058</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070244"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070245" severity="low">
    <xccdf:title>RHSA-2007:0245: cpio security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU cpio copies files into or out of a cpio or tar archive.

A buffer overflow was found in cpio on 64-bit platforms. By tricking a
user into adding a specially crafted large file to a cpio archive, a local
attacker may be able to exploit this flaw to execute arbitrary code with
the target user's privileges. (CVE-2005-4268)

This erratum also addresses the following bugs:

* cpio did not set exit codes appropriately.

* cpio did not create a ram disk properly.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4268</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070245"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070252" severity="low">
    <xccdf:title>RHSA-2007:0252: sendmail security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sendmail is a very widely used Mail Transport Agent (MTA). MTAs deliver
mail from one machine to another. Sendmail is not a client program, but
rather a behind-the-scenes daemon that moves email over networks or the
Internet to its final destination.

The configuration of Sendmail on Red Hat Enterprise Linux was found to not
reject the "localhost.localdomain" domain name for e-mail messages that
came from external hosts. This could have allowed remote attackers to
disguise spoofed messages (CVE-2006-7176).

This updated package also fixes the following bugs:

* Infinite loop within tls read.

* Incorrect path to selinuxenabled in initscript.

* Build artifacts from sendmail-cf package.

* Missing socketmap support.

* Add support for CipherList configuration directive.

* Path for aliases file.

* Failure of shutting down sm-client.

* Allows to specify persistent queue runners.

* Missing dnl for SMART_HOST define.

* Fixes connections stay in CLOSE_WAIT.

All users of Sendmail should upgrade to these updated packages, which
contains backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7176</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070252"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070257" severity="low">
    <xccdf:title>RHSA-2007:0257: openssh security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

OpenSSH stores hostnames, IP addresses, and keys in plaintext in the
known_hosts file.  A local attacker that has already compromised a user's
SSH account could use this information to generate a list of additional
targets that are likely to have the same password or key.  (CVE-2005-2666)

The following bugs have also been fixed in this update:

* The ssh client could abort the running connection when the server
application generated a large output at once.

* When 'X11UseLocalhost' option was set to 'no' on systems with IPv6
networking enabled, the X11 forwarding socket listened only for IPv6
connections.

* When the privilege separation was enabled in /etc/ssh/sshd_config, some
log messages in the system log were duplicated and also had timestamps from
an incorrect timezone.

All users of openssh should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2666</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070257"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070276" severity="low">
    <xccdf:title>RHSA-2007:0276: shadow-utils security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The shadow-utils package includes the necessary programs for converting
UNIX password files to the shadow password format, as well as programs for
managing user and group accounts.

A flaw was found in the useradd tool in shadow-utils. A new user's
mailbox, when created, could have random permissions for a short period.
This could allow a local attacker to read or modify the mailbox.
(CVE-2006-1174)

This update also fixes the following bugs:

* shadow-utils debuginfo package was empty.

* faillog was unusable on 64-bit systems. It checked every UID from 0 to
the max UID, which was an excessively large number on 64-bit systems.

* typo bug in login.defs file

All users of shadow-utils are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0276</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1174</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070276"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070286" severity="low">
    <xccdf:title>RHSA-2007:0286: gdm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Gdm (the GNOME Display Manager) is a highly configurable reimplementation
of xdm, the X Display Manager. Gdm allows you to log into your system with
the X Window System running and supports running several different X
sessions on your local machine at the same time.

Marcus Meissner discovered a race condition issue in the way Gdm modifies
the permissions on the .ICEauthority file. A local attacker could exploit
this flaw to gain privileges. Due to the nature of the flaw, however, a
successful exploitation was unlikely. (CVE-2006-1057)

This erratum also includes a bug fix to correct the pam configuration for
the audit system.

All users of gdm should upgrade to this updated package, which contains
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1057</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070286"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070310" severity="low">
    <xccdf:title>RHSA-2007:0310: openldap security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled selfwrite access. Users with
selfwrite access were able to modify the distinguished name of any user.
(CVE-2006-4600)

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4600</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070310"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070322" severity="medium">
    <xccdf:title>RHSA-2007:0322: xscreensaver security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>XScreenSaver is a collection of screensavers.

Alex Yamauchi discovered a flaw in the way XScreenSaver verifies user
passwords. When a system is using a remote directory service for login
credentials, a local attacker may be able to cause a network outage causing
XScreenSaver to crash, unlocking the screen. (CVE-2007-1859)

Users of XScreenSaver should upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1859</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070322"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070323" severity="high">
    <xccdf:title>RHSA-2007:0323: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Xen package contains the tools for managing the virtual machine monitor
in Red Hat Enterprise Linux virtualization.

The following security flaws are fixed in the updated Xen package:

Joris van Rantwijk found a flaw in the Pygrub utility which is used as a
boot loader for guest domains.  A malicious local administrator of a guest
domain could create a carefully crafted grub.conf file which would trigger
the execution of arbitrary code outside of that domain. (CVE-2007-4993)

Tavis Ormandy discovered a heap overflow flaw during video-to-video copy
operations in the Cirrus VGA extension code used in Xen.  A malicious local
administrator of a guest domain could potentially trigger this flaw and
execute arbitrary code outside of the domain. (CVE-2007-1320)

Tavis Ormandy discovered insufficient input validation leading to a heap
overflow in the Xen NE2000 network driver.   If the driver is in use, a
malicious local administrator of a guest domain could potentially trigger
this flaw and execute arbitrary code outside of the domain.  Xen does not
use this driver by default. (CVE-2007-1321)

Users of Xen should update to these erratum packages containing backported
patches which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1320</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4993</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070327" severity="high">
    <xccdf:title>RHSA-2007:0327: tomcat security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tomcat is a servlet container for Java Servlet and JavaServer Pages
technologies.

Tomcat was found to accept multiple content-length headers in a
request. This could allow attackers to poison a web-cache, bypass web
application firewall protection, or conduct cross-site scripting attacks. 
(CVE-2005-2090)

Tomcat permitted various characters as path delimiters. If Tomcat was used
behind certain proxies and configured to only proxy some contexts, an
attacker could construct an HTTP request to work around the context
restriction and potentially access non-proxied content. (CVE-2007-0450)

The implict-objects.jsp file distributed in the examples webapp displayed a
number of unfiltered header values. If the JSP examples were accessible,
this flaw could allow a remote attacker to perform cross-site scripting
attacks. (CVE-2006-7195)

Users should upgrade to these erratum packages which contain an update to
Tomcat that resolves these issues.  Updated jakarta-commons-modeler
packages are also included which correct a bug when used with Tomcat 5.5.23.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1358</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070336" severity="medium">
    <xccdf:title>RHSA-2007:0336: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw was found in the way PostgreSQL allows authenticated users to
execute security-definer functions.  It was possible for an unprivileged
user to execute arbitrary code with the privileges of the security-definer
function. (CVE-2007-2138)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 8.1.9, 7.4.17, and 7.3.19 which corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2138</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070336"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070338" severity="medium">
    <xccdf:title>RHSA-2007:0338: freeradius security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A memory leak flaw was found in the way FreeRADIUS parses certain
authentication requests. A remote attacker could send a specially crafted
authentication request which could cause FreeRADIUS to leak a small amount
of memory. If enough of these requests are sent, the FreeRADIUS daemon
would consume a vast quantity of system memory leading to a possible denial
of service.   (CVE-2007-2028)

Users of FreeRADIUS should update to these erratum packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2028</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070338"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070342" severity="medium">
    <xccdf:title>RHSA-2007:0342: ipsec-tools security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon. It was
possible for a remote attacker, with knowledge of an existing ipsec tunnel,
to terminate the ipsec connection between two machines. (CVE-2007-1841)

Users of ipsec-tools should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070342"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070343" severity="medium">
    <xccdf:title>RHSA-2007:0343: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Marsu discovered a stack overflow bug in The GIMP RAS file loader.  An
attacker could create a carefully crafted file that could cause The GIMP to
crash or possibly execute arbitrary code if the file was opened by a
victim.  (CVE-2007-2356)

For users of Red Hat Enterprise Linux 5, the previous GIMP packages had a
bug that concerned the execution order in which the symbolic links to
externally packaged GIMP plugins are installed and removed, causing the
symbolic links to vanish when the package is updated.

Users of The GIMP should update to these erratum packages which contain a
backported fix to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2356</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070343"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070344" severity="medium">
    <xccdf:title>RHSA-2007:0344: evolution-data-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The evolution-data-server package provides a unified backend for programs
that work with contacts, tasks, and calendar information.

A flaw was found in the way evolution-data-server processed certain APOP
authentication requests. By sending certain responses when
evolution-data-server attempted to authenticate against an APOP server, a
remote attacker could potentially acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

All users of evolution-data-server should upgrade to these updated
packages, which contain a backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070344"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070345" severity="medium">
    <xccdf:title>RHSA-2007:0345: vixie-cron security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

Raphael Marichez discovered a denial of service bug in the way vixie-cron
verifies crontab file integrity. A local user with the ability to create a
hardlink to /etc/crontab can prevent vixie-cron from executing certain
system  cron jobs. (CVE-2007-1856)

All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1856</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070345"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070346" severity="medium">
    <xccdf:title>RHSA-2007:0346: vim security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>VIM (VIsual editor iMproved) is a version of the vi editor.

An arbitrary command execution flaw was found in the way VIM processes
modelines.  If a user with modelines enabled opened a text file containing
a carefully crafted modeline, arbitrary commands could be executed as the user
running VIM. (CVE-2007-2438)

Users of VIM are advised to upgrade to these updated packages, which
resolve this issue.

Please note: this issue did not affect VIM as distributed with Red Hat
Enterprise Linux 2.1, 3, or 4.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0346</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2438</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070346"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070347" severity="high">
    <xccdf:title>RHSA-2007:0347: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the handling of IPv6 type 0 routing headers that allowed remote
users to cause a denial of service that led to a network amplification
between two routers (CVE-2007-2242, Important).

* a flaw in the nfnetlink_log netfilter module that allowed a local user to
cause a denial of service (CVE-2007-1496, Important).

* a flaw in the flow list of listening IPv6 sockets that allowed a local
user to cause a denial of service (CVE-2007-1592, Important).

* a flaw in the handling of netlink messages that allowed a local user to
cause a denial of service (infinite recursion) (CVE-2007-1861, Important).

* a flaw in the IPv4 forwarding base that allowed a local user to cause an
out-of-bounds access (CVE-2007-2172, Important).

* a flaw in the nf_conntrack netfilter module for IPv6 that allowed remote
users to bypass certain netfilter rules using IPv6 fragments
(CVE-2007-1497, Moderate).

In addition to the security issues described above, fixes for the following
have been included:

* a regression in ipv6 routing.

* an error in memory initialization that caused gdb to output inaccurate
backtraces on ia64.

* the nmi watchdog timeout was updated from 5 to 30 seconds.

* a flaw in distributed lock management that could result in errors during
virtual machine migration.

* an omitted include in kernel-headers that led to compile failures for
some packages.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2242</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070347"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070348" severity="high">
    <xccdf:title>RHSA-2007:0348: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A heap buffer overflow flaw was found in the PHP 'xmlrpc' extension.  A
PHP script which implements an XML-RPC server using this extension
could allow a remote attacker to execute arbitrary code as the 'apache'
user.  Note that this flaw does not affect PHP applications using the
pure-PHP XML_RPC class provided in /usr/share/pear. (CVE-2007-1864)

A flaw was found in the PHP 'ftp' extension.  If a PHP script used this
extension to provide access to a private FTP server, and passed untrusted
script input directly to any function provided by this extension, a remote
attacker would be able to send arbitrary FTP commands to the server. 
(CVE-2007-2509)

A buffer overflow flaw was found in the PHP 'soap' extension, regarding the
handling of an HTTP redirect response when using the SOAP client provided
by this extension with an untrusted SOAP server.  No mechanism to trigger
this flaw remotely is known.  (CVE-2007-2510)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2510</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070348"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070349" severity="high">
    <xccdf:title>RHSA-2007:0349: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A heap buffer overflow flaw was found in the PHP 'xmlrpc' extension. A
PHP script which implements an XML-RPC server using this extension could
allow a remote attacker to execute arbitrary code as the 'apache' user.
Note that this flaw does not affect PHP applications using the pure-PHP
XML_RPC class provided in /usr/share/pear. (CVE-2007-1864)

A flaw was found in the PHP 'ftp' extension. If a PHP script used this
extension to provide access to a private FTP server, and passed untrusted
script input directly to any function provided by this extension, a remote
attacker would be able to send arbitrary FTP commands to the server.
(CVE-2007-2509)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0349</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2509</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070349"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070353" severity="medium">
    <xccdf:title>RHSA-2007:0353: evolution security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processed certain APOP authentication
requests. A remote attacker could potentially acquire certain portions of a
user's authentication credentials by sending certain responses when
evolution-data-server attempted to authenticate against an APOP server.
(CVE-2007-1558)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070353"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070354" severity="high">
    <xccdf:title>RHSA-2007:0354: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba provides file and printer sharing services to SMB/CIFS clients.

Various bugs were found in NDR parsing, used to decode MS-RPC requests in
Samba.  A remote attacker could have sent carefully crafted requests
causing a heap overflow, which may have led to the ability to execute
arbitrary code on the server.  (CVE-2007-2446)

Unescaped user input parameters were being passed as arguments to /bin/sh.
A remote, authenticated, user could have triggered this flaw and executed
arbitrary code on the server.  Additionally, on Red Hat Enterprise Linux 5
only, this flaw could be triggered by a remote unauthenticated user if
Samba was configured to use the non-default "username map script" option. 
(CVE-2007-2447)

Users of Samba should upgrade to these packages, which contain backported
patches to correct these issues.  After upgrading, Samba should be
restarted using "service smb restart"

On Red Hat Enterprise Linux 5 the impact of these issues is reduced as
Samba is constrained by the default SELinux "targeted" policy.

Red Hat would like to thank the Samba developers, TippingPoint, and
iDefense for reporting these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0354</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070354"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070356" severity="medium">
    <xccdf:title>RHSA-2007:0356: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was found in the handling of malformed images in libpng. An attacker
could create a carefully crafted PNG image file in such a way that it could
cause an application linked with libpng to crash when the file was
manipulated.  (CVE-2007-2445)

A flaw was found in the sPLT chunk handling code in libpng. An attacker
could create a carefully crafted PNG image file in such a way that it could
cause an application linked with libpng to crash when the file was opened. 
(CVE-2006-5793)

Users of libpng should update to these updated packages which contain
backported patches to correct these issues.

Red Hat would like to thank Glenn Randers-Pehrson, Mats Palmgren, and Tavis
Ormandy for supplying details and patches for these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0356</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2445</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070356"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070358" severity="medium">
    <xccdf:title>RHSA-2007:0358: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP4. 

Several HTML filtering bugs were discovered in SquirrelMail.  An attacker
could inject arbitrary JavaScript leading to cross-site scripting attacks
by sending an e-mail viewed by a user within SquirrelMail. 
(CVE-2007-1262)

Squirrelmail did not sufficiently check arguments to IMG tags in HTML
e-mail messages. This could be exploited by an attacker by sending
arbitrary e-mail messages on behalf of a squirrelmail user tricked into opening
a maliciously crafted HTML e-mail message.  (CVE-2007-2589)

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0358</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2589</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070358"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070368" severity="medium">
    <xccdf:title>RHSA-2007:0368: tcpdump security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tcpdump is a command line tool for monitoring network traffic.

Moritz Jodeit discovered a denial of service bug in the tcpdump IEEE 802.11
processing code. If a certain link type was explicitly specified, an
attacker could inject a carefully crafted frame onto the IEEE 802.11
network that could crash a running tcpdump session. (CVE-2007-1218)

An integer overflow flaw was found in tcpdump's BGP processing code. An
attacker could execute arbitrary code with the privilege of the pcap user
by injecting a crafted frame onto the network. (CVE-2007-3798)

In addition, the following bugs have been addressed:

* The arpwatch service initialization script would exit prematurely,
returning an incorrect successful exit status and preventing the status
command from running in case networking is not available.

* Tcpdump would not drop root privileges completely when launched with the
-C option. This might have been abused by an attacker to gain root
privileges in case a security problem was found in tcpdump. Users of
tcpdump are encouraged to specify meaningful arguments to the -Z option in
case they want tcpdump to write files with privileges other than of the
pcap user.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0368</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070368"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070376" severity="high">
    <xccdf:title>RHSA-2007:0376: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the mount handling routine for 64-bit systems that allowed a
local user to cause denial of service (CVE-2006-7203, Important).

* a flaw in the PPP over Ethernet implementation that allowed a remote user
to cause a denial of service (CVE-2007-2525, Important).

* a flaw in the Bluetooth subsystem that allowed a local user to trigger an
information leak (CVE-2007-1353, Low).

* a bug in the random number generator that prevented the manual seeding of
the entropy pool (CVE-2007-2453, Low).

In addition to the security issues described above, fixes for the following
have been included:

* a race condition between ext3_link/unlink that could create an orphan
inode list corruption.

* a bug in the e1000 driver that could lead to a watchdog timeout panic.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2525</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070385" severity="medium">
    <xccdf:title>RHSA-2007:0385: fetchmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Fetchmail is a remote mail retrieval and forwarding utility intended
for use over on-demand TCP/IP links, like SLIP or PPP connections.

A flaw was found in the way fetchmail processed certain APOP authentication
requests. By sending certain responses when fetchmail attempted to
authenticate against an APOP server, a remote attacker could potentially
acquire certain portions of a user's authentication credentials.
(CVE-2007-1558)

All users of fetchmail should upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070385"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070386" severity="medium">
    <xccdf:title>RHSA-2007:0386: mutt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt used temporary files on NFS file systems.
Due to an implementation issue in the NFS protocol, Mutt was not able to
exclusively open a new file.  A local attacker could conduct a
time-dependent attack and possibly gain access to e-mail attachments opened
by a victim. (CVE-2006-5297)

A flaw was found in the way Mutt processed certain APOP authentication
requests. By sending certain responses when mutt attempted to authenticate
against an APOP server, a remote attacker could potentially acquire certain
portions of a user's authentication credentials. (CVE-2007-1558)

A flaw was found in the way Mutt handled certain characters in gecos fields
which could lead to a buffer overflow.  The gecos field is an entry in the
password database typically used to record general information about the
user.  A local attacker could give themselves a carefully crafted "Real
Name" which could execute arbitrary code if a victim uses Mutt and expands
the attackers alias.  (CVE-2007-2683)

All users of mutt should upgrade to this updated package, which
contains a backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5297</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2683</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070387" severity="medium">
    <xccdf:title>RHSA-2007:0387: tcpdump security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tcpdump is a command line tool for monitoring network traffic.

Moritz Jodeit discovered a denial of service bug in the tcpdump IEEE
802.11 processing code. An attacker could inject a carefully crafted frame
onto the IEEE 802.11 network that could crash a running tcpdump session if
a certain link type was explicitly specified. (CVE-2007-1218)

An integer overflow flaw was found in tcpdump's BGP processing code. An
attacker could execute arbitrary code with the privilege of the pcap user
by injecting a crafted frame onto the network. (CVE-2007-3798)

In addition, the following bugs have been addressed: 

* if called with -C and -W switches, tcpdump would create the first
savefile with the privileges of the user that executed tcpdump (usually
root), rather than with ones of the pcap user.  This could result in the
inability to save the complete traffic log file properly without the
immediate notice of the user running tcpdump.

* the arpwatch service initialization script would exit prematurely,
returning a successful exit status incorrectly and preventing the status
command from running in case networking is not available.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0387</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070387"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070389" severity="medium">
    <xccdf:title>RHSA-2007:0389: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite.

An out of bounds memory read flaw was discovered in Quagga's bgpd.  A
configured peer of bgpd could cause Quagga to crash, leading to a denial of
service (CVE-2007-1995).

All users of Quagga should upgrade to this updated package, which
contains a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1995</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070389"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070391" severity="medium">
    <xccdf:title>RHSA-2007:0391: file security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The file command is used to identify a particular file according to the
type of data contained by the file.

The fix for CVE-2007-1536 introduced a new integer underflow flaw in the
file utility. An attacker could create a carefully crafted file which, if
examined by a victim using the file utility, could lead to arbitrary code
execution. (CVE-2007-2799)

This issue did not affect the version of the file utility distributed with
Red Hat Enterprise Linux 2.1 or 3.

Users should upgrade to this erratum package, which contain a backported
patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2799</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070391"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070395" severity="low">
    <xccdf:title>RHSA-2007:0395: mod_perl security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mod_perl incorporates a Perl interpreter into the Apache web server,
so that the Apache web server can directly execute Perl code.

An issue was found in the "namespace_from_uri" method of the
ModPerl::RegistryCooker class.  If a server implemented a mod_perl registry
module using this method, a remote attacker requesting a carefully crafted
URI can cause resource consumption, which could lead to a denial of service
(CVE-2007-1349).

Users of mod_perl should update to these erratum packages which contain a
backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1349</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070395"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070400" severity="high">
    <xccdf:title>RHSA-2007:0400: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Firefox to crash or potentially execute arbitrary code as the user
running Firefox. (CVE-2007-2867, CVE-2007-2868)

A flaw was found in the way Firefox handled certain FTP PASV commands. A
malicious FTP server could use this flaw to perform a rudimentary
port-scan of machines behind a user's firewall. (CVE-2007-1562)

Several denial of service flaws were found in the way Firefox handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent Firefox from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way Firefox handled the addEventListener
JavaScript method. A malicious web site could use this method to access or
modify sensitive data from another web site. (CVE-2007-2870)

A flaw was found in the way Firefox displayed certain web content. A
malicious web page could generate content that would overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.12 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0400</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070400"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070401" severity="high">
    <xccdf:title>RHSA-2007:0401: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Thunderbird to crash or potentially execute arbitrary code
as the user running Thunderbird. (CVE-2007-2867, CVE-2007-2868)

Several denial of service flaws were found in the way Thunderbird handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent Thunderbird from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way Thunderbird processed certain APOP
authentication requests. By sending certain responses when Thunderbird
attempted to authenticate against an APOP server, a remote attacker could
potentially acquire certain portions of a user's authentication
credentials. (CVE-2007-1558)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.12 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070401"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070402" severity="high">
    <xccdf:title>RHSA-2007:0402: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause SeaMonkey to crash or potentially execute arbitrary code as
the user running SeaMonkey. (CVE-2007-2867, CVE-2007-2868)

A flaw was found in the way SeaMonkey handled certain FTP PASV commands. A
malicious FTP server could use this flaw to perform a rudimentary port-scan
of machines behind a user's firewall. (CVE-2007-1562)

Several denial of service flaws were found in the way SeaMonkey handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent SeaMonkey from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way SeaMonkey processed certain APOP authentication
requests. By sending certain responses when SeaMonkey attempted to
authenticate against an APOP server, a remote attacker could potentially
acquire certain portions of a user's authentication credentials.
(CVE-2007-1558)

A flaw was found in the way SeaMonkey handled the addEventListener
JavaScript method. A malicious web site could use this method to access or
modify sensitive data from another web site. (CVE-2007-2870)

A flaw was found in the way SeaMonkey displayed certain web content. A
malicious web page could generate content that would overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871) 

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain SeaMonkey version 1.0.9 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070402"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070403" severity="medium">
    <xccdf:title>RHSA-2007:0403: freetype security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality,  portable font engine.

An integer overflow flaw was found in the way the FreeType font engine
processed TTF font files. If a user loaded a carefully crafted font file
with a program linked against FreeType, it could cause the application to
crash or execute arbitrary code. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2007-2754)

Users of FreeType should upgrade to these updated packages, which contain
a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070403"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070406" severity="high">
    <xccdf:title>RHSA-2007:0406: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the RTF import filer.  An attacker could
create a carefully crafted RTF file that could cause OpenOffice.org to
crash or possibly execute arbitrary code if the file was opened by a
victim. (CVE-2007-0245)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0245</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070406"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070488" severity="high">
    <xccdf:title>RHSA-2007:0488: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the connection tracking support for SCTP that allowed a remote
user to cause a denial of service by dereferencing a NULL pointer.
(CVE-2007-2876, Important)

* a flaw in the mount handling routine for 64-bit systems that allowed a
local user to cause denial of service (crash). (CVE-2006-7203, Important)

* a flaw in the IPv4 forwarding base that allowed a local user to cause an
out-of-bounds access. (CVE-2007-2172, Important)

* a flaw in the PPP over Ethernet implementation that allowed a local user
to cause a denial of service (memory consumption) by creating a socket
using connect and then releasing it before the PPPIOCGCHAN ioctl has been
called. (CVE-2007-2525, Important)

* a flaw in the fput ioctl handling of 32-bit applications running on
64-bit platforms that allowed a local user to cause a denial of service
(panic). (CVE-2007-0773, Important)

* a flaw in the NFS locking daemon that allowed a local user to cause
denial of service (deadlock). (CVE-2006-5158, Moderate)

* a flaw in the sysfs_readdir function that allowed a local user to cause a
denial of service by dereferencing a NULL pointer. (CVE-2007-3104, Moderate)

* a flaw in the core-dump handling that allowed a local user to create core
dumps from unreadable binaries via PT_INTERP. (CVE-2007-0958, Low) 

* a flaw in the Bluetooth subsystem that allowed a local user to trigger an
information leak. (CVE-2007-1353, Low)

In addition, the following bugs were addressed:

* the NFS could recurse on the same spinlock. Also, NFS, under certain
conditions, did not completely clean up Posix locks on a file close,
leading to mount failures.

* the 32bit compatibility didn't return to userspace correct values for the
rt_sigtimedwait system call.

* the count for unused inodes could be incorrect at times, resulting in
dirty data not being written to disk in a timely manner.

* the cciss driver had an incorrect disk size calculation (off-by-one
error) which prevented disk dumps.

Red Hat would like to thank Ilja van Sprundel and the OpenVZ Linux kernel
team for reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0773</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3104</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070488"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070492" severity="medium">
    <xccdf:title>RHSA-2007:0492: spamassassin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

Martin Krafft discovered a symlink issue in SpamAssassin that affects
certain non-default configurations. A local user could use this flaw to
create or overwrite files writable by the spamd process (CVE-2007-2873).

Users of SpamAssassin should upgrade to these updated packages which
contain a backported patch to correct this issue.

Note: This issue did not affect the version of SpamAssassin shipped with
Red Hat Enterprise Linux 3.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2873</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070492"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070494" severity="high">
    <xccdf:title>RHSA-2007:0494: kdebase security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager. 

A problem with the interaction between the Flash Player and the Konqueror
web browser was found. The problem could lead to key presses leaking to the
Flash Player applet instead of the browser (CVE-2007-2022).

Users of Konqueror who have installed the Adobe Flash Player plugin should
upgrade to these updated packages, which contain a patch provided by Dirk
Müller that protects against this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070494"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070497" severity="medium">
    <xccdf:title>RHSA-2007:0497: iscsi-initiator-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The iscsi package provides the server daemon for the iSCSI protocol, as
well as the utility programs used to manage it. iSCSI is a protocol for
distributed disk access using SCSI commands sent over Internet Protocol
networks.

Olaf Kirch discovered two flaws in open-iscsi.  A local attacker could use
these flaws to cause the server daemon to stop responding, leading to a
denial of service.  (CVE-2007-3099, CVE-2007-3100).

All users of open-iscsi should upgrade to this updated package which
resolves these issues.

Note: This issue did not affect Red Hat Enterprise Linux 2.1, 3, or 4.
open-iscsi is available in Red Hat Enterprise Linux 5 as a Technology
Preview.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3099</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3100</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070497"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070501" severity="medium">
    <xccdf:title>RHSA-2007:0501: libexif integer overflow (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

An integer overflow flaw was found in the way libexif parses EXIF image
tags. If a victim opens a carefully crafted EXIF image file it could cause
the application linked against libexif to execute arbitrary code or crash.
(CVE-2007-4168)

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4168</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070501"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070509" severity="high">
    <xccdf:title>RHSA-2007:0509: evolution security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processes certain IMAP server
messages. If a user can be tricked into connecting to a malicious IMAP
server it may be possible to execute arbitrary code as the user running
evolution. (CVE-2007-3257)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3257</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070509"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070510" severity="high">
    <xccdf:title>RHSA-2007:0510: evolution-data-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The evolution-data-server package provides a unified backend for programs
that work with contacts, tasks, and calendar information.

A flaw was found in the way evolution-data-server processes certain IMAP
server messages. If a user can be tricked into connecting to a malicious
IMAP server it may be possible to execute arbitrary code as the user
running the evolution-data-server process. (CVE-2007-3257) 

All users of evolution-data-server should upgrade to these updated
packages, which contain a backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3257</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070510"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070513" severity="medium">
    <xccdf:title>RHSA-2007:0513: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Multiple integer overflow and input validation flaws were found in The
GIMP's image loaders.  An attacker could create a carefully crafted image
file that could cause The GIMP to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2006-4519, CVE-2007-2949,
CVE-2007-3741)

Users of The GIMP should update to these erratum packages, which contain a
backported fix to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2949</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3741</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070513"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070519" severity="medium">
    <xccdf:title>RHSA-2007:0519: xorg-x11 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A temporary file flaw was found in the way the X.Org X11 xfs font server
startup script executes. A local user could modify the permissions of the
file of their choosing, possibly elevating their local privileges
(CVE-2007-3103).

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3103</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070519"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070520" severity="medium">
    <xccdf:title>RHSA-2007:0520: xorg-x11-xfs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The X.Org X11 xfs font server provides a standard mechanism for an X server
to communicate with a font renderer.

A temporary file flaw was found in the way the X.Org X11 xfs font server
startup script executes. A local user could modify the permissions of a
file of their choosing, possibly elevating their local privileges.
(CVE-2007-3103)

Users of the X.org X11 xfs font server should upgrade to these updated
packages, which contain a backported patch and are not vulnerable to this
issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3103</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070520"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070534" severity="medium">
    <xccdf:title>RHSA-2007:0534: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the Apache HTTP Server mod_status module. On sites
where the server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack. On Red Hat
Enterprise Linux the server-status page is not enabled by default and it is
best practice to not make this publicly available. (CVE-2006-5752)

A bug was found in the Apache HTTP Server mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-1863)

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart Apache
after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1863</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070534"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070539" severity="medium">
    <xccdf:title>RHSA-2007:0539: aide security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Advanced Intrusion Detection Environment (AIDE) is a file integrity checker
and intrusion detection program.

A flaw was discovered in the way file checksums were stored in the AIDE
database. A packaging flaw in the Red Hat AIDE rpm resulted in the file
database not containing any file checksum information. This could prevent
AIDE from detecting certain file modifications. (CVE-2007-3849)

This update also fixes the following bugs:

* certain configurations could result in a segmentation fault upon
initialization.

* AIDE was unable to open its log file in the LSPP evaluated configuration.

* if AIDE found SELinux context differences, the changed files report it
generated only included the first 32 characters of the context.

All users of AIDE are advised to upgrade to this updated package containing
AIDE version 0.13.1 which is not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0539</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3849</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070539"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070540" severity="medium">
    <xccdf:title>RHSA-2007:0540: openssh security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the way the ssh server wrote account names to the audit
subsystem. An attacker could inject strings containing parts of audit
messages, which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

A flaw was found in the way the OpenSSH server processes GSSAPI
authentication requests. When GSSAPI authentication was enabled in the
OpenSSH server, a remote attacker was potentially able to determine if a
username is valid. (CVE-2006-5052)

The following bugs in SELinux MLS (Multi-Level Security) support has also
been fixed in this update:

* It was sometimes not possible to select a SELinux role and level when
logging in using ssh.

* If the user obtained a non-default SELinux role or level, the role change
was not recorded in the audit subsystem.

* In some cases, on labeled networks, sshd allowed logins from level ranges
it should not allow.

The updated packages also contain experimental support for using private
keys stored in PKCS#11 tokens for client authentication. The support is
provided through the NSS (Network Security Services) library.

All users of openssh should upgrade to these updated packages, which
contain patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070540"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070542" severity="low">
    <xccdf:title>RHSA-2007:0542: mcstrans security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>mcstrans is the translation daemon used on SELinux machines to translate
program context into human readable form.

An algorithmic complexity weakness was found in the way the mcstrans daemon
handled ranges of compartments in sensitivity labels. A local user could
trigger this flaw causing mctransd to temporarily stop responding to other
requests; a partial denial of service.  (CVE-2007-4570)

This update also fixes a problem where the mcstrans daemon was preventing
SSH connections into an SELinux box, that was running a Multi-Level
Security (MLS) Policy with multiple categories.

Users of mcstrans are advised to upgrade to this updated package, which
resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4570</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070542"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070555" severity="medium">
    <xccdf:title>RHSA-2007:0555: pam security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

A flaw was found in the way pam_console set console device permissions. It
was possible for various console devices to retain ownership of the console
user after logging out, possibly leaking information to another local user.
(CVE-2007-1716)

A flaw was found in the way the PAM library wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

As well, these updated packages fix the following bugs:

* truncated MD5-hashed passwords in "/etc/shadow" were treated as valid, 
resulting in insecure and invalid passwords.

* the pam_namespace module did not convert context names to raw format and
did not unmount polyinstantiated directories in some cases. It also crashed
when an unknown user name was used in "/etc/security/namespace.conf", the
pam_namespace configuration file.

* the pam_selinux module was not relabeling the controlling tty correctly,
and in some cases it did not send complete information about user role and
level change to the audit subsystem.

These updated packages add the following enhancements:

* pam_limits module now supports parsing additional config files placed
into the /etc/security/limits.d/ directory. These files are read after the
main configuration file.

* the modules pam_limits, pam_access, and pam_time now send a message to
the audit subsystem when a user is denied access based on the number of
login sessions, origin of user, and time of login.

* pam_unix module security properties were improved. Functionality in the
setuid helper binary, unix_chkpwd, which was not required for user
authentication, was moved to a new non-setuid helper binary, unix_update.

All users of PAM should upgrade to these updated packages, which resolve
these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070555"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070556" severity="medium">
    <xccdf:title>RHSA-2007:0556: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

The Apache HTTP Server did not verify that a process was an Apache child
process before sending it signals. A local attacker with the ability to run
scripts on the Apache HTTP Server could manipulate the scoreboard and cause
arbitrary processes to be terminated which could lead to a denial of
service (CVE-2007-3304).  This issue is not exploitable on Red Hat
Enterprise Linux 5 if using the default SELinux targeted policy.

A flaw was found in the Apache HTTP Server mod_status module. On sites
where the server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack. On Red Hat
Enterprise Linux the server-status page is not enabled by default and it is
best practice to not make this publicly available. (CVE-2006-5752)

A bug was found in the Apache HTTP Server mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-1863)

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart Apache
after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3304</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070556"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070559" severity="high">
    <xccdf:title>RHSA-2007:0559: cman security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cman is the Red Hat Cluster Manager.

A flaw was found in the cman daemon.  A local attacker could connect to the
cman daemon and trigger a static buffer overflow leading to a denial of
service or, potentially, an escalation of privileges.  (CVE-2007-3374)

Users of Cluster Manager should upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0559</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070559"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070562" severity="high">
    <xccdf:title>RHSA-2007:0562: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

David Coffey discovered an uninitialized pointer free flaw in the RPC
library used by kadmind.  On Red Hat Enterprise Linux 4 and 5, glibc
detects attempts to free invalid pointers.  A remote unauthenticated
attacker who can access kadmind could trigger this flaw and cause kadmind
to crash. (CVE-2007-2442)

David Coffey also discovered an overflow flaw in the RPC library used by
kadmind.  On Red Hat Enterprise Linux, exploitation of this flaw is limited
to a denial of service.  A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-2443)

A stack buffer overflow flaw was found in kadmind.  An authenticated
attacker who can access kadmind could trigger this flaw and potentially
execute arbitrary code on the Kerberos server. (CVE-2007-2798)

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070562"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070569" severity="medium">
    <xccdf:title>RHSA-2007:0569: tomcat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tomcat is a servlet container for Java Servlet and JavaServer Pages (JSP)
technologies.

Some JSPs within the 'examples' web application did not escape user
provided data. If the JSP examples were accessible, this flaw could allow a
remote attacker to perform cross-site scripting attacks (CVE-2007-2449).

Note: it is recommended the 'examples' web application not be installed on
a production system.

The Manager and Host Manager web applications did not escape user provided
data. If a user is logged in to the Manager or Host Manager web
application, an attacker could perform a cross-site scripting attack
(CVE-2007-2450).

Users of Tomcat should update to these erratum packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2450</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070569"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070595" severity="medium">
    <xccdf:title>RHSA-2007:0595: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain a fix for the following security issue:

* a flaw in the signal handling on PowerPC-based systems that allowed a
local user to cause a denial of service (floating point corruption).
(CVE-2007-3107, Moderate).

In addition to the security issue described above, a fix for the following
have been included:

* a bug that can lead to data corruption with ServerWorks IDE controllers.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3107</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070595"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070605" severity="high">
    <xccdf:title>RHSA-2007:0605: HelixPlayer security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HelixPlayer is a media player.

A buffer overflow flaw was found in the way HelixPlayer processed
Synchronized Multimedia Integration Language (SMIL) files. It was possible
for a malformed SMIL file to execute arbitrary code with the permissions of
the user running HelixPlayer. (CVE-2007-3410)

All users of HelixPlayer are advised to upgrade to this updated package,
which contains a backported patch and is not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3410</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070605"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070631" severity="low">
    <xccdf:title>RHSA-2007:0631: coolkey security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>coolkey contains the driver support for the CoolKey and Common Access Card
(CAC) Smart Card products. The CAC is used by the U.S. Government.

Steve Grubb discovered a flaw in the way coolkey created a temporary
directory. A local attacker could perform a symlink attack and cause
arbitrary files to be overwritten. (CVE-2007-4129)

In addition, the updated packages contain fixes for the following bugs in
the CAC Smart Card support:

* CAC Smart Cards can have from 1 to 3 certificates. The coolkey driver,
however, was not recognizing cards if they had less than 3 certificates.

* logging into a CAC Smart Card token with a new application would cause
other, already authenticated, applications to lose their login status
unless the Smart Card was then removed from the reader and re-inserted.

All CAC users should upgrade to these updated packages, which resolve these
issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0631</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4129</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070631"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070640" severity="medium">
    <xccdf:title>RHSA-2007:0640: conga security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Conga package is a web-based administration tool for remote cluster and
storage management.

A flaw was found in ricci during a code audit.  A remote attacker who is
able to connect to ricci could cause ricci to temporarily refuse additional
connections, a denial of service (CVE-2007-4136).

Fixes in this updated package include:

* The nodename is now set for manual fencing.

* The node log no longer displays in random order.

* A bug that prevented a node from responding when a cluster was deleted is
now fixed.

* A PAM configuration that incorrectly called the deprecated module
pam_stack was removed.

* A bug that prevented some quorum disk configurations from being accepted
is now fixed.

* Setting multicast addresses now works properly.

* rpm -V on luci no longer fails. 

* The user interface rendering time for storage interface is now faster.

* An error message that incorrectly appeared when rebooting nodes during
cluster creation was removed.

* Cluster snaps configuration (an unsupported feature) has been removed
altogether to prevent user confusion. 

* A user permission bug resulting from a luci code error is now fixed.

* luci and ricci init script return codes are now LSB-compliant.

* VG creation on cluster nodes now defaults to "clustered".

* An SELinux AVC bug that prevented users from setting up shared storage on
nodes is now fixed.

* An access error that occurred when attempting to access a cluster node
after its cluster was deleted is now fixed.

* IP addresses can now be used to create clusters. 

* Attempting to configure a fence device no longer results in an
AttributeError.

* Attempting to create a new fence device to a valid cluster no longer
results in a KeyError.

* Several minor user interface validation errors have been fixed, such as
enforcing cluster name length and fence port, etc.

* A browser lock-up that could occur during storage configuration has been
fixed.

* Virtual service creation now works without error.

* The fence_xvm tag is no longer misspelled in the cluster.conf file.

* Luci failover forms are complete and working.
* Rebooting a fresh cluster install no longer generates an error message.

* A bug that prevented failed cluster services from being started is now
fixed.

* A bug that caused some cluster operations (e.g., node delete) to fail on
clusters with mixed-cased cluster names is now fixed.

* Global cluster resources can be reused when constructing cluster
services.

Enhancements in this updated package include:

* Users can now access Conga through Internet Explorer 6.

* Dead nodes can now be evicted from a cluster.

* Shared storage on new clusters is now enabled by default.

* The fence user-interface flow is now simpler.

* A port number is now shown in ricci error messages.

* The kmod-gfs-xen kernel module is now installed when creating a cluster.

* Cluster creation status is now shown visually.

* User names are now sorted for display.

* The fence_xvmd tag can now be added from the dom0 cluster nodes.

* The ampersand character (&amp;) can now be used in fence names.

* All packaged files are now installed with proper owners and permissions.

* New cluster node members are now properly initialized.

* Storage operations can now be completed even if an LVM snapshot is present.

* Users are now informed via dialog when nodes are rebooted as part of a
cluster operation.

* Failover domains are now properly listed for virtual services and
traditional clustered services.

* Luci can now create and distribute keys for fence_xvmd.

All Conga users are advised to upgrade to this update, which applies these
fixes and enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4136</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070640"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070662" severity="medium">
    <xccdf:title>RHSA-2007:0662: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server. 

The Apache HTTP Server did not verify that a process was an Apache child
process before sending it signals. A local attacker with the ability to run
scripts on the Apache HTTP Server could manipulate the scoreboard and cause
arbitrary processes to be terminated which could lead to a denial of
service.  (CVE-2007-3304).

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct this issue. Users should restart Apache
after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0662</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3304</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070662"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070674" severity="medium">
    <xccdf:title>RHSA-2007:0674: perl-Net-DNS security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Net::DNS is a collection of Perl modules that act as a Domain Name System
(DNS) resolver.

A flaw was found in the way Net::DNS generated the ID field in a DNS query.
This predictable ID field could be used by a remote attacker to return
invalid DNS data. (CVE-2007-3377)

A denial of service flaw was found in the way Net::DNS parsed certain DNS
requests. A malformed response to a DNS request could cause the application
using Net::DNS to crash or stop responding. (CVE-2007-3409)

Users of Net::DNS should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3409</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070674"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070675" severity="medium">
    <xccdf:title>RHSA-2007:0675: perl-Net-DNS security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Net::DNS is a collection of Perl modules that act as a Domain Name System
(DNS) resolver.

A flaw was found in the way Net::DNS generated the ID field in a DNS query.
This predictable ID field could be used by a remote attacker to return
invalid DNS data. (CVE-2007-3377)

Users of Net::DNS should upgrade to this updated package, which contains
backported patches to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3377</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070675"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070701" severity="low">
    <xccdf:title>RHSA-2007:0701: xterm security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xterm program is a terminal emulator for the X Window System. It
provides DEC VT102 and Tektronix 4014 compatible terminals for
programs that cannot use the window system directly.

A bug was found in the way xterm packages were built that caused the
pseudo-terminal device files of the xterm emulated terminals to be owned by
the incorrect group. This flaw did not affect Red Hat Enterprise Linux 4
Update 4 and earlier. (CVE-2007-2797)

All users of xterm are advised to upgrade to this updated package, which
contains a patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2797</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070701"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070703" severity="medium">
    <xccdf:title>RHSA-2007:0703: openssh security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the way the ssh server wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

A flaw was found in the way the OpenSSH server processes GSSAPI
authentication requests. When GSSAPI authentication was enabled in OpenSSH
server, a remote attacker may have been able to determine if a username is
valid. (CVE-2006-5052)

The following bugs were also fixed:

* the ssh daemon did not generate audit messages when an ssh session was
closed.

* GSSAPI authentication sometimes failed on clusters using DNS or
load-balancing.

* the sftp client and server leaked small amounts of memory in some cases.

* the sftp client didn't properly exit and return non-zero status in batch
mode when the destination disk drive was full.

* when restarting the ssh daemon with the initscript, the ssh daemon was
sometimes not restarted successfully because the old running ssh daemon was
not properly killed.

* with challenge/response authentication enabled, the pam sub-process was
not terminated if the user authentication timed out.

All users of openssh should upgrade to these updated packages, which
contain patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070703"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070705" severity="high">
    <xccdf:title>RHSA-2007:0705: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the DRM driver for Intel graphics cards that allowed a local
user to access any part of the main memory. To access the DRM functionality
a user must have access to the X server which is granted through the
graphical login. This also only affected systems with an Intel 965 or later
graphic chipset. (CVE-2007-3851, Important)

* a flaw in the VFAT compat ioctl handling on 64-bit systems that allowed a
local user to corrupt a kernel_dirent struct and cause a denial of service
(system crash). (CVE-2007-2878, Important)

* a flaw in the connection tracking support for SCTP that allowed a remote
user to cause a denial of service by dereferencing a NULL pointer.
(CVE-2007-2876, Important)

* flaw in the CIFS filesystem which could cause the umask values of a
process to not be honored. This affected CIFS filesystems where the Unix
extensions are supported. (CVE-2007-3740, Important)

* a flaw in the stack expansion when using the hugetlb kernel on PowerPC
systems that allowed a local user to cause a denial of service.
(CVE-2007-3739, Moderate)

* a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a
denial of service or potential remote access. Exploitation would require
the attacker to be able to send arbitrary frames over the ISDN network to
the victim's machine. (CVE-2007-1217, Moderate)

* a flaw in the cpuset support that allowed a local user to obtain
sensitive information from kernel memory. To exploit this the cpuset
filesystem would have to already be mounted. (CVE-2007-2875, Moderate)

* a flaw in the CIFS handling of the mount option "sec=" that didn't enable
integrity checking and didn't produce any error message. (CVE-2007-3843,
Low)

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1217</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2875</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3851</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070705"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070709" severity="low">
    <xccdf:title>RHSA-2007:0709: wireshark security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's HTTP, iSeries, DCP
ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors. It was possible for
Wireshark to crash or stop responding if it read a malformed packet off the
network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392,
CVE-2007-3393)

Wireshark would interpret certain completion codes incorrectly when
dissecting IPMI traffic. Additionally, IPMI 2.0 packets would be reported
as malformed IPMI traffic.

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.6, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3390</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070709"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070710" severity="low">
    <xccdf:title>RHSA-2007:0710: wireshark security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's HTTP, iSeries, DCP
ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors.  It was possible for
Wireshark to crash or stop responding if it read a malformed packet off the
network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392,
CVE-2007-3393)

Users of Wireshark and Ethereal should upgrade to these updated packages,
containing Wireshark version 0.99.6, which is not vulnerable to these
issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3390</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070710"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070720" severity="high">
    <xccdf:title>RHSA-2007:0720: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Maurycy Prodeus discovered an integer overflow flaw in the way CUPS processes
PDF files.  An attacker could create a malicious PDF file that could
potentially execute arbitrary code when printed.  (CVE-2007-3387)

All users of CUPS should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070720"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070721" severity="medium">
    <xccdf:title>RHSA-2007:0721: qt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

Several format string flaws were found in Qt error message handling.  If an
application linked against Qt created an error message from user supplied
data in a certain way, it could lead to a denial of service or possibly
allow the execution of arbitrary code. (CVE-2007-3388)

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct these issues.

Red Hat would like to acknowledge Tim Brown of Portcullis Computer
Security and Dirk Mueller for these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3388</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070721"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070722" severity="high">
    <xccdf:title>RHSA-2007:0722: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause SeaMonkey to crash or potentially execute arbitrary code as the user
running SeaMonkey. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737, CVE-2007-3738)

Several content injection flaws were found in the way SeaMonkey handled
certain JavaScript code. A web page containing malicious JavaScript code
could inject arbitrary content into other web pages. (CVE-2007-3736,
CVE-2007-3089)

A flaw was found in the way SeaMonkey cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-3656)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3738</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070722"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070723" severity="medium">
    <xccdf:title>RHSA-2007:0723: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML email message containing JavaScript code
could cause Thunderbird to crash or potentially execute arbitrary code as
the user running Thunderbird.  JavaScript support is disabled by default in
Thunderbird; these issues are not exploitable unless the user has enabled
JavaScript. (CVE-2007-3089, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736,
CVE-2007-3737, CVE-2007-3738)

Users of Thunderbird are advised to upgrade to these erratum packages,
which contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3738</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070723"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070724" severity="high">
    <xccdf:title>RHSA-2007:0724: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Firefox to crash or potentially execute arbitrary code as the user
running Firefox. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737, CVE-2007-3738)

Several content injection flaws were found in the way Firefox handled
certain JavaScript code. A web page containing malicious JavaScript code
could inject arbitrary content into other web pages. (CVE-2007-3736,
CVE-2007-3089)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-3656)

Users of Firefox are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3738</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070724"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070729" severity="high">
    <xccdf:title>RHSA-2007:0729: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a PDF file viewer.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause kpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of kdegraphics should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070729"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070730" severity="high">
    <xccdf:title>RHSA-2007:0730: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gpdf is a GNOME based viewer for Portable Document Format (PDF) files. 

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause gpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of gpdf should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070730"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070731" severity="high">
    <xccdf:title>RHSA-2007:0731: tetex security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input and creates a typesetter-independent .dvi
(DeVice Independent) file as output.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause TeTeX to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of TeTeX should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070731"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070732" severity="high">
    <xccdf:title>RHSA-2007:0732: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a PDF rendering library, used by applications such as evince.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause an application linked with poppler to crash or potentially execute
arbitrary code when opened.  (CVE-2007-3387)

All users of poppler should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070732"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070735" severity="high">
    <xccdf:title>RHSA-2007:0735: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files. 

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause Xpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of Xpdf should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070735"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070737" severity="medium">
    <xccdf:title>RHSA-2007:0737: pam security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

A flaw was found in the way pam_console set console device permissions. It
was possible for various console devices to retain ownership of the console
user after logging out, possibly leaking information to another local user.
(CVE-2007-1716)

A flaw was found in the way the PAM library wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages, which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

As well, these updated packages fix the following bugs:

* the pam_xauth module, which is used for copying the X11 authentication
cookie, did not reset the "XAUTHORITY" variable in certain circumstances,
causing unnecessary delays when using su command.

* when calculating password similarity, pam_cracklib disregarded changes
to the last character in passwords when "difok=x" (where "x" is the
number of characters required to change) was configured in
"/etc/pam.d/system-auth". This resulted in password changes that should
have been successful to fail with the following error:

BAD PASSWORD: is too similar to the old one

This issue has been resolved in these updated packages.

* the pam_limits module, which provides setting up system resources limits
for user sessions, reset the nice priority of the user session to "0" if it
was not configured otherwise in the "/etc/security/limits.conf"
configuration file.

These updated packages add the following enhancement:

* a new PAM module, pam_tally2, which allows accounts to be locked after a
maximum number of failed log in attempts.

All users of PAM should upgrade to these updated packages, which resolve
these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070737"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070740" severity="medium">
    <xccdf:title>RHSA-2007:0740: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. 

A flaw was found in the way BIND generates outbound DNS query ids. If an
attacker is able to acquire a finite set of query IDs, it becomes possible
to accurately predict future query IDs. Future query ID prediction may
allow an attacker to conduct a DNS cache poisoning attack, which can result
in the DNS server returning incorrect client query data. (CVE-2007-2926)

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2926</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070740"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070746" severity="medium">
    <xccdf:title>RHSA-2007:0746: httpd security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module. (CVE-2007-3847)

As well, these updated packages fix the following bugs:

* Set-Cookie headers with a status code of 3xx are not forwarded to
clients when the "ProxyErrorOverride" directive is enabled. These
responses are overridden at the proxy. Only the responses with status
codes of 4xx and 5xx are overridden in these updated packages.

* the default "/etc/logrotate.d/httpd" script incorrectly invoked the kill
command, instead of using the "/sbin/service httpd restart" command. If you
configured the httpd PID to be in a location other than
"/var/run/httpd.pid", the httpd logs failed to be rotated. This has been
resolved in these updated packages.

* the "ProxyTimeout" directive was not inherited across virtual host
definitions.

* the logresolve utility was unable to read lines longer the 1024 bytes.

This update adds the following enhancements:

* a new configuration option has been added, "ServerTokens Full-Release",
which adds the package release to the server version string, which is
returned in the "Server" response header.

* a new module has been added, mod_version, which allows configuration
files to be written containing sections, which are evaluated only if the
version of httpd used matches a specified condition.

Users of httpd are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3847</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070746"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070747" severity="medium">
    <xccdf:title>RHSA-2007:0747: httpd security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module. (CVE-2007-3847)

As well, these updated packages fix the following bugs:

* the default "/etc/logrotate.d/httpd" script incorrectly invoked the kill
command, instead of using the "/sbin/service httpd restart" command. If you
configured the httpd PID to be in a location other than
"/var/run/httpd.pid", the httpd logs failed to be rotated. This has been
resolved in these updated packages.

* Set-Cookie headers with a status code of 3xx are not forwarded to
clients when the "ProxyErrorOverride" directive is enabled. These
responses are overridden at the proxy. Only the responses with status
codes of 4xx and 5xx are overridden in these updated packages.

* mod_proxy did not correctly handle percent-encoded characters (ie %20)
when configured as a reverse proxy.

* invalid HTTP status codes could be logged if output filters returned
errors.

* the "ProxyTimeout" directive was not inherited across virtual host
definitions.

* in some cases the Content-Length header was dropped from HEAD responses.
This resulted in certain sites not working correctly with mod_proxy, such
as www.windowsupdate.com.

This update adds the following enhancements:

* a new configuration option has been added, "ServerTokens Full-Release",
which adds the package release to the server version string, which is
returned in the "Server" response header.

* a new module has been added, mod_version, which allows configuration
files to be written containing sections, which are evaluated only if the
version of httpd used matches a specified condition.

Users of httpd are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3847</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070747"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070765" severity="medium">
    <xccdf:title>RHSA-2007:0765: libgtop2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libgtop2 package contains a library for obtaining information about a
running system, such as cpu, memory and disk usage; active processes; and
PIDs.

A flaw was found in the way libgtop2 handled long filenames mapped
into the address space of a process. An attacker could execute arbitrary
code on behalf of the user running gnome-system-monitor by executing a
process and mapping a file with a specially crafted name into the
processes' address space. (CVE-2007-0235)

This update also fixes the following bug:

* when a version of libgtop2 compiled to run on a 32-bit architecture was
used to inspect a process running in 64-bit mode, it failed to report
certain information regarding address space mapping correctly.

All users of gnome-system-monitor are advised to upgrade to this updated
libgtop2 package, which contains backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0765</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070765"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070774" severity="medium">
    <xccdf:title>RHSA-2007:0774: kernel security and bugfix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a
denial of service or potential remote access. Exploitation would require
the attacker to be able to send arbitrary frames over the ISDN network to
the victim's machine. (CVE-2007-1217, Moderate) 

* a flaw in the perfmon subsystem on ia64 platforms that allowed a local
user to cause a denial of service. (CVE-2006-0558, Moderate)

In addition, the following bugs were addressed:

* a panic after reloading of the LSI Fusion driver.

* a vm performance problem was corrected by balancing inactive page lists.

* added a nodirplus option to address NFSv3 performance issues with large
directories.

* changed the personality handling to disallow personality changes of
setuid and setgid binaries. This ensures they keep any randomization and
Exec-shield protection.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1217</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070774"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070777" severity="medium">
    <xccdf:title>RHSA-2007:0777: gdm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Gdm (the GNOME Display Manager) is a highly configurable reimplementation
of xdm, the X Display Manager. Gdm allows you to log into your system with
the X Window System running and supports running several different X
sessions on your local machine at the same time.

A flaw was found in the way Gdm listens on its unix domain socket.  A local
user could crash a running X session by writing malicious data to Gdm's
unix domain socket. (CVE-2007-3381)

All users of gdm should upgrade to this updated package, which contains a
backported patch that resolves this issue.

Red Hat would like to thank JLANTHEA for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3381</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070777"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070779" severity="low">
    <xccdf:title>RHSA-2007:0779: mailman security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage email discussion lists.

A flaw was found in Mailman. A remote attacker could spoof messages in
the error log, and possibly trick the administrator into visiting malicious
URLs via a carriage return/line feed sequence in the URI. (CVE-2006-4624)

As well, these updated packages fix the following bugs:

* canceling a subscription on the confirm subscription request page
caused mailman to crash.

* editing the sender filter caused all spam filter rules to be deleted.

* the migrate-fhs script was not included.

* the mailman init script returned a zero (success) exit code even when
an incorrect command was given. For example, the "mailman foo" command
returned a zero exit code. In these updated packages the mailmain init
script returns the correct exit codes.

Users of Mailman are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4624</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070779"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070795" severity="medium">
    <xccdf:title>RHSA-2007:0795: cyrus-sasl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-sasl package contains the Cyrus implementation of SASL. SASL is
the Simple Authentication and Security Layer, a method for adding
authentication support to connection-based protocols.

A bug was found in cyrus-sasl's DIGEST-MD5 authentication mechanism. As
part of the DIGEST-MD5 authentication exchange, the client is expected to
send a specific set of information to the server. If one of these items
(the "realm") was not sent or was malformed, it was possible for a remote
unauthenticated attacker to cause a denial of service (segmentation fault)
on the server. (CVE-2006-1721)

This errata also fixes the following bugs:

* the Kerberos 5 library included in Red Hat Enterprise Linux 4 was not
thread safe. This update adds functionality which allows it to be used
safely in a threaded application.

* several memory leak bugs were fixed in cyrus-sasl's DIGEST-MD5
authentication plug-in.

* /dev/urandom is now used by default on systems which don't support
hwrandom. Previously, dev/random was the default.

* cyrus-sasl needs zlib-devel to build properly. This dependency
information is now included in the package.

Users are advised to upgrade to this updated cyrus-sasl package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0795</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1721</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070795"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070845" severity="high">
    <xccdf:title>RHSA-2007:0845: libvorbis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvorbis package contains runtime libraries for use in programs that
support Ogg Voribs. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Several flaws were found in the way libvorbis processed audio data. An
attacker could create a carefully crafted OGG audio file in such a way that
it could cause an application linked with libvorbis to crash or execute
arbitrary code when it was opened. (CVE-2007-3106, CVE-2007-4029,
CVE-2007-4065, CVE-2007-4066)

Users of libvorbis are advised to upgrade to this updated package, which
contains backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3106</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4066</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070845"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070848" severity="high">
    <xccdf:title>RHSA-2007:0848: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the TIFF parser.  An attacker could
create a carefully crafted document containing a malicious TIFF file that
could cause OpenOffice.org to crash or possibly execute arbitrary code if
opened by a victim. (CVE-2007-2834)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2834</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070848"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070858" severity="high">
    <xccdf:title>RHSA-2007:0858: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by kadmind.   A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash.  On Red Hat
Enterprise Linux 5 it is not possible to exploit this flaw to run arbitrary
code as the overflow is blocked by FORTIFY_SOURCE.  (CVE-2007-3999)

Garrett Wollman discovered an uninitialized pointer flaw in kadmind.  A
remote unauthenticated attacker who can access kadmind could trigger this
flaw and cause kadmind to crash.  (CVE-2007-4000)

These issues did not affect the versions of Kerberos distributed with Red
Hat Enterprise Linux 2.1, 3, or 4.

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070858"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070860" severity="medium">
    <xccdf:title>RHSA-2007:0860: tar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive. 

A path traversal flaw was discovered in the way GNU tar extracted archives.
A malicious user could create a tar archive that could write to arbitrary
files to which the user running GNU tar had write access. (CVE-2007-4131)

Red Hat would like to thank Dmitry V. Levin for reporting this issue.

Users of tar should upgrade to this updated package, which contains a
replacement backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4131</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070860"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070871" severity="medium">
    <xccdf:title>RHSA-2007:0871: tomcat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tomcat is a servlet container for Java Servlet and Java Server Pages
technologies.

Tomcat was found treating single quote characters -- ' -- as delimiters in
cookies. This could allow remote attackers to obtain sensitive information,
such as session IDs, for session hijacking attacks (CVE-2007-3382).

It was reported Tomcat did not properly handle the following character
sequence in a cookie: \" (a backslash followed by a double-quote). It was
possible remote attackers could use this failure to obtain sensitive
information, such as session IDs, for session hijacking attacks
(CVE-2007-3385).

A cross-site scripting (XSS) vulnerability existed in the Host Manager
Servlet. This allowed remote attackers to inject arbitrary HTML and web
script via crafted requests (CVE-2007-3386).

Users of Tomcat should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3386</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070871"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070873" severity="medium">
    <xccdf:title>RHSA-2007:0873: star security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Star is a tar-like archiver. It saves multiple files into a single tape or
disk archive, and can restore individual files from the archive. Star
includes multi-volume support, automatic archive format detection and ACL
support.

A path traversal flaw was discovered in the way star extracted archives. A
malicious user could create a tar archive that would cause star to write to
arbitrary files to which the user running star had write access.
(CVE-2007-4134)

Red Hat would like to thank Robert Buchholz for reporting this issue.

As well, this update adds the command line argument "-.." to the Red Hat
Enterprise Linux 3 version of star. This allows star to extract files
containing "/../" in their pathname.

Users of star should upgrade to this updated package, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0873</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4134</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070873"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070875" severity="high">
    <xccdf:title>RHSA-2007:0875: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was discovered in MySQL's authentication protocol. It is possible
for a remote unauthenticated attacker to send a specially crafted
authentication request to the MySQL server causing it to crash. (CVE-2007-3780)

All users of the MySQL server are advised to upgrade to these updated
packages, which contain a backported patch which fixes this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0875</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3780</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070875"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070883" severity="high">
    <xccdf:title>RHSA-2007:0883: qt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

A flaw was found in the way Qt expanded certain UTF8 characters. It was
possible to prevent a Qt-based application from properly sanitizing user
supplied input. This could, for example, result in a cross-site scripting
attack against the Konqueror web browser. (CVE-2007-0242)

A buffer overflow flaw was found in the way Qt expanded malformed Unicode
strings. If an application linked against Qt parsed a malicious Unicode
string, it could lead to a denial of service or possibly allow the
execution of arbitrary code. (CVE-2007-4137)

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4137</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070883"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070890" severity="medium">
    <xccdf:title>RHSA-2007:0890: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Various integer overflow flaws were found in the PHP gd extension. A script
that could be forced to resize images from an untrusted source could
possibly allow a remote attacker to execute arbitrary code as the apache
user. (CVE-2007-3996)

An integer overflow flaw was found in the PHP chunk_split function. If a
remote attacker was able to pass arbitrary data to the third argument of
chunk_split they could possibly execute arbitrary code as the apache user.
Note that it is unusual for a PHP script to use the chunk_script function
with a user-supplied third argument. (CVE-2007-2872)

A previous security update introduced a bug into PHP session cookie
handling. This could allow an attacker to stop a victim from viewing a
vulnerable web site if the victim has first visited a malicious web page
under the control of the attacker, and that page can set a cookie for the
vulnerable web site. (CVE-2007-4670)

A flaw was found in the PHP money_format function. If a remote attacker
was able to pass arbitrary data to the money_format function this could
possibly result in an information leak or denial of service. Note that is
is unusual for a PHP script to pass user-supplied data to the money_format
function. (CVE-2007-4658)

A flaw was found in the PHP wordwrap function. If a remote attacker was
able to pass arbitrary data to the wordwrap function this could possibly
result in a denial of service. (CVE-2007-3998)

A bug was found in PHP session cookie handling. This could allow an
attacker to create a cross-site cookie insertion attack if a victim follows
an untrusted carefully-crafted URL. (CVE-2007-3799)

An infinite-loop flaw was discovered in the PHP gd extension. A script
that could be forced to process PNG images from an untrusted source could
allow a remote attacker to cause a denial of service. (CVE-2007-2756)

Users of PHP should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2756</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3996</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4670</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070890"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070892" severity="high">
    <xccdf:title>RHSA-2007:0892: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

The MIT Kerberos Team discovered a problem with the originally published
patch for svc_auth_gss.c (CVE-2007-3999).  A remote unauthenticated
attacker who can access kadmind could trigger this flaw and cause kadmind
to crash.  On Red Hat Enterprise Linux 5 it is not possible to exploit this
flaw to run arbitrary code as the overflow is blocked by FORTIFY_SOURCE.
(CVE-2007-4743)

This issue did not affect the versions of Kerberos distributed with Red
Hat Enterprise Linux 2.1, 3, or 4.

Users of krb5-server are advised to update to these erratum packages which
contain a corrected backported fix for this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0892</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4743</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070892"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070898" severity="medium">
    <xccdf:title>RHSA-2007:0898: xorg-x11 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way X.Org's composite extension handles 32 bit
color depth windows while running in 16 bit color depth mode. If an X.org
server has enabled the composite extension, it may be possible for a
malicious authorized client to cause a denial of service (crash) or
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-4730)

Please note this flaw can only be triggered when using a compositing window
manager. Red Hat Enterprise Linux 4 does not ship with a compositing window
manager.

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4730</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070898"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070905" severity="medium">
    <xccdf:title>RHSA-2007:0905: kdebase security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager.

These updated packages address the following vulnerabilities:

Kees Huijgen found a flaw in the way KDM handled logins when autologin and
"shutdown with password" were enabled.  A local user would have been able
to login via KDM as any user without requiring a password. (CVE-2007-4569)

Two Konqueror address spoofing flaws were discovered. A malicious web site
could spoof the Konqueror address bar, tricking a victim into believing the
page was from a different site. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4569</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070905"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070909" severity="medium">
    <xccdf:title>RHSA-2007:0909: kdelibs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs package provides libraries for the K Desktop Environment (KDE).

Two cross-site-scripting flaws were found in the way Konqueror processes
certain HTML content. This could result in a malicious attacker presenting
misleading content to an unsuspecting user. (CVE-2007-0242, CVE-2007-0537)

A flaw was found in KDE JavaScript implementation.  A web page containing
malicious JavaScript code could cause Konqueror to crash. (CVE-2007-1308)

A flaw was found in the way Konqueror handled certain FTP PASV commands.
A malicious FTP server could use this flaw to perform a rudimentary
port-scan of machines behind a user's firewall. (CVE-2007-1564)

Two Konqueror address spoofing flaws have been discovered. It was
possible for a malicious website to cause the Konqueror address bar to
display information which could trick a user into believing they are at a 
different website than they actually are. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0909</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070909"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070913" severity="high">
    <xccdf:title>RHSA-2007:0913: nfs-utils-lib security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils-lib package contains support libraries that are needed by the
commands and daemons of the nfs-utils package.

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by nfs-utils-lib. A remote unauthenticated attacker who can
access an application linked against nfs-utils-lib could trigger this flaw
and cause the application to crash. On Red Hat Enterprise Linux 4 it is not
possible to exploit this flaw to run arbitrary code as the overflow is
blocked by FORTIFY_SOURCE. (CVE-2007-3999)

Users of nfs-utils-lib are advised to upgrade to this updated package,
which contains a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3999</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070913"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070932" severity="medium">
    <xccdf:title>RHSA-2007:0932: pwlib security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PWLib is a library used to support cross-platform applications.  

In Red Hat Enterprise Linux 5, the Ekiga teleconferencing application uses
PWLib.

A memory management flaw was discovered in PWLib.  An attacker could use this
flaw to crash an application, such as Ekiga, which is linked with pwlib
(CVE-2007-4897).  

Users should upgrade to these updated packages which contain a backported
patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0932</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4897</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070932"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070933" severity="medium">
    <xccdf:title>RHSA-2007:0933: elinks security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ELinks is a text mode Web browser used from the command line that supports
rendering modern web pages.

An information disclosure flaw was found in the way ELinks passes https
POST data to a proxy server. POST data sent via a proxy to an https site is
not properly encrypted by ELinks, possibly allowing the disclosure of
sensitive information. (CVE-2007-5034)

All users of Elinks are advised to upgrade to this updated package, which
contains a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5034</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070933"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070936" severity="high">
    <xccdf:title>RHSA-2007:0936: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

A flaw was found in the IA32 system call emulation provided on AMD64 and
Intel 64 platforms. An improperly validated 64-bit value could be stored in
the %RAX register, which could trigger an out-of-bounds system call table
access. An untrusted local user could exploit this flaw to run code in the
kernel (ie a root privilege escalation). (CVE-2007-4573).

Red Hat would like to thank Wojciech Purczynski for reporting this issue.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0936</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4573</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070936"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070937" severity="high">
    <xccdf:title>RHSA-2007:0937: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

A flaw was found in the IA32 system call emulation provided on AMD64 and
Intel 64 platforms. An improperly validated 64-bit value could be stored in
the %RAX register, which could trigger an out-of-bounds system call table
access. An untrusted local user could exploit this flaw to run code in the
kernel (ie a root privilege escalation). (CVE-2007-4573).

Red Hat would like to thank Wojciech Purczynski for reporting this issue.

Red Hat Enterprise Linux 4 users are advised to upgrade to these packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4573</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070937"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070939" severity="high">
    <xccdf:title>RHSA-2007:0939: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel is the core of the operating system.

These updated kernel packages contain fixes for the following security
issues:

* A flaw was found in the handling of process death signals. This allowed a
local user to send arbitrary signals to the suid-process executed by that
user. A successful exploitation of this flaw depends on the structure of
the suid-program and its signal handling. (CVE-2007-3848, Important)

* A flaw was found in the CIFS file system. This could cause the umask
values of a process to not be honored on CIFS file systems where UNIX
extensions are supported. (CVE-2007-3740, Important)

* A flaw was found in the VFAT compat ioctl handling on 64-bit systems. 
This allowed a local user to corrupt a kernel_dirent struct and cause a
denial of service. (CVE-2007-2878, Important) 

* A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local
user who had the ability to read the /proc/driver/snd-page-alloc file could
see portions of kernel memory. (CVE-2007-4571, Moderate) 

* A flaw was found in the aacraid SCSI driver. This allowed a local user to
make ioctl calls to the driver that should be restricted to privileged
users. (CVE-2007-4308, Moderate) 

* A flaw was found in the stack expansion when using the hugetlb kernel on
PowerPC systems. This allowed a local user to cause a denial of service.
(CVE-2007-3739, Moderate) 

* A flaw was found in the handling of zombie processes. A local user could
create processes that would not be properly reaped which could lead to a
denial of service. (CVE-2006-6921, Moderate)

* A flaw was found in the CIFS file system handling. The mount option
"sec=" did not enable integrity checking or produce an error message if
used. (CVE-2007-3843, Low)

* A flaw was found in the random number generator implementation that
allowed a local user to cause a denial of service or possibly gain
privileges. This flaw could be exploited if the root user raised the
default wakeup threshold over the size of the output pool.
(CVE-2007-3105, Low)

Additionally, the following bugs were fixed:

* A flaw was found in the kernel netpoll code, creating a potential
deadlock condition.  If the xmit_lock for a given network interface is
held, and a subsequent netpoll event is generated from within the lock
owning context (a console message for example), deadlock on that cpu will
result, because the netpoll code will attempt to re-acquire the xmit_lock.
 The fix is to, in the netpoll code, only attempt to take the lock, and
fail if it is already acquired (rather than block on it), and queue the
message to be sent for later delivery.  Any user of netpoll code in the
kernel (netdump or netconsole services), is exposed to this problem, and
should resolve the issue by upgrading to this kernel release immediately.

* A flaw was found where, under 64-bit mode (x86_64), AMD processors were
not able to address greater than a 40-bit physical address space; and Intel
processors were only able to address up to a 36-bit physical address space. 
The fix is to increase the physical addressing for an AMD processor to 48
bits, and an Intel processor to 38 bits.  Please see the Red Hat
Knowledgebase for more detailed information.

* A flaw was found in the xenU kernel that may prevent a paravirtualized
guest with more than one CPU from starting when running under an Enterprise
Linux 5.1 hypervisor.  The fix is to allow your Enterprise Linux 4 Xen SMP
guests to boot under a 5.1 hypervisor. Please see the Red Hat Knowledgebase
for more detailed information.
 
Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6921</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4571</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070939"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070940" severity="high">
    <xccdf:title>RHSA-2007:0940: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* A flaw was found in the backported stack unwinder fixes in Red Hat
Enterprise Linux 5.  On AMD64 and Intel 64 platforms, a local user could
trigger this flaw and cause a denial of service. (CVE-2007-4574, Important)

* A flaw was found in the handling of process death signals. This allowed a
local user to send arbitrary signals to the suid-process executed by that
user. A successful exploitation of this flaw depends on the structure of
the suid-program and its signal handling. (CVE-2007-3848, Important)

* A flaw was found in the Distributed Lock Manager (DLM) in the cluster
manager. This allowed a remote user who is able to connect to the DLM port
to cause a denial of service. (CVE-2007-3380, Important)

* A flaw was found in the aacraid SCSI driver. This allowed a local user to
make ioctl calls to the driver which should otherwise be restricted to
privileged users. (CVE-2007-4308, Moderate)

* A flaw was found in the prio_tree handling of the hugetlb support that
allowed a local user to cause a denial of service. This only affected
kernels with hugetlb support. (CVE-2007-4133, Moderate)

* A flaw was found in the eHCA driver on PowerPC architectures that allowed
a local user to access 60k of physical address space. This address space
could contain sensitive information. (CVE-2007-3850, Moderate)

* A flaw was found in ptrace support that allowed a local user to cause a
denial of service via a NULL pointer dereference. (CVE-2007-3731, Moderate)

* A flaw was found in the usblcd driver that allowed a local user to cause
a denial
of service by writing data to the device node. To exploit this issue, write
access to the device node was needed. (CVE-2007-3513, Moderate)

* A flaw was found in the random number generator implementation that
allowed a local user to cause a denial of service or possibly gain
privileges. If the root user raised the default wakeup threshold over the
size of the output pool, this flaw could be exploited. (CVE-2007-3105, Low)

In addition to the security issues described above, several bug fixes
preventing possible system crashes and data corruption were also included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3850</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4133</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4574</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070940"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070951" severity="high">
    <xccdf:title>RHSA-2007:0951: nfs-utils-lib security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils-lib package contains support libraries that are needed by the
commands and daemons of the nfs-utils package.

The updated nfs-utils package fixes the following vulnerabilities:

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by nfs-utils-lib. A remote unauthenticated attacker who can
access an application linked against nfs-utils-lib could trigger this flaw
and cause the application to crash. On Red Hat Enterprise Linux 5 it is not
possible to exploit this flaw to run arbitrary code as the overflow is
blocked by FORTIFY_SOURCE. (CVE-2007-3999)

Tony Ernst from SGI has discovered a flaw in the way nfsidmap maps NFSv4
unknown uids.  If an unknown user ID is encountered on an NFSv4 mounted
filesystem, the files will default to being owned by 'root' rather than
'nobody'. (CVE-2007-4135)

Users of nfs-utils-lib are advised to upgrade to this updated package,
which contains backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0951</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4135</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070951"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070957" severity="medium">
    <xccdf:title>RHSA-2007:0957: opal security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Open Phone Abstraction Library (opal) is implementation of various
telephony and video communication protocols for use over packet based 
networks.

In Red Hat Enterprise Linux 5, the Ekiga application uses opal.

A flaw was discovered in the way opal handled certain Session Initiation 
Protocol (SIP) packets.  An attacker could use this flaw to crash an 
application, such as Ekiga, which is linked with opal. (CVE-2007-4924)

Users should upgrade to these updated opal packages which contain a 
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4924</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070957"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070960" severity="high">
    <xccdf:title>RHSA-2007:0960: hplip security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The hplip (Hewlett-Packard Linux Imaging and Printing Project) package
provides drivers for HP printers and multi-function peripherals.

Kees Cook discovered a flaw in the way the hplip hpssd daemon handled user
input. A local attacker could send a specially crafted request to the hpssd
daemon, possibly allowing them to run arbitrary commands as the root user.
(CVE-2007-5208). On Red Hat Enterprise Linux 5, the SELinux targeted
policy for hpssd which is enabled by default, blocks the ability to exploit
this issue to run arbitrary code.

Users of hplip are advised to upgrade to this updated package, which
contains backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5208</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070960"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070961" severity="medium">
    <xccdf:title>RHSA-2007:0961: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for object-oriented programming.

A flaw was discovered in the way Ruby's CGI module handles certain HTTP
requests. If a remote attacker sends a specially crafted request, it is
possible to cause the ruby CGI script to enter an infinite loop, possibly
causing a denial of service. (CVE-2006-6303)

An SSL certificate validation flaw was discovered in several Ruby Net
modules. The libraries were not checking the requested host name against
the common name (CN) in the SSL server certificate, possibly allowing a man
in the middle attack. (CVE-2007-5162, CVE-2007-5770)

Users of Ruby should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5770</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070961"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070964" severity="high">
    <xccdf:title>RHSA-2007:0964: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library. Datagram TLS (DTLS) is a protocol
based on TLS that is capable of securing datagram transport (UDP for
instance). 

The OpenSSL security team discovered a flaw in DTLS support.  An attacker
could create a malicious client or server that could trigger a heap
overflow. This is possibly exploitable to run arbitrary code, but it has
not been verified  (CVE-2007-4995). Note that this flaw only affects
applications making use of DTLS. Red Hat does not ship any DTLS client or
server applications in Red Hat Enterprise Linux.

A flaw was found in the SSL_get_shared_ciphers() utility function. An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer with a single byte (CVE-2007-5135). Few
applications make use of this vulnerable function and generally it is used
only when applications are compiled for debugging.

A number of possible side-channel attacks were discovered affecting
OpenSSL. A local attacker could possibly obtain RSA private keys being
used on a system. In practice these attacks would be difficult to perform
outside of a lab environment. This update contains backported patches
designed to mitigate these issues.  (CVE-2007-3108).

Users of OpenSSL should upgrade to these updated packages, which contain
backported patches to resolve these issues.  

Please note that the fix for the DTLS flaw involved an overhaul of the DTLS
handshake processing which may introduce incompatibilities if a new client
is used with an older server.

After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5135</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070964"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070965" severity="medium">
    <xccdf:title>RHSA-2007:0965: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for object-oriented programming.

An SSL certificate validation flaw was discovered in several Ruby Net
modules. The libraries were not checking the requested host name against
the common name (CN) in the SSL server certificate, possibly allowing a man
in the middle attack. (CVE-2007-5162, CVE-2007-5770)

Users of Ruby should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0965</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5770</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070965"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070966" severity="high">
    <xccdf:title>RHSA-2007:0966: perl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

A flaw was found in Perl's regular expression engine. Specially crafted
input to a regular expression can cause Perl to improperly allocate memory,
possibly resulting in arbitrary code running with the permissions of the
user running Perl. (CVE-2007-5116)

Users of Perl are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5116</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070966"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070967" severity="high">
    <xccdf:title>RHSA-2007:0967: pcre security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

Multiple flaws were found in the way pcre handles certain malformed regular
expressions. If an application linked against pcre, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2007-1659, CVE-2007-1660)

Users of pcre are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0967</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1660</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070967"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070968" severity="high">
    <xccdf:title>RHSA-2007:0968: pcre security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

Multiple flaws were found in the way pcre handles certain malformed regular
expressions. If an application linked against pcre, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2007-1660)

Users of pcre are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0968</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1660</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070968"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070969" severity="medium">
    <xccdf:title>RHSA-2007:0969: util-linux security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. 

A flaw was discovered in the way that the mount and umount utilities
used the setuid and setgid functions, which could lead to privileges being
dropped improperly.  A local user could use this flaw to run mount helper
applications such as, mount.nfs, with additional privileges (CVE-2007-5191).

Users are advised to update to these erratum packages which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0969</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5191</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070969"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070975" severity="high">
    <xccdf:title>RHSA-2007:0975: flac security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FLAC is a Free Lossless Audio Codec.  The flac package consists of a FLAC
encoder and decoder in library form, a program to encode and decode FLAC
files, a metadata editor for FLAC files and input plugins for various music
players.

A security flaw was found in the way flac processed audio data. An
attacker could create a carefully crafted FLAC audio file in such a way that
it could cause an application linked with flac libraries to crash or execute
arbitrary code when it was opened. (CVE-2007-4619)

Users of flac are advised to upgrade to this updated package, which
contains a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6277</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070975"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070979" severity="high">
    <xccdf:title>RHSA-2007:0979: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way in which Firefox processed certain
malformed web content. A web page containing malicious content could cause
Firefox to crash or potentially execute arbitrary code as the user running
Firefox. (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which Firefox displayed malformed
web content. A web page containing specially-crafted content could
potentially trick a user into surrendering sensitive information.
(CVE-2007-1095, CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)

A flaw was found in the Firefox sftp protocol handler. A malicious web page
could access data from a remote sftp site, possibly stealing sensitive user
data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which Firefox generates a
digest authentication request. If a user opened a specially-crafted URL, it
was possible to perform cross-site scripting attacks, web cache poisoning,
or other, similar exploits. (CVE-2007-2292)

All users of Firefox are advised to upgrade to these updated packages,
which contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5334</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5340</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070979"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070980" severity="high">
    <xccdf:title>RHSA-2007:0980: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way in which SeaMonkey processed certain
malformed web content. A web page containing malicious content could cause
SeaMonkey to crash or potentially execute arbitrary code as the user
running SeaMonkey. (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which SeaMonkey displayed malformed
web content. A web page containing specially-crafted content could
potentially trick a user into surrendering sensitive information. 
(CVE-2007-1095, CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)

A flaw was found in the SeaMonkey sftp protocol handler. A malicious web
page could access data from a remote sftp site, possibly stealing sensitive
user data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which SeaMonkey generates
a digest authentication request. If a user opened a specially-crafted URL,
it was possible to perform cross-site scripting attacks, web cache
poisoning, or other, similar exploits. (CVE-2007-2292)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0980</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5334</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5340</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070980"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070981" severity="medium">
    <xccdf:title>RHSA-2007:0981: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way in which Thunderbird processed certain
malformed HTML mail content. An HTML mail message containing malicious
content could cause Thunderbird to crash or potentially execute arbitrary
code as the user running Thunderbird. JavaScript support is disabled by
default in Thunderbird; these issues are not exploitable unless the user
has enabled JavaScript.  (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which Thunderbird displayed
malformed HTML mail content. An HTML mail message containing
specially-crafted content could potentially trick a user into surrendering
sensitive information.  (CVE-2007-1095, CVE-2007-3844, CVE-2007-3511,
CVE-2007-5334)

A flaw was found in the Thunderbird sftp protocol handler. A malicious HTML
mail message could access data from a remote sftp site, possibly stealing
sensitive user data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which Thunderbird
generates a digest authentication request. If a user opened a
specially-crafted URL, it was possible to perform cross-site scripting
attacks, web cache poisoning, or other, similar exploits. (CVE-2007-2292)

Users of Thunderbird are advised to upgrade to these erratum packages,
which contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5334</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5340</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070992" severity="medium">
    <xccdf:title>RHSA-2007:0992: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

Several flaws were discovered in the way libpng handled various PNG image
chunks.  An attacker could create a carefully crafted PNG image file in
such a way that it could cause an application linked with libpng to crash
when the file was manipulated. (CVE-2007-5269)

Users should update to these updated packages which contain a backported
patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5269</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070992"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20070993" severity="high">
    <xccdf:title>RHSA-2007:0993: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

A memory leak was found in the Red Hat Content Accelerator kernel patch.  A
local user could use this flaw to cause a denial of service (memory
exhaustion). (CVE-2007-5494, Important)

A flaw was found in the handling of IEEE 802.11 frames affecting several
wireless LAN modules.  In certain circumstances, a remote attacker could
trigger this flaw by sending a malicious packet over a wireless network and
cause a denial of service (kernel crash). (CVE-2007-4997, Important). 

A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local
user who had the ability to read the /proc/driver/snd-page-alloc file could
see portions of kernel memory. (CVE-2007-4571, Moderate). 

In addition to the security issues described above, several bug fixes
preventing possible memory corruption, system crashes, SCSI I/O fails,
networking drivers performance regression and journaling block device layer
issue were also included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to resolve these issues.

Red Hat would like to credit Vasily Averin, Chris Evans, and Neil Kettle 
for reporting the security issues corrected by this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:0993</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20070993"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071003" severity="medium">
    <xccdf:title>RHSA-2007:1003: openssl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, and is also a
full-strength general-purpose cryptography library.

A flaw was found in the SSL_get_shared_ciphers() utility function. An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer by a single byte (CVE-2007-5135). Few
applications make use of this vulnerable function and generally it is used
only when applications are compiled for debugging. 

A number of possible side-channel attacks were discovered affecting
OpenSSL. A local attacker could possibly obtain RSA private keys being used
on a system. In practice these attacks would be difficult to perform
outside of a lab environment. This update contains backported patches to
mitigate these issues. (CVE-2007-3108)

As well, these updated packages fix the following bugs:

* multithreaded applications could cause a segmentation fault or deadlock
when calling the random number generator initialization (RAND_poll) in the
OpenSSL library, for a large number of threads simultaneously.

* in certain circumstances, if an application using the OpenSSL library
reused the SSL session cache for multiple purposes (with various parameters
of the SSL protocol), the session parameters could be mismatched.

* a segmentation fault could occur when a corrupted pkcs12 file was being
loaded using the "openssl pkcs12 -in [pkcs12-file]" command, where
[pkcs12-file] is the pkcs12 file.

Users of OpenSSL should upgrade to these updated packages, which contain
backported patches to resolve these issues.

Note: After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5135</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071016" severity="high">
    <xccdf:title>RHSA-2007:1016: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap-based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

A flaw was found in the way Samba assigned group IDs under certain
conditions. If the "winbind nss info" parameter in smb.conf is set to
either "sfu" or "rfc2307", Samba users are incorrectly assigned the group
ID of 0. (CVE-2007-4138)

Red Hat would like to thank Alin Rad Pop of Secunia Research, Rick King,
and the Samba developers for responsibly disclosing these issues.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4572</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5398</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071017" severity="high">
    <xccdf:title>RHSA-2007:1017: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

A flaw was found in the way Samba assigned group IDs under certain
conditions. If the "winbind nss info" parameter in smb.conf is set to
either "sfu" or "rfc2307", Samba users are incorrectly assigned the group
ID of 0. (CVE-2007-4138)

Red Hat would like to thank Alin Rad Pop of Secunia Research, Rick King,
and the Samba developers for responsibly disclosing these issues.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4572</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5398</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071017"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071020" severity="high">
    <xccdf:title>RHSA-2007:1020: cups security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A flaw was found in the way CUPS handles certain Internet Printing Protocol
(IPP) tags. A remote attacker who is able to connect to the IPP TCP port
could send a malicious request causing the CUPS daemon to crash, or
potentially execute arbitrary code. Please note that the default CUPS
configuration does not allow remote hosts to connect to the IPP TCP port.
(CVE-2007-4351)

Red Hat would like to thank Alin Rad Pop for reporting this issue.

All CUPS users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.

In addition, the following bugs were fixed:

* the CUPS service has been changed to start after sshd, to avoid causing
delays when logging in when the system is booted.

* the logrotate settings have been adjusted so they do not cause CUPS to
reload its configuration. This is to avoid re-printing the current job,
which could occur when it was a long-running job.

* a bug has been fixed in the handling of the If-Modified-Since: HTTP
header.

* in the LSPP configuration, labels for labeled jobs did not line-wrap.
This has been fixed.

* an access check in the LSPP configuration has been made more secure.

* the cups-lpd service no longer ignores the "-odocument-format=..."
option.

* a memory allocation bug has been fixed in cupsd.

* support for UNIX domain sockets authentication without passwords has been
added.

* in the LSPP configuration, a problem that could lead to cupsd crashing
has been fixed.

* the error handling in the initscript has been improved.

* The job-originating-host-name attribute was not correctly set for jobs
submitted via the cups-lpd service. This has been fixed.

* a problem with parsing IPv6 addresses in the configuration file has been
fixed.

* a problem that could lead to cupsd crashing when it failed to open a
"file:" URI has been fixed.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4351</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071020"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071021" severity="high">
    <xccdf:title>RHSA-2007:1021: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause CUPS to crash
or potentially execute arbitrary code when printed. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071021"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071022" severity="high">
    <xccdf:title>RHSA-2007:1022: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause CUPS to crash
or potentially execute arbitrary code when printed.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.
A remote attacker who is able to connect to the IPP TCP port could send a
malicious request causing the CUPS daemon to crash. (CVE-2007-4351)

A flaw was found in the way CUPS handled SSL negotiation. A remote attacker
capable of connecting to the CUPS daemon could cause CUPS to crash.
(CVE-2007-4045)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071022"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071024" severity="high">
    <xccdf:title>RHSA-2007:1024: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment. This includes kpdf, a PDF file viewer.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause kpdf to crash,
or potentially execute arbitrary code when opened. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071024"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071025" severity="high">
    <xccdf:title>RHSA-2007:1025: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gpdf is a GNOME-based viewer for Portable Document Format (PDF) files. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause gpdf to crash,
or potentially execute arbitrary code when opened.  
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071025"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071026" severity="high">
    <xccdf:title>RHSA-2007:1026: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a PDF rendering library, used by applications such as evince. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause an application
linked with poppler to crash, or potentially execute arbitrary code when
opened. (CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071026"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071027" severity="high">
    <xccdf:title>RHSA-2007:1027: tetex security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (dvi) file as output. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause TeTeX to crash
or potentially execute arbitrary code when opened. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

A flaw was found in the t1lib library, used in the handling of Type 1
fonts. An attacker could create a malicious file that would cause TeTeX to
crash, or potentially execute arbitrary code when opened. (CVE-2007-4033)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071027"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071029" severity="high">
    <xccdf:title>RHSA-2007:1029: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause Xpdf to crash,
or potentially execute arbitrary code when opened.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071029"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071037" severity="high">
    <xccdf:title>RHSA-2007:1037: openldap security and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP's slapd daemon handled malformed
objectClasses LDAP attributes.  A local or remote attacker could create an
LDAP request which could cause a denial of service by crashing slapd.
(CVE-2007-5707)

In addition, the following feature was added: 
* OpenLDAP client tools now have new option to configure their bind timeout.

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue and provide this security
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1037</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5707</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071037"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071038" severity="medium">
    <xccdf:title>RHSA-2007:1038: openldap security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP's slapd daemon handled malformed
objectClasses LDAP attributes.  An authenticated local or remote attacker
could create an LDAP request which could cause a denial of service by
crashing slapd. (CVE-2007-5707)

In addition, the following feature was added:
* OpenLDAP client tools now have new option to configure their bind timeout.

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue and provide this security
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5707</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071038"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071045" severity="medium">
    <xccdf:title>RHSA-2007:1045: net-snmp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Simple Network Management Protocol (SNMP) is a protocol used for network
management.

A flaw was discovered in the way net-snmp handled certain requests. A
remote attacker who can connect to the snmpd UDP port (161 by default)
could send a malicious packet causing snmpd to crash, resulting in a
denial of service. (CVE-2007-5846)

All users of net-snmp are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5846</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071045"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071048" severity="medium">
    <xccdf:title>RHSA-2007:1048: openoffice.org, hsqldb security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite.
HSQLDB is a Java relational database engine used by OpenOffice.org Base.

It was discovered that HSQLDB could allow the execution of arbitrary public
static Java methods. A carefully crafted odb file opened in OpenOffice.org
Base could execute arbitrary commands with the permissions of the user
running OpenOffice.org. (CVE-2007-4575)

It was discovered that HSQLDB did not have a password set on the 'sa' user.
 If HSQLDB has been configured as a service, a remote attacker who could
connect to the HSQLDB port (tcp 9001) could execute arbitrary SQL commands.
(CVE-2003-0845)

Note that in Red Hat Enterprise Linux 5, HSQLDB is not enabled as a service
by default, and needs manual configuration in order to work as a service.

Users of OpenOffice.org or HSQLDB should update to these errata packages
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1048</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2003-0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4575</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071048"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071051" severity="high">
    <xccdf:title>RHSA-2007:1051: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment. This includes kpdf, a PDF file viewer.

Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker
could create a malicious PDF file that would cause kpdf to crash, or
potentially execute arbitrary code when opened. (CVE-2007-5393)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5393</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071051"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071052" severity="high">
    <xccdf:title>RHSA-2007:1052: pcre security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

Flaws were found in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2005-4872, CVE-2006-7227)

Users of PCRE are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7227</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071052"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071059" severity="high">
    <xccdf:title>RHSA-2007:1059: pcre security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

Flaws were discovered in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may have been possible to run
arbitrary code as the user running the application.
(CVE-2006-7225, CVE-2006-7226, CVE-2006-7228, CVE-2006-7230)

Users of PCRE are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.

Red Hat would like to thank Ludwig Nussel for reporting these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7225</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7226</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7230</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071059"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071068" severity="high">
    <xccdf:title>RHSA-2007:1068: pcre security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

Flaws were discovered in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may have been possible to run
arbitrary code as the user running the application.
(CVE-2006-7225, CVE-2006-7226, CVE-2006-7228, CVE-2006-7230, CVE-2007-1659)

Users of PCRE are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.

Red Hat would like to thank Ludwig Nussel for reporting these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7225</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7226</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7230</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1659</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071068"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071076" severity="medium">
    <xccdf:title>RHSA-2007:1076: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

An integer overflow flaw was discovered in the way Python's pcre module
handled certain regular expressions. If a Python application used the pcre
module to compile and execute untrusted regular expressions, it may be
possible to cause the application to crash, or allow arbitrary code
execution with the privileges of the Python interpreter. (CVE-2006-7228)

A flaw was discovered in the strxfrm() function of Python's locale module.
Strings generated by this function were not properly NULL-terminated. This
may possibly cause disclosure of data stored in the memory of a Python
application using this function. (CVE-2007-2052)

Multiple integer overflow flaws were discovered in Python's imageop module.
If an application written in Python used the imageop module to process
untrusted images, it could cause the application to crash, enter an
infinite loop, or possibly execute arbitrary code with the privileges of
the Python interpreter. (CVE-2007-4965)

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4965</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071076"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071078" severity="high">
    <xccdf:title>RHSA-2007:1078: cairo security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Cairo is a vector graphics library designed to provide high-quality display
and print output.

An integer overflow flaw was found in the way Cairo processes PNG images.
If an application linked against Cairo processes a malicious PNG image, it
is possible to execute arbitrary code as the user running the application.
(CVE-2007-5503)

Users of Cairo are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5503</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071078"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071082" severity="high">
    <xccdf:title>RHSA-2007:1082: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

A cross-site scripting flaw was found in the way Firefox handled the
jar: URI scheme. It was possible for a malicious website to leverage this
flaw and conduct a cross-site scripting attack against a user running
Firefox. (CVE-2007-5947)

Several flaws were found in the way Firefox processed certain malformed web
content. A webpage containing malicious content could cause Firefox to
crash, or potentially execute arbitrary code as the user running Firefox.
(CVE-2007-5959)

A race condition existed when Firefox set the "window.location" property
for a webpage. This flaw could allow a webpage to set an arbitrary Referer
header, which may lead to a Cross-site Request Forgery (CSRF) attack
against websites that rely only on the Referer header for protection.
(CVE-2007-5960)

Users of Firefox are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5960</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071082"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071083" severity="medium">
    <xccdf:title>RHSA-2007:1083: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A cross-site scripting flaw was found in the way Thunderbird handled the
jar: URI scheme. It may be possible for a malicious HTML mail message to
leverage this flaw, and conduct a cross-site scripting attack against a
user running Thunderbird. (CVE-2007-5947)

Several flaws were found in the way Thunderbird processed certain malformed
HTML mail content. A HTML mail message containing malicious content could
cause Thunderbird to crash, or potentially execute arbitrary code as the
user running Thunderbird. (CVE-2007-5959)

A race condition existed when Thunderbird set the "window.location"
property when displaying HTML mail content. This flaw could allow a HTML
mail message to set an arbitrary Referer header, which may lead to a
Cross-site Request Forgery (CSRF) attack against websites that rely only on
the Referer header for protection. (CVE-2007-5960) 

All users of thunderbird are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5960</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071083"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071084" severity="high">
    <xccdf:title>RHSA-2007:1084: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A cross-site scripting flaw was found in the way SeaMonkey handled the
jar: URI scheme. It was possible for a malicious website to leverage this
flaw and conduct a cross-site scripting attack against a user running
SeaMonkey. (CVE-2007-5947)

Several flaws were found in the way SeaMonkey processed certain malformed
web content. A webpage containing malicious content could cause SeaMonkey
to crash, or potentially execute arbitrary code as the user running
SeaMonkey. (CVE-2007-5959)

A race condition existed when Seamonkey set the "window.location" property
for a webpage. This flaw could allow a webpage to set an arbitrary Referer
header, which may lead to a Cross-site Request Forgery (CSRF) attack
against websites that rely only on the Referer header for protection.
(CVE-2007-5960)

Users of SeaMonkey are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5960</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071084"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071090" severity="medium">
    <xccdf:title>RHSA-2007:1090: openoffice.org2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite.
HSQLDB is the default database engine shipped with OpenOffice.org 2.

It was discovered that HSQLDB could allow the execution of arbitrary public
static Java methods.  A carefully crafted odb file opened in OpenOffice.org
Base could execute arbitrary commands with the permissions of the user
running OpenOffice.org. (CVE-2007-4575)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4575</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071095" severity="medium">
    <xccdf:title>RHSA-2007:1095: htdig security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ht://Dig system is a complete World Wide Web indexing and searching
system for a small domain or intranet.

A cross-site scripting flaw was discovered in a htdig search page. An
attacker could construct a carefully crafted URL, which once visited by an 
unsuspecting user, could cause a user's Web browser to execute malicious
script in the context of the visited htdig search Web page. (CVE-2007-6110)

Users of htdig are advised to upgrade to these updated packages, which
contain backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6110</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071095"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071104" severity="high">
    <xccdf:title>RHSA-2007:1104: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system. 

These updated packages fix the following security issues:

A flaw was found in the handling of IEEE 802.11 frames, which affected
several wireless LAN modules. In certain situations, a remote attacker
could trigger this flaw by sending a malicious packet over a wireless
network, causing a denial of service (kernel crash).
(CVE-2007-4997, Important)

A memory leak was found in the Red Hat Content Accelerator kernel patch.
A local user could use this flaw to cause a denial of service (memory
exhaustion). (CVE-2007-5494, Important)

Additionally, the following bugs were fixed:

* when running the "ls -la" command on an NFSv4 mount point, incorrect
file attributes, and outdated file size and timestamp information were
returned. As well, symbolic links may have been displayed as actual files.

* a bug which caused the cmirror write path to appear deadlocked after a
successful recovery, which may have caused syncing to hang, has been
resolved.

* a kernel panic which occurred when manually configuring LCS interfaces on
the IBM S/390 has been resolved.

* when running a 32-bit binary on a 64-bit system, it was possible to
mmap page at address 0 without flag MAP_FIXED set. This has been
resolved in these updated packages.

* the Non-Maskable Interrupt (NMI) Watchdog did not increment the NMI
interrupt counter in "/proc/interrupts" on systems running an AMD Opteron
CPU. This caused systems running NMI Watchdog to restart at regular
intervals.

* a bug which caused the diskdump utility to run very slowly on devices
using Fusion MPT has been resolved.

All users are advised to upgrade to these updated packages, which resolve
these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1104</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071104"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071114" severity="high">
    <xccdf:title>RHSA-2007:1114: samba security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A stack buffer overflow flaw was found in the way Samba authenticates
remote users. A remote unauthenticated user could trigger this flaw to
cause the Samba server to crash, or execute arbitrary code with the
permissions of the Samba server. (CVE-2007-6015)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

This update also fixes a regression caused by the fix for CVE-2007-4572,
which prevented some clients from being able to properly access shares.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071114"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071128" severity="high">
    <xccdf:title>RHSA-2007:1128: autofs security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon, which
automatically mounts and unmounts file systems after a period of
inactivity. 

There was a security issue with the default installed configuration of
autofs version 5 whereby the entry for the "hosts" map did not specify the
"nosuid" mount option.  A local user with control of a remote nfs server
could create a setuid root executable within an exported filesystem on the
remote nfs server that, if mounted using the default hosts map, would allow
the user to gain root privileges. (CVE-2007-5964) 

Due to the fact that autofs always mounted hosts map entries suid by
default, autofs has now been altered to always use the "nosuid" option when
mounting from the default hosts map. The "suid" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the hosts map which corresponds to the /net entry in the
default configuration.

Users are advised to upgrade to these updated autofs packages, which
resolve this issue.

Red Hat would like to thank Josh Lange for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071128"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071129" severity="high">
    <xccdf:title>RHSA-2007:1129: autofs5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon, which
automatically mounts and unmounts file systems after a period of
inactivity.  The autofs version 5 package was made available as a
technology preview in Red Hat Enterprise Linux version 4.6.

There was a security issue with the default installed configuration of
autofs version 5 whereby the entry for the "hosts" map did not specify the
"nosuid" mount option. A local user with control of a remote nfs server
could create a setuid root executable within an exported filesystem on the
remote nfs server that, if mounted using the default hosts map, would allow
the user to gain root privileges. (CVE-2007-5964)

Due to the fact that autofs version 5 always mounted hosts map entries suid
by default, autofs has now been altered to always use the "nosuid" option
when mounting from the default hosts map. The "suid" option must be
explicitly given in the master map entry to revert to the old behavior.
This change affects only the hosts map which corresponds to the /net entry
in the default configuration.

Users are advised to upgrade to these updated autofs5 packages, which
resolve this issue.

Red Hat would like to thank Josh Lange for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1129</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071129"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071130" severity="medium">
    <xccdf:title>RHSA-2007:1130: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A flaw was found in the way squid stored HTTP headers for cached objects
in system memory. An attacker could cause squid to use additional memory,
and trigger high CPU usage when processing requests for certain cached
objects, possibly leading to a denial of service. (CVE-2007-6239)

Users of squid are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6239</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071130"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071155" severity="high">
    <xccdf:title>RHSA-2007:1155: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

A flaw was found in a way MySQL handled symbolic links when database tables
were created with explicit "DATA" and "INDEX DIRECTORY" options. An
authenticated user could create a table that would overwrite tables in
other databases, causing destruction of data or allowing the user to
elevate privileges. (CVE-2007-5969)

A flaw was found in a way MySQL's InnoDB engine handled spatial indexes. An
authenticated user could create a table with spatial indexes, which are not
supported by the InnoDB engine, that would cause the mysql daemon to crash
when used. This issue only causes a temporary denial of service, as the
mysql daemon will be automatically restarted after the crash.
(CVE-2007-5925)

All mysql users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5969</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071155"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071165" severity="medium">
    <xccdf:title>RHSA-2007:1165: libexif security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libexif packages contain the Exif library. Exif is an image file format
specification that enables metadata tags to be added to existing JPEG, TIFF
and RIFF files. The Exif library makes it possible to parse an Exif file
and read this metadata.

An infinite recursion flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to crash. (CVE-2007-6351)

An integer overflow flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to execute arbitrary code, or crash.
(CVE-2007-6352)

Users of libexif are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6352</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071165"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071166" severity="medium">
    <xccdf:title>RHSA-2007:1166: libexif security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libexif packages contain the Exif library. Exif is an image file format
specification that enables metadata tags to be added to existing JPEG, TIFF
and RIFF files. The Exif library makes it possible to parse an Exif file
and read this metadata.

An integer overflow flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to execute arbitrary code, or crash.
(CVE-2007-6352)

Users of libexif are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6352</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071176" severity="high">
    <xccdf:title>RHSA-2007:1176: autofs security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon, which
automatically mounts file systems when you use them, and unmounts them when
you are not using them. This can include network file systems and CD-ROMs.

There was a security issue with the default configuration of autofs version
5, whereby the entry for the "-hosts" map did not specify the "nodev" mount
option. A local user with control of a remote NFS server could create
special device files on the remote file system, that if mounted using the
default "-hosts" map, could allow the user to access important system
devices. (CVE-2007-6285)

This issue is similar to CVE-2007-5964, which fixed a missing "nosuid"
mount option in autofs. Both the "nodev" and "nosuid" options should be
enabled to prevent a possible compromise of machine integrity.

Due to the fact that autofs always mounted "-hosts" map entries "dev" by
default, autofs has now been altered to always use the "nodev" option when
mounting from the default "-hosts" map. The "dev" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the "-hosts" map which corresponds to the "/net" entry in the
default configuration.

All autofs users are advised to upgrade to these updated packages, which
resolve this issue.

Red Hat would like to thank Tim Baum for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6285</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071176"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20071177" severity="high">
    <xccdf:title>RHSA-2007:1177: autofs5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon, which
automatically mounts file systems when you use them, and unmounts them when
you are not using them. This can include network file systems and CD-ROMs.
The autofs5 packages were made available as a technology preview in Red Hat
Enterprise Linux 4.6.

There was a security issue with the default configuration of autofs version
5, whereby the entry for the "-hosts" map did not specify the "nodev" mount
option. A local user with control of a remote NFS server could create
special device files on the remote file system, that if mounted using the
default "-hosts" map, could allow the user to access important system
devices. (CVE-2007-6285)

This issue is similar to CVE-2007-5964, which fixed a missing "nosuid"
mount option in autofs. Both the "nodev" and "nosuid" options should be
enabled to prevent a possible compromise of machine integrity.

Due to the fact that autofs always mounted "-hosts" map entries "dev" by
default, autofs has now been altered to always use the "nodev" option when
mounting from the default "-hosts" map. The "dev" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the "-hosts" map which corresponds to the "/net" entry in the
default configuration.

All autofs5 users are advised to upgrade to these updated packages, which
resolve this issue.

Red Hat would like to thank Tim Baum for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2007:1177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6285</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20071177"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080002" severity="high">
    <xccdf:title>RHSA-2008:0002: tog-pegasus security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tog-pegasus packages provide OpenPegasus Web-Based Enterprise
Management (WBEM) services. WBEM is a platform and resource independent
DMTF standard that defines a common information model, and communication
protocol for monitoring and controlling resources.

During a security audit, a stack buffer overflow flaw was found in the PAM
authentication code in the OpenPegasus CIM management server. An
unauthenticated remote user could trigger this flaw and potentially execute
arbitrary code with root privileges. (CVE-2008-0003)

Note that the tog-pegasus packages are not installed by default on Red Hat
Enterprise Linux. The Red Hat Security Response Team believes that it would
be hard to remotely exploit this issue to execute arbitrary code, due to
the default SELinux targeted policy on Red Hat Enterprise Linux 4 and 5,
and the SELinux memory protection tests enabled by default on Red Hat
Enterprise Linux 5.

Users of tog-pegasus should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages the tog-pegasus service should be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0003</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080002"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080003" severity="medium">
    <xccdf:title>RHSA-2008:0003: e2fsprogs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The e2fsprogs packages contain a number of utilities for creating,
checking, modifying, and correcting any inconsistencies in second and third
extended (ext2/ext3) file systems.

Multiple integer overflow flaws were found in the way e2fsprogs processes
file system content. If a victim opens a carefully crafted file system with
a program using e2fsprogs, it may be possible to execute arbitrary code
with the permissions of the victim. It may be possible to leverage this
flaw in a virtualized environment to gain access to other virtualized
hosts. (CVE-2007-5497)

Red Hat would like to thank Rafal Wojtczuk of McAfee Avert Research for
responsibly disclosing these issues.

Users of e2fsprogs are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5497</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080006" severity="medium">
    <xccdf:title>RHSA-2008:0006: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_imap module. On sites where mod_imap was
enabled and an imagemap file was publicly available, a cross-site scripting
attack was possible. (CVE-2007-5000)

A flaw was found in the mod_autoindex module. On sites where directory
listings are used, and the "AddDefaultCharset" directive has been removed
from the configuration, a cross-site scripting attack was possible against
Web browsers which do not correctly derive the response character set
following the rules in RFC 2616. (CVE-2007-4465)

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly available, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against Web browsers which do not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of Apache httpd should upgrade to these updated packages, which
contain backported patches to resolve these issues. Users should restart
httpd after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6388</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0005</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080006"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080008" severity="medium">
    <xccdf:title>RHSA-2008:0008: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_imagemap module. On sites where mod_imagemap
was enabled and an imagemap file was publicly available, a cross-site
scripting attack was possible. (CVE-2007-5000)

A flaw was found in the mod_autoindex module. On sites where directory
listings are used, and the "AddDefaultCharset" directive has been removed
from the configuration, a cross-site scripting attack might have been
possible against Web browsers which do not correctly derive the response
character set following the rules in RFC 2616. (CVE-2007-4465)

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly available, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, a cross-site scripting attack against an
authorized user was possible. (CVE-2007-6421)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, an authorized user could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. This could lead to a denial of service if using a
threaded Multi-Processing Module. (CVE-2007-6422) 

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against Web browsers which do not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of Apache httpd should upgrade to these updated packages, which
contain backported patches to resolve these issues. Users should restart
httpd after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6388</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0005</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080030" severity="high">
    <xccdf:title>RHSA-2008:0030: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xorg-x11 packages contain X.Org, an open source implementation of the X
Window System. It provides the basic low-level functionality that
full-fledged graphical user interfaces are designed upon.

Two integer overflow flaws were found in the X.Org server's EVI and MIT-SHM
modules. A malicious authorized client could exploit these issues to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-6429)

A heap based buffer overflow flaw was found in the way the X.Org server
handled malformed font files. A malicious local user could exploit these
issues to potentially execute arbitrary code with the privileges of the
X.Org server. (CVE-2008-0006)

A memory corruption flaw was found in the X.Org server's XInput extension.
A malicious authorized client could exploit this issue to cause a denial of
service (crash), or potentially execute arbitrary code with root privileges
on the X.Org server. (CVE-2007-6427)

An input validation flaw was found in the X.Org server's XFree86-Misc
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-5760)

An information disclosure flaw was found in the X.Org server's TOG-CUP
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially view arbitrary memory content
within the X server's address space. (CVE-2007-6428)

An integer and heap overflow flaw were found in the X.Org font server, xfs.
A user with the ability to connect to the font server could have been able
to cause a denial of service (crash), or potentially execute arbitrary code
with the permissions of the font server. (CVE-2007-4568, CVE-2007-4990)

A flaw was found in the X.Org server's XC-SECURITY extension, that could
have allowed a local user to verify the existence of an arbitrary file,
even in directories that are not normally accessible to that user.
(CVE-2007-5958)

Users of xorg-x11 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0006</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080030"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080031" severity="high">
    <xccdf:title>RHSA-2008:0031: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
basic low-level functionality that full-fledged graphical user interfaces
are designed upon.

Two integer overflow flaws were found in the X.Org server's EVI and MIT-SHM
modules. A malicious authorized client could exploit these issues to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-6429)

A memory corruption flaw was found in the X.Org server's XInput extension.
A malicious authorized client could exploit this issue to cause a denial of
service (crash), or potentially execute arbitrary code with root privileges
on the X.Org server. (CVE-2007-6427)

An input validation flaw was found in the X.Org server's XFree86-Misc
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-5760)

An information disclosure flaw was found in the X.Org server's TOG-CUP
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially view arbitrary memory content
within the X server's address space. (CVE-2007-6428)

A flaw was found in the X.Org server's XC-SECURITY extension, that could
have allowed a local user to verify the existence of an arbitrary file,
even in directories that are not normally accessible to that user.
(CVE-2007-5958)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6429</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080031"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080032" severity="high">
    <xccdf:title>RHSA-2008:0032: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A denial of service flaw was found in the way libxml2 processes certain
content. If an application linked against libxml2 processes malformed XML
content, it could cause the application to stop responding. (CVE-2007-6284)

Red Hat would like to thank the Google Security Team for responsibly
disclosing this issue.

All users are advised to upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0032</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6284</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080032"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080038" severity="medium">
    <xccdf:title>RHSA-2008:0038: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced Object-Relational database management system
(DBMS). The postgresql packages include the client programs and libraries
needed to access a PostgreSQL DBMS server.

Will Drewry discovered multiple flaws in PostgreSQL's regular expression
engine. An authenticated attacker could use these flaws to cause a denial
of service by causing the PostgreSQL server to crash, enter an infinite
loop, or use extensive CPU and memory resources while processing queries
containing specially crafted regular expressions. Applications that accept
regular expressions from untrusted sources may expose this problem to
unauthorized attackers. (CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)

A privilege escalation flaw was discovered in PostgreSQL. An authenticated
attacker could create an index function that would be executed with
administrator privileges during database maintenance tasks, such as
database vacuuming. (CVE-2007-6600)

A privilege escalation flaw was discovered in PostgreSQL's Database Link
library (dblink). An authenticated attacker could use dblink to possibly
escalate privileges on systems with "trust" or "ident" authentication
configured. Please note that dblink functionality is not enabled by
default, and can only by enabled by a database administrator on systems
with the postgresql-contrib package installed. (CVE-2007-3278,
CVE-2007-6601)

All postgresql users should upgrade to these updated packages, which
include PostgreSQL 7.4.19 and 8.1.11, and resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3278</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4769</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6601</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080038"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080042" severity="medium">
    <xccdf:title>RHSA-2008:0042: tomcat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tomcat is a servlet container for Java Servlet and JavaServer Pages
technologies.

A directory traversal vulnerability existed in the Apache Tomcat webdav
servlet. In some configurations it allowed remote authenticated users to
read files accessible to the local tomcat process. (CVE-2007-5461)

The default security policy in the JULI logging component did not restrict
access permissions to files. This could be misused by untrusted web
applications to access and write arbitrary files in the context of the
tomcat process. (CVE-2007-5342)

Users of Tomcat should update to these errata packages, which contain
backported patches and are not vulnerable to these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5461</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080042"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080055" severity="high">
    <xccdf:title>RHSA-2008:0055: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated kernel packages fix the following security issues:

A flaw was found in the virtual filesystem (VFS). A local unprivileged
user could truncate directories to which they had write permission; this
could render the contents of the directory inaccessible. (CVE-2008-0001,
Important)

A flaw was found in the implementation of ptrace. A local unprivileged user
could trigger this flaw and possibly cause a denial of service (system
hang). (CVE-2007-5500, Important)

A flaw was found in the way the Red Hat Enterprise Linux 4 kernel handled
page faults when a CPU used the NUMA method for accessing memory on Itanium
architectures. A local unprivileged user could trigger this flaw and cause
a denial of service (system panic). (CVE-2007-4130, Important)

A possible NULL pointer dereference was found in the chrp_show_cpuinfo
function when using the PowerPC architecture. This may have allowed a local
unprivileged user to cause a denial of service (crash).
(CVE-2007-6694, Moderate)

A flaw was found in the way core dump files were created. If a local user
can get a root-owned process to dump a core file into a directory, which
the user has write access to, they could gain read access to that core
file. This could potentially grant unauthorized access to sensitive
information. (CVE-2007-6206, Moderate)

Two buffer overflow flaws were found in the Linux kernel ISDN subsystem. A
local unprivileged  user could use these flaws to cause a denial of
service. (CVE-2007-6063, CVE-2007-6151, Moderate)

As well, these updated packages fix the following bug:

* when moving volumes that contain multiple segments, and a mirror segment
is not the first in the mapping table, running the "pvmove /dev/[device]
/dev/[device]" command caused a kernel panic. A "kernel: Unable to handle
kernel paging request at virtual address [address]" error was logged by
syslog.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0001</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080055"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080058" severity="medium">
    <xccdf:title>RHSA-2008:0058: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Several flaws were found in Wireshark. Wireshark could crash or possibly
execute arbitrary code as the user running Wireshark if it read a malformed
packet off the network. (CVE-2007-6112, CVE-2007-6114, CVE-2007-6115,
CVE-2007-6117)

Several denial of service bugs were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off the network.
(CVE-2007-6111, CVE-2007-6113, CVE-2007-6116, CVE-2007-6118, CVE-2007-6119,
CVE-2007-6120, CVE-2007-6121, CVE-2007-6438, CVE-2007-6439, CVE-2007-6441,
CVE-2007-6450, CVE-2007-6451)

As well, Wireshark switched from using net-snmp to libsmi, which is
included in this errata.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 0.99.7, and resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6111</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6117</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6118</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6119</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6120</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6451</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080058"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080061" severity="medium">
    <xccdf:title>RHSA-2008:0061: setroubleshoot security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The setroubleshoot packages provide tools to help diagnose SELinux
problems. When AVC messages occur, an alert is generated that gives
information about the problem, and how to create a resolution.

A flaw was found in the way sealert wrote diagnostic messages to a
temporary file. A local unprivileged user could perform a symbolic link
attack, and cause arbitrary files, writable by other users, to be
overwritten when a victim runs sealert. (CVE-2007-5495)

A flaw was found in the way sealert displayed records from the
setroubleshoot database as unescaped HTML. An local unprivileged attacker
could cause AVC denial events with carefully crafted process or file names,
injecting arbitrary HTML tags into the logs, which could be used as a
scripting attack, or to confuse the user running sealert. (CVE-2007-5496)

Additionally, the following bugs have been fixed in these update packages:

* in certain situations, the sealert process used excessive CPU. These
alerts are now capped at a maximum of 30, D-Bus is used instead of polling,
threads causing excessive wake-up have been removed, and more robust
exception-handling has been added.

* different combinations of the sealert '-a', '-l', '-H', and '-v' options
did not work as documented.

* the SETroubleShoot browser did not allow multiple entries to be deleted. 

* the SETroubleShoot browser did not display statements that displayed
whether SELinux was using Enforcing or Permissive mode, particularly when
warning about SELinux preventions.

* in certain cases, the SETroubleShoot browser gave incorrect instructions
regarding paths, and would not display the full paths to files.

* adding an email recipient to the recipients option from the
/etc/setroubleshoot/setroubleshoot.cfg file and then generating an SELinux
denial caused a traceback error. The recipients option has been removed;
email addresses are now managed through the SETroubleShoot browser by
navigating to File -&gt; Edit Email Alert List, or by editing the
/var/lib/setroubleshoot/email_alert_recipients file.

* the setroubleshoot browser incorrectly displayed a period between the
httpd_sys_content_t context and the directory path.

* on the PowerPC architecture, The get_credentials() function in
access_control.py would generate an exception when it called the
socket.getsockopt() function.

* The code which handles path information has been completely rewritten so
that assumptions on path information which were misleading are no longer
made. If the path information is not present, it will be presented as
"&lt;Unknown&gt;".

* setroubleshoot had problems with non-English locales under certain
circumstances, possibly causing a python traceback, an sealert window
pop-up containing an error, a "RuntimeError: maximum recursion depth
exceeded" error after a traceback, or a "UnicodeEncodeError" after a traceback.

* sealert ran even when SELinux was disabled, causing "attempt to open
server connection failed" errors. Sealert now checks whether SELinux is
enabled or disabled.

* the database setroubleshoot maintains was world-readable. The
setroubleshoot database is now mode 600, and is owned by the root user and
group.

* setroubleshoot did not validate requests to set AVC filtering options for
users. In these updated packages, checks ensure that requests originate
from the filter owner.

* the previous setroubleshoot packages required a number of GNOME packages
and libraries. setroubleshoot has therefore been split into 2 packages:
setroubleshoot and setroubleshoot-server.

* a bug in decoding the audit field caused an "Input is not proper UTF-8,
indicate encoding!" error message. The decoding code has been rewritten.

* a file name mismatch in the setroubleshoot init script would cause a
failure to shut down.

Users of setroubleshoot are advised to upgrade to these updated packages,
which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5495</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5496</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080061"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080064" severity="high">
    <xccdf:title>RHSA-2008:0064: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont package contains the X.Org X11 libXfont runtime library.

A heap based buffer overflow flaw was found in the way the X.Org server
handled malformed font files. A malicious local user could exploit this
issue to potentially execute arbitrary code with the privileges of the
X.Org server. (CVE-2008-0006)

Users of X.Org libXfont should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0006</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080064"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080089" severity="high">
    <xccdf:title>RHSA-2008:0089: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These new kernel packages fix the following security issues:

A flaw was found in the virtual filesystem (VFS). An unprivileged local
user could truncate directories to which they had write permission; this
could render the contents of the directory inaccessible. (CVE-2008-0001,
Important)

A flaw was found in the Xen PAL emulation on Intel 64 platforms. A guest
Hardware-assisted virtual machine (HVM) could read the arbitrary physical
memory of the host system, which could make information available to
unauthorized users. (CVE-2007-6416, Important)

A flaw was found in the way core dump files were created. If a local user
can get a root-owned process to dump a core file into a directory, which
the user has write access to, they could gain read access to that core
file, potentially containing sensitive information. (CVE-2007-6206, Moderate)

A buffer overflow flaw was found in the CIFS virtual file system. A
remote,authenticated user could issue a request that could lead to a denial
of service. (CVE-2007-5904, Moderate)

A flaw was found in the "sysfs_readdir" function. A local user could create
a race condition which would cause a denial of service (kernel oops).
(CVE-2007-3104, Moderate)

As well, these updated packages fix the following bugs:

* running the "strace -f" command caused strace to hang, without displaying
information about child processes.

* unmounting an unresponsive, interruptable NFS mount, for example, one
mounted with the "intr" option, may have caused a system crash.

* a bug in the s2io.ko driver prevented VLAN devices from being added.
Attempting to add a device to a VLAN, for example, running the "vconfig
add [device-name] [vlan-id]" command caused vconfig to fail.

* tux used an incorrect open flag bit. This caused problems when building
packages in a chroot environment, such as mock, which is used by the koji
build system.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3104</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5904</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0001</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080089"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080090" severity="high">
    <xccdf:title>RHSA-2008:0090: icu security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

Will Drewry reported multiple flaws in the way libicu processed certain
malformed regular expressions. If an application linked against ICU, such
as OpenOffice.org, processed a carefully crafted regular expression, it may
be possible to execute arbitrary code as the user running the application.
(CVE-2007-4770, CVE-2007-4771)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4770</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4771</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080103" severity="high">
    <xccdf:title>RHSA-2008:0103: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed web
content. A webpage containing malicious content could cause Firefox to
crash, or potentially execute arbitrary code as the user running Firefox.
(CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419)

Several flaws were found in the way Firefox displayed malformed web
content. A webpage containing specially-crafted content could trick a user
into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way Firefox stored password data. If a user saves
login information for a malicious website, it could be possible to corrupt
the password database, preventing the user from properly accessing saved
password data. (CVE-2008-0417)

A flaw was found in the way Firefox handles certain chrome URLs. If a user
has certain extensions installed, it could allow a malicious website to
steal sensitive session data. Note: this flaw does not affect a default
installation of Firefox. (CVE-2008-0418)

A flaw was found in the way Firefox saves certain text files. If a
website offers a file of type "plain/text", rather than "text/plain",
Firefox will not show future "text/plain" content to the user in the
browser, forcing them to save those files locally to view the content.
(CVE-2008-0592) 

Users of firefox are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0103</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0593</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080103"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080104" severity="high">
    <xccdf:title>RHSA-2008:0104: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
web content. A webpage containing malicious content could cause SeaMonkey
to crash, or potentially execute arbitrary code as the user running
SeaMonkey. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419)

Several flaws were found in the way SeaMonkey displayed malformed web
content. A webpage containing specially-crafted content could trick a user
into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way SeaMonkey stored password data. If a user
saves login information for a malicious website, it could be possible
to corrupt the password database, preventing the user from properly
accessing saved password data. (CVE-2008-0417)

A flaw was found in the way SeaMonkey handles certain chrome URLs. If a
user has certain extensions installed, it could allow a malicious website
to steal sensitive session data. Note: this flaw does not affect a default
installation of SeaMonkey. (CVE-2008-0418)

A flaw was found in the way SeaMonkey saves certain text files. If a
website offers a file of type "plain/text", rather than "text/plain",
SeaMonkey will not show future "text/plain" content to the user in the
browser, forcing them to save those files locally to view the content.
(CVE-2008-0592)

Users of SeaMonkey are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0104</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0593</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080104"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080105" severity="high">
    <xccdf:title>RHSA-2008:0105: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A heap-based buffer overflow flaw was found in the way Thunderbird
processed messages with external-body Multipurpose Internet Message
Extensions (MIME) types. A HTML mail message containing malicious content
could cause Thunderbird to execute arbitrary code as the user running
Thunderbird. (CVE-2008-0304)

Several flaws were found in the way Thunderbird processed certain malformed
HTML mail content. A HTML mail message containing malicious content could
cause Thunderbird to crash, or potentially execute arbitrary code as the
user running Thunderbird. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415,
CVE-2008-0419)

Several flaws were found in the way Thunderbird displayed malformed HTML
mail content. A HTML mail message containing specially-crafted content
could trick a user into surrendering sensitive information. (CVE-2008-0420,
CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way Thunderbird handles certain chrome URLs. If a
user has certain extensions installed, it could allow a malicious HTML mail
message to steal sensitive session data. Note: this flaw does not affect a
default installation of Thunderbird. (CVE-2008-0418)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the way Thunderbird saves certain text files. If a
remote site offers a file of type "plain/text", rather than "text/plain",
Thunderbird will not show future "text/plain" content to the user, forcing
them to save those files locally to view the content. (CVE-2008-0592)

Users of thunderbird are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0593</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080105"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080110" severity="medium">
    <xccdf:title>RHSA-2008:0110: openldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.

These updated openldap packages fix a flaw in the way the OpenLDAP slapd
daemon handled modify and modrdn requests with NOOP control on objects
stored in a Berkeley DB (BDB) storage backend.  An authenticated attacker
with permission to perform modify or modrdn operations on such LDAP objects
could cause slapd to crash. (CVE-2007-6698, CVE-2008-0658)

Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0110</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0658</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080110"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080129" severity="high">
    <xccdf:title>RHSA-2008:0129: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

A flaw was found in vmsplice. An unprivileged local user could use this
flaw to gain root privileges. (CVE-2008-0600)

Red Hat is aware that a public exploit for this issue is available. This
issue did not affect the Linux kernels distributed with Red Hat Enterprise
Linux 2.1, 3, or 4.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0129</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0600</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080129"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080131" severity="medium">
    <xccdf:title>RHSA-2008:0131: netpbm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps) and others. The package includes no interactive tools and is
primarily used by other programs (eg CGI scripts that manage web-site
images).

An input validation flaw was discovered in the GIF-to-PNM converter
(giftopnm) shipped with the netpbm package. An attacker could create a
carefully crafted GIF file which could cause giftopnm to crash or possibly
execute arbitrary code as the user running giftopnm. (CVE-2008-0554)

All users are advised to upgrade to these updated packages which contain a
backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0554</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080131"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080135" severity="medium">
    <xccdf:title>RHSA-2008:0135: tk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tk is a graphical toolkit for the Tcl scripting language.

An input validation flaw was discovered in Tk's GIF image handling. A
code-size value read from a GIF image was not properly validated before
being used, leading to a buffer overflow. A specially crafted GIF file
could use this to cause a crash or, potentially, execute code with the
privileges of the application using the Tk graphical toolkit.
(CVE-2008-0553)

A buffer overflow flaw was discovered in Tk's animated GIF image handling.
An animated GIF containing an initial image smaller than subsequent images
could cause a crash or, potentially, execute code with the privileges of
the application using the Tk library. (CVE-2007-5378)

All users are advised to upgrade to these updated packages which contain a
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0553</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080136" severity="medium">
    <xccdf:title>RHSA-2008:0136: tk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tk is a graphical toolkit for the Tcl scripting language.

An input validation flaw was discovered in Tk's GIF image handling. A
code-size value read from a GIF image was not properly validated before
being used, leading to a buffer overflow. A specially crafted GIF file
could use this to cause a crash or, potentially, execute code with the
privileges of the application using the Tk graphical toolkit.
(CVE-2008-0553)

A buffer overflow flaw was discovered in Tk's animated GIF image handling.
An animated GIF containing an initial image smaller than subsequent images
could cause a crash or, potentially, execute code with the privileges of
the application using the Tk library. (CVE-2007-5137)

All users are advised to upgrade to these updated packages which contain a
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0553</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080136"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080145" severity="medium">
    <xccdf:title>RHSA-2008:0145: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Several heap-based buffer overflow flaws were found in ImageMagick. If a
victim opened a specially crafted DCM or XWD file, an attacker could
potentially execute arbitrary code on the victim's machine. (CVE-2007-1797)

Several denial of service flaws were found in ImageMagick's parsing of XCF
and DCM files. Attempting to process a specially-crafted input file in
these formats could cause ImageMagick to enter an infinite loop.
(CVE-2007-4985)

Several integer overflow flaws were found in ImageMagick. If a victim
opened a specially-crafted DCM, DIB, XBM, XCF or XWD file, an attacker
could potentially execute arbitrary code with the privileges of the user
running ImageMagick. (CVE-2007-4986)

An integer overflow flaw was found in ImageMagick's DIB parsing code. If a
victim opened a specially-crafted DIB file, an attacker could potentially
execute arbitrary code with the privileges of the user running ImageMagick.
(CVE-2007-4988)

A heap-based buffer overflow flaw was found in the way ImageMagick parsed
XCF files. If a specially-crafted XCF image was opened, ImageMagick could
be made to overwrite heap memory beyond the bounds of its allocated memory.
This could, potentially, allow an attacker to execute arbitrary code on the
machine running ImageMagick. (CVE-2008-1096)

A heap-based buffer overflow flaw was found in ImageMagick's processing of
certain malformed PCX images. If a victim opened a specially-crafted PCX
file, an attacker could possibly execute arbitrary code on the victim's
machine. (CVE-2008-1097)

All users of ImageMagick should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4985</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1097</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080145"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080146" severity="medium">
    <xccdf:title>RHSA-2008:0146: gd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gd package contains a graphics library used for the dynamic creation of
images such as PNG and JPEG.

Multiple issues were discovered in the gd GIF image-handling code. A
carefully-crafted GIF file could cause a crash or possibly execute code
with the privileges of the application using the gd library.
(CVE-2006-4484, CVE-2007-3475, CVE-2007-3476)

An integer overflow was discovered in the gdImageCreateTrueColor()
function, leading to incorrect memory allocations. A carefully crafted
image could cause a crash or possibly execute code with the privileges of
the application using the gd library. (CVE-2007-3472)

A buffer over-read flaw was discovered. This could cause a crash in an
application using the gd library to render certain strings using a
JIS-encoded font. (CVE-2007-0455)

A flaw was discovered in the gd PNG image handling code. A truncated PNG
image could cause an infinite loop in an application using the gd library.
(CVE-2007-2756)

A flaw was discovered in the gd X BitMap (XBM) image-handling code. A
malformed or truncated XBM image could cause a crash in an application
using the gd library. (CVE-2007-3473)

Users of gd should upgrade to these updated packages, which contain
backported patches which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2756</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3476</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080146"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080154" severity="high">
    <xccdf:title>RHSA-2008:0154: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw in the hypervisor for hosts running on Itanium architectures
allowed an Intel VTi domain to read arbitrary physical memory from other
Intel VTi domains, which could make information available to unauthorized
users. (CVE-2007-6207, Important)

* two buffer overflow flaws were found in ISDN subsystem. A local
unprivileged user could use these flaws to cause a denial of service.
(CVE-2007-5938: Important, CVE-2007-6063: Moderate)

* a possible NULL pointer dereference was found in the subsystem used for
showing CPU information, as used by CHRP systems on PowerPC architectures.
This may have allowed a local unprivileged user to cause a denial of
service (crash). (CVE-2007-6694, Moderate)

* a flaw was found in the handling of zombie processes. A local user could
create processes that would not be properly reaped, possibly causing a
denial of service. (CVE-2006-6921, Moderate)

As well, these updated packages fix the following bugs:

* a bug was found in the Linux kernel audit subsystem. When the audit
daemon was setup to log the execve system call with a large number of
arguments, the kernel could run out of memory, causing a kernel panic.

* on IBM System z architectures, using the IBM Hardware Management Console
to toggle IBM FICON channel path ids (CHPID) caused a file ID miscompare,
possibly causing data corruption.

* when running the IA-32 Execution Layer (IA-32EL) or a Java VM on Itanium
architectures, a bug in the address translation in the hypervisor caused
the wrong address to be registered, causing Dom0 to hang.

* on Itanium architectures, frequent Corrected Platform Error errors may
have caused the hypervisor to hang.

* when enabling a CPU without hot plug support, routines for checking the
presence of the CPU were missing. The CPU tried to access its own
resources, causing a kernel panic.

* after updating to kernel-2.6.18-53.el5, a bug in the CCISS driver caused
the HP Array Configuration Utility CLI to become unstable, possibly causing
a system hang, or a kernel panic.

* a bug in NFS directory caching could have caused different hosts to have
different views of NFS directories.

* on Itanium architectures, the Corrected Machine Check Interrupt masked
hot-added CPUs as disabled.

* when running Oracle database software on the Intel 64 and AMD64
architectures, if an SGA larger than 4GB was created, and had hugepages
allocated to it, the hugepages were not freed after database shutdown.

* in a clustered environment, when two or more NFS clients had the same
logical volume mounted, and one of them modified a file on the volume, NULL
characters may have been inserted, possibly causing data corruption.

These updated packages resolve several severe issues in the lpfc driver:

* a system hang after LUN discovery.

* a general fault protection, a NULL pointer dereference, or slab
corruption could occur while running a debug on the kernel.

* the inability to handle kernel paging requests in "lpfc_get_scsi_buf".

* erroneous structure references caused certain FC discovery routines to
reference and change "lpfc_nodelist" structures, even after they were
freed.

* the lpfc driver failed to interpret certain fields correctly, causing
tape backup software to fail. Tape drives reported "Illegal Request".

* the lpfc driver did not clear structures correctly, resulting in SCSI
I/Os being rejected by targets, and causing errors.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6921</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5938</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6694</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080155" severity="high">
    <xccdf:title>RHSA-2008:0155: ghostscript security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a program for displaying PostScript files, or printing them
to non-PostScript printers.

Chris Evans from the Google Security Team reported a stack-based buffer
overflow flaw in Ghostscript's zseticcspace() function. An attacker could
create a malicious PostScript file that would cause Ghostscript to execute
arbitrary code when opened. (CVE-2008-0411)

These updated packages also fix a bug, which prevented the pxlmono printer
driver from producing valid output on Red Hat Enterprise Linux 4.

All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080155"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080157" severity="high">
    <xccdf:title>RHSA-2008:0157: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems. The Internet Printing Protocol (IPP) is a
standard network protocol for remote printing, as well as managing print
jobs.

A flaw was found in the way CUPS handles the addition and removal of remote
shared printers via IPP. A remote attacker could send malicious UDP IPP
packets causing the CUPS daemon to crash. (CVE-2008-0882)

Note: the default configuration of CUPS on Red Hat Enterprise Linux 5 will
only accept requests of this type from the local subnet. This issue did not
affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3 or
4.

All cups users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0882</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080157"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080159" severity="medium">
    <xccdf:title>RHSA-2008:0159: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used
both for the system-wide message bus service, and as a
per-user-login-session messaging facility.

Havoc Pennington discovered a flaw in the way the dbus-daemon applies its
security policy. A user with the ability to connect to the dbus-daemon may
be able to execute certain method calls they should normally not have
permission to access.  (CVE-2008-0595)

Red Hat does not ship any applications in Red Hat Enterprise Linux 5 that
would allow a user to leverage this flaw to elevate their privileges.

This flaw does not affect the version of D-Bus shipped in Red Hat
Enterprise Linux 4.

All users are advised to upgrade to these updated dbus packages, which
contain a backported patch and are not vulnerable to this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0595</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080159"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080161" severity="high">
    <xccdf:title>RHSA-2008:0161: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A flaw was found in the way CUPS handled the addition and removal of remote
shared printers via IPP.  A remote attacker could send malicious UDP IPP
packets causing the CUPS daemon to attempt to dereference already freed
memory and crash. (CVE-2008-0597)

A memory management flaw was found in the way CUPS handled the addition and
removal of remote shared printers via IPP.  When shared printer was
removed, allocated memory was not properly freed, leading to a memory leak
possibly causing CUPS daemon crash after exhausting available memory.
(CVE-2008-0596)

These issues were found during the investigation of CVE-2008-0882, which
did not affect Red Hat Enterprise Linux 4.

Note that the default configuration of CUPS on Red Hat Enterprise Linux
4 allow requests of this type only from the local subnet.

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0161</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0597</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080161"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080164" severity="high">
    <xccdf:title>RHSA-2008:0164: krb5 security and bugfix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the way the MIT Kerberos Authentication Service and Key
Distribution Center server (krb5kdc) handled Kerberos v4 protocol packets.
An unauthenticated remote attacker could use this flaw to crash the
krb5kdc daemon, disclose portions of its memory, or possibly execute
arbitrary code using malformed or truncated Kerberos v4 protocol requests.
(CVE-2008-0062, CVE-2008-0063)

This issue only affected krb5kdc with Kerberos v4 protocol compatibility
enabled, which is the default setting on Red Hat Enterprise Linux 4.
Kerberos v4 protocol support can be disabled by adding "v4_mode=none"
(without the quotes) to the "[kdcdefaults]" section of
/var/kerberos/krb5kdc/kdc.conf.

Jeff Altman of Secure Endpoints discovered a flaw in the RPC library as
used by MIT Kerberos kadmind server. An unauthenticated remote attacker
could use this flaw to crash kadmind or possibly execute arbitrary code.
This issue only affected systems with certain resource limits configured
and did not affect systems using default resource limits used by Red Hat
Enterprise Linux 5. (CVE-2008-0947)

Red Hat would like to thank MIT for reporting these issues.

Multiple memory management flaws were discovered in the GSSAPI library used
by MIT Kerberos. These flaws could possibly result in use of already freed
memory or an attempt to free already freed memory blocks (double-free
flaw), possibly causing a crash or arbitrary code execution.
(CVE-2007-5901, CVE-2007-5971)

In addition to the security issues resolved above, the following bugs were
also fixed:

* delegated krb5 credentials were not properly stored when SPNEGO was the
underlying mechanism during GSSAPI authentication. Consequently,
applications attempting to copy delegated Kerberos 5 credentials into a
credential cache received an "Invalid credential was supplied" message
rather than a copy of the delegated credentials. With this update, SPNEGO
credentials can be properly searched, allowing applications to copy
delegated credentials as expected.

* applications can initiate context acceptance (via gss_accept_sec_context)
without passing a ret_flags value that would indicate that credentials were
delegated. A delegated credential handle should have been returned in such
instances. This updated package adds a temp_ret_flag that stores the
credential status in the event no other ret_flags value is passed by an
application calling gss_accept_sec_context.

* kpasswd did not fallback to TCP on receipt of certain errors, or when a
packet was too big for UDP. This update corrects this.

* when the libkrb5 password-routine generated a set-password or
change-password request, incorrect sequence numbers were generated for all
requests subsequent to the first request. This caused password change
requests to fail if the primary server was unavailable. This updated
package corrects this by saving the sequence number value after the AP-REQ
data is built and restoring this value before the request is generated.

* when a user's password expired, kinit would not prompt that user to
change the password, instead simply informing the user their password had
expired. This update corrects this behavior: kinit now prompts for a new
password to be set when a password has expired.

All krb5 users are advised to upgrade to these updated packages, which
contain backported fixes to address these vulnerabilities and fix these
bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5901</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5971</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0947</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080167" severity="medium">
    <xccdf:title>RHSA-2008:0167: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

A buffer overflow flaw was found in the CIFS virtual file system. A
remote authenticated user could issue a request that could lead to
a denial of service. (CVE-2007-5904, Moderate)

As well, these updated packages fix the following bugs:

* a bug was found in the Linux kernel audit subsystem. When the audit
daemon was setup to log the execve system call with a large number
of arguments, the kernel could run out out memory while attempting to
create audit log messages. This could cause a kernel panic. In these
updated packages, large audit messages are split into acceptable sizes,
which resolves this issue.

* on certain Intel chipsets, it was not possible to load the acpiphp
module using the "modprobe acpiphp" command. Because the acpiphp module
did not recurse across PCI bridges, hardware detection for PCI hot plug
slots failed. In these updated packages, hardware detection works
correctly.

* on IBM System z architectures that run the IBM z/VM hypervisor, the IBM
eServer zSeries HiperSockets network interface (layer 3) allowed ARP
packets to be sent and received, even when the "NOARP" flag was set. These
ARP packets caused problems for virtual machines.

* it was possible for the iounmap function to sleep while holding a lock.
This may have caused a deadlock for drivers and other code that uses the
iounmap function. In these updated packages, the lock is dropped before
the sleep code is called, which resolves this issue.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5904</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080167"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080175" severity="high">
    <xccdf:title>RHSA-2008:0175: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Multiple heap overflows and an integer underflow were found in the Quattro
Pro(R) import filter. An attacker could create a carefully crafted Quattro
Pro file that could cause OpenOffice.org to crash or possibly execute
arbitrary code if the file was opened by a victim. (CVE-2007-5745,
CVE-2007-5747)

A heap overflow flaw was found in the EMF parser. An attacker could create
a carefully crafted EMF file that could cause OpenOffice.org to crash or
possibly execute arbitrary code if the malicious EMF image was added to a
document or if a document containing the malicious EMF file was opened by a
victim. (CVE-2007-5746)

A heap overflow flaw was found in the OLE Structured Storage file parser.
(OLE Structured Storage is a format used by Microsoft Office documents.) An
attacker could create a carefully crafted OLE file that could cause
OpenOffice.org to crash or possibly execute arbitrary code if the file was
opened by a victim. (CVE-2008-0320)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5745</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0320</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080175"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080176" severity="high">
    <xccdf:title>RHSA-2008:0176: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the EMF parser. An attacker could create
a carefully crafted EMF file that could cause OpenOffice.org to crash or
possibly execute arbitrary code if the malicious EMF image was added to a
document or if a document containing the malicious EMF file was opened by a
victim. (CVE-2007-5746)

A heap overflow flaw was found in the OLE Structured Storage file parser.
(OLE Structured Storage is a format used by Microsoft Office documents.) An
attacker could create a carefully crafted OLE file that could cause
OpenOffice.org to crash or possibly execute arbitrary code if the file was
opened by a victim. (CVE-2008-0320)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0320</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080176"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080177" severity="high">
    <xccdf:title>RHSA-2008:0177: evolution security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string flaw was found in the way Evolution displayed encrypted
mail content. If a user opened a carefully crafted mail message, arbitrary
code could be executed as the user running Evolution. (CVE-2008-0072)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Red Hat would like to thank Ulf Härnhammar of Secunia Research for finding
and reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0072</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080177"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080180" severity="high">
    <xccdf:title>RHSA-2008:0180: krb5 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the way the MIT Kerberos Authentication Service and Key
Distribution Center server (krb5kdc) handled Kerberos v4 protocol packets.
An unauthenticated remote attacker could use this flaw to crash the
krb5kdc daemon, disclose portions of its memory, or possibly execute
arbitrary code using malformed or truncated Kerberos v4 protocol
requests. (CVE-2008-0062, CVE-2008-0063)

This issue only affected krb5kdc with Kerberos v4 protocol compatibility
enabled, which is the default setting on Red Hat Enterprise Linux 4.
Kerberos v4 protocol support can be disabled by adding "v4_mode=none"
(without the quotes) to the "[kdcdefaults]" section of
/var/kerberos/krb5kdc/kdc.conf.

Red Hat would like to thank MIT for reporting these issues.

A double-free flaw was discovered in the GSSAPI library used by MIT
Kerberos. This flaw could possibly cause a crash of the application using
the GSSAPI library. (CVE-2007-5971)

All krb5 users are advised to update to these erratum packages which
contain backported fixes to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5971</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0063</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080192" severity="medium">
    <xccdf:title>RHSA-2008:0192: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A heap buffer overflow flaw was found in a CUPS administration interface
CGI script. A local attacker able to connect to the IPP port (TCP port 631)
could send a malicious request causing the script to crash or, potentially,
execute arbitrary code as the "lp" user. Please note: the default CUPS
configuration in Red Hat Enterprise Linux 5 does not allow remote
connections to the IPP TCP port. (CVE-2008-0047)

Red Hat would like to thank "regenrecht" for reporting this issue.

This issue did not affect the versions of CUPS as shipped with Red Hat
Enterprise Linux 3 or 4.

Two overflows were discovered in the HP-GL/2-to-PostScript filter. An
attacker could create a malicious HP-GL/2 file that could possibly execute
arbitrary code as the "lp" user if the file is printed. (CVE-2008-0053)

A buffer overflow flaw was discovered in the GIF decoding routines used by
CUPS image converting filters "imagetops" and "imagetoraster". An attacker
could create a malicious GIF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1373)

All cups users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0047</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1373</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080192"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080194" severity="high">
    <xccdf:title>RHSA-2008:0194: xen security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain tools for managing the virtual machine monitor in
Red Hat Virtualization.

These updated packages fix the following security issues:

Daniel P. Berrange discovered that the hypervisor's para-virtualized
framebuffer (PVFB) backend failed to validate the format of messages
serving to update the contents of the framebuffer. This could allow a
malicious user to cause a denial of service, or compromise the privileged
domain (Dom0). (CVE-2008-1944)

Markus Armbruster discovered that the hypervisor's para-virtualized
framebuffer (PVFB) backend failed to validate the frontend's framebuffer
description. This could allow a malicious user to cause a denial of
service, or to use a specially crafted frontend to compromise the
privileged domain (Dom0). (CVE-2008-1943)

Chris Wright discovered a security vulnerability in the QEMU block format
auto-detection, when running fully-virtualized guests. Such
fully-virtualized guests, with a raw formatted disk image, were able
to write a header to that disk image describing another format. This could
allow such guests to read arbitrary files in their hypervisor's host.
(CVE-2008-2004)

Ian Jackson discovered a security vulnerability in the QEMU block device
drivers backend. A guest operating system could issue a block device
request and read or write arbitrary memory locations, which could lead to
privilege escalation. (CVE-2008-0928)

Tavis Ormandy found that QEMU did not perform adequate sanity-checking of
data received via the "net socket listen" option. A malicious local
administrator of a guest domain could trigger this flaw to potentially
execute arbitrary code outside of the domain. (CVE-2007-5730)

Steve Kemp discovered that the xenbaked daemon and the XenMon utility
communicated via an insecure temporary file. A malicious local
administrator of a guest domain could perform a symbolic link attack,
causing arbitrary files to be truncated. (CVE-2007-3919)

As well, in the previous xen packages, it was possible for Dom0 to fail to
flush data from a fully-virtualized guest to disk, even if the guest
explicitly requested the flush. This could cause data integrity problems on
the guest. In these updated packages, Dom0 always respects the request to
flush to disk.

Users of xen are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0928</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2004</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080194"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080197" severity="medium">
    <xccdf:title>RHSA-2008:0197: gnome-screensaver security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gnome-screensaver is the GNOME project's official screen saver program.

A flaw was found in the way gnome-screensaver verified user passwords. When
a system used a remote directory service for login credentials, a local
attacker able to cause a network outage could cause gnome-screensaver to
crash, unlocking the screen. (CVE-2008-0887)

Users of gnome-screensaver should upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0887</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080206" severity="medium">
    <xccdf:title>RHSA-2008:0206: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Two overflows were discovered in the HP-GL/2-to-PostScript filter. An
attacker could create a malicious HP-GL/2 file that could possibly execute
arbitrary code as the "lp" user if the file is printed. (CVE-2008-0053)

A buffer overflow flaw was discovered in the GIF decoding routines used by
CUPS image converting filters "imagetops" and "imagetoraster". An attacker
could create a malicious GIF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1373)

It was discovered that the patch used to address CVE-2004-0888 in CUPS
packages in Red Hat Enterprise Linux 3 and 4 did not completely resolve the
integer overflow in the "pdftops" filter on 64-bit platforms.  An attacker
could create a malicious PDF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1374)

All cups users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080207" severity="high">
    <xccdf:title>RHSA-2008:0207: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of some malformed web content. A
web page containing such malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237)

Several flaws were found in the display of malformed web content. A web
page containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

All Firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1233</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1236</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1241</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080207"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080208" severity="high">
    <xccdf:title>RHSA-2008:0208: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the processing of some malformed web content. A
web page containing such malicious content could cause SeaMonkey to crash
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237)

Several flaws were found in the display of malformed web content. A web
page containing specially-crafted content could, potentially, trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1233</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1236</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1241</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080208"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080209" severity="medium">
    <xccdf:title>RHSA-2008:0209: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of some malformed HTML mail
content. An HTML mail message containing such malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code as the user
running Thunderbird. (CVE-2008-1233, CVE-2008-1235, CVE-2008-1236,
CVE-2008-1237)

Several flaws were found in the display of malformed web content. An HTML
mail message containing specially-crafted content could, potentially, trick
a user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1233</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1236</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1241</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080209"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080214" severity="medium">
    <xccdf:title>RHSA-2008:0214: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A flaw was found in the way squid manipulated HTTP headers for cached
objects stored in system memory. An attacker could use this flaw to cause a
squid child process to exit. This interrupted existing connections and made
proxy services unavailable. Note: the parent squid process started a new
child process, so this attack only resulted in a temporary denial of
service. (CVE-2008-1612)

Users of squid are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1612</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080214"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080218" severity="medium">
    <xccdf:title>RHSA-2008:0218: gnome-screensaver security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gnome-screensaver is the GNOME project's official screen saver program.

A flaw was found in the way gnome-screensaver verified user passwords. When
a system used a remote directory service for login credentials, a local
attacker able to cause a network outage could cause gnome-screensaver to
crash, unlocking the screen. (CVE-2008-0887)

Users of gnome-screensaver should upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0887</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080218"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080222" severity="high">
    <xccdf:title>RHSA-2008:0222: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

A flaw was found in the processing of malformed JavaScript content. A web
page containing such malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-1380)

All Firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1380</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080222"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080223" severity="high">
    <xccdf:title>RHSA-2008:0223: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A flaw was found in the processing of malformed JavaScript content. A web
page containing such malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-1380)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1380</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080223"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080224" severity="medium">
    <xccdf:title>RHSA-2008:0224: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the processing of malformed JavaScript content. An HTML
mail message containing such malicious content could cause Thunderbird to
crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-1380)

Note: JavaScript support is disabled by default in Thunderbird; the above
issue is not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1380</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080224"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080233" severity="high">
    <xccdf:title>RHSA-2008:0233: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* the absence of a protection mechanism when attempting to access a
critical section of code has been found in the Linux kernel open file
descriptors control mechanism, fcntl. This could allow a local unprivileged
user to simultaneously execute code, which would otherwise be protected
against parallel execution. As well, a race condition when handling locks
in the Linux kernel fcntl functionality, may have allowed a process
belonging to a local unprivileged user to gain re-ordered access to the
descriptor table. (CVE-2008-1669, Important)

* a possible hypervisor panic was found in the Linux kernel. A privileged
user of a fully virtualized guest could initiate a stress-test File
Transfer Protocol (FTP) transfer between the guest and the hypervisor,
possibly leading to hypervisor panic. (CVE-2008-1619, Important)

* the absence of a protection mechanism when attempting to access a
critical section of code, as well as a race condition, have been found
in the Linux kernel file system event notifier, dnotify. This could allow a
local unprivileged user to get inconsistent data, or to send arbitrary
signals to arbitrary system processes. (CVE-2008-1375, Important)

Red Hat would like to thank Nick Piggin for responsibly disclosing the
following issue:

* when accessing kernel memory locations, certain Linux kernel drivers
registering a fault handler did not perform required range checks. A local
unprivileged user could use this flaw to gain read or write access to
arbitrary kernel memory, or possibly cause a kernel crash.
(CVE-2008-0007, Important)

* the absence of sanity-checks was found in the hypervisor block backend
driver, when running 32-bit paravirtualized guests on a 64-bit host. The
number of blocks to be processed per one request from guest to host, or
vice-versa, was not checked for its maximum value, which could have allowed
a local privileged user of the guest operating system to cause a denial of
service. (CVE-2007-5498, Important)

* it was discovered that the Linux kernel handled string operations in the
opposite way to the GNU Compiler Collection (GCC). This could allow a local
unprivileged user to cause memory corruption. (CVE-2008-1367, Low)

As well, these updated packages fix the following bugs:

* on IBM System z architectures, when running QIOASSIST enabled QDIO
devices in an IBM z/VM environment, the output queue stalled under heavy
load. This caused network performance to degrade, possibly causing network
hangs and outages.

* multiple buffer overflows were discovered in the neofb video driver. It
was not possible for an unprivileged user to exploit these issues, and as
such, they have not been handled as security issues.

* when running Microsoft Windows in a HVM, a bug in vmalloc/vfree caused
network performance to degrade.

* on certain architectures, a bug in the libATA sata_nv driver may have
caused infinite reboots, and an "ata1: CPB flags CMD err flags 0x11" error.

* repeatedly hot-plugging a PCI Express card may have caused "Bad DLLP"
errors.

* a NULL pointer dereference in NFS, which may have caused applications to
crash, has been resolved.

* when attempting to kexec reboot, either manually or via a panic-triggered
kdump, the Unisys ES7000/one hanged after rebooting in the new kernel,
after printing the "Memory: 32839688k/33685504k available" line.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0233</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1367</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1669</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080233"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080235" severity="high">
    <xccdf:title>RHSA-2008:0235: speex security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Speex is a patent-free compression format designed especially for speech.
The Speex package contains a library for handling Speex files and sample
encoder and decoder implementations using this library.

The Speex library was found to not properly validate input values read from
the Speex files headers. An attacker could create a malicious Speex file
that would crash an application or, possibly, allow arbitrary code
execution with the privileges of the application calling the Speex library.
(CVE-2008-1686)

All users of speex are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1686</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080235"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080237" severity="high">
    <xccdf:title>RHSA-2008:0237: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* the absence of a protection mechanism when attempting to access a
critical section of code has been found in the Linux kernel open file
descriptors control mechanism, fcntl. This could allow a local unprivileged
user to simultaneously execute code, which would otherwise be protected
against parallel execution. As well, a race condition when handling locks
in the Linux kernel fcntl functionality, may have allowed a process
belonging to a local unprivileged user to gain re-ordered access to the
descriptor table. (CVE-2008-1669, Important)

* on AMD64 architectures, the possibility of a kernel crash was discovered
by testing the Linux kernel process-trace ability. This could allow a local
unprivileged user to cause a denial of service (kernel crash).
(CVE-2008-1615, Important)

* the absence of a protection mechanism when attempting to access a
critical section of code, as well as a race condition, have been found
in the Linux kernel file system event notifier, dnotify. This could allow a
local unprivileged user to get inconsistent data, or to send arbitrary
signals to arbitrary system processes. (CVE-2008-1375, Important)

Red Hat would like to thank Nick Piggin for responsibly disclosing the
following issue:

* when accessing kernel memory locations, certain Linux kernel drivers
registering a fault handler did not perform required range checks. A local
unprivileged user could use this flaw to gain read or write access to
arbitrary kernel memory, or possibly cause a kernel crash.
(CVE-2008-0007, Important)

* the possibility of a kernel crash was found in the Linux kernel IPsec
protocol implementation, due to improper handling of fragmented ESP
packets. When an attacker controlling an intermediate router fragmented
these packets into very small pieces, it would cause a kernel crash on the
receiving node during packet reassembly. (CVE-2007-6282, Important)

* a flaw in the MOXA serial driver could allow a local unprivileged user
to perform privileged operations, such as replacing firmware.
(CVE-2005-0504, Important)

As well, these updated packages fix the following bugs:

* multiple buffer overflows in the neofb driver have been resolved. It was
not possible for an unprivileged user to exploit these issues, and as such,
they have not been handled as security issues.

* a kernel panic, due to inconsistent detection of AGP aperture size, has
been resolved.

* a race condition in UNIX domain sockets may have caused "recv()" to
return zero. In clustered configurations, this may have caused unexpected
failovers.

* to prevent link storms, network link carrier events were delayed by up to
one second, causing unnecessary packet loss. Now, link carrier events are
scheduled immediately.

* a client-side race on blocking locks caused large time delays on NFS file
systems.

* in certain situations, the libATA sata_nv driver may have sent commands
with duplicate tags, which were rejected by SATA devices. This may have
caused infinite reboots.

* running the "service network restart" command may have caused networking
to fail.

* a bug in NFS caused cached information about directories to be stored
for too long, causing wrong attributes to be read.

* on systems with a large highmem/lowmem ratio, NFS write performance may
have been very slow when using small files.

* a bug, which caused network hangs when the system clock was wrapped
around zero, has been resolved.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-0504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6282</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1669</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080237"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080238" severity="high">
    <xccdf:title>RHSA-2008:0238: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including kpdf, a PDF file viewer.

Kees Cook discovered a flaw in the way kpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause kpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080238"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080239" severity="high">
    <xccdf:title>RHSA-2008:0239: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a PDF rendering library, used by applications such as Evince.

Kees Cook discovered a flaw in the way poppler displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause applications that use poppler -- such as Evince -- to crash,
or, potentially, execute arbitrary code when opened. (CVE-2008-1693)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0239</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080239"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080240" severity="high">
    <xccdf:title>RHSA-2008:0240: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files.

Kees Cook discovered a flaw in the way xpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause xpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0240</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080240"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080262" severity="high">
    <xccdf:title>RHSA-2008:0262: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gpdf is a GNOME-based viewer for Portable Document Format (PDF) files.

Kees Cook discovered a flaw in the way gpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause gpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

Users of gpdf are advised to upgrade to this updated package, which
contains a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080262"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080270" severity="high">
    <xccdf:title>RHSA-2008:0270: libvorbis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Will Drewry of the Google Security Team reported several flaws in the way
libvorbis processed audio data. An attacker could create a carefully
crafted OGG audio file in such a way that it could cause an application
linked with libvorbis to crash, or execute arbitrary code when it was
opened. (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423)

Moreover, additional OGG file sanity-checks have been added to prevent
possible exploitation of similar issues in the future.

Users of libvorbis are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1423</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080270"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080275" severity="high">
    <xccdf:title>RHSA-2008:0275: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* on AMD64 architectures, the possibility of a kernel crash was discovered
by testing the Linux kernel process-trace ability. This could allow a local
unprivileged user to cause a denial of service (kernel crash).
(CVE-2008-1615, Important)

* on 64-bit architectures, the possibility of a timer-expiration value
overflow was found in the Linux kernel high-resolution timers
functionality, hrtimer. This could allow a local unprivileged user to setup
a large interval value, forcing the timer expiry value to become negative,
causing a denial of service (kernel hang). (CVE-2007-6712, Important)

* the possibility of a kernel crash was found in the Linux kernel IPsec
protocol implementation, due to improper handling of fragmented ESP
packets. When an attacker controlling an intermediate router fragmented
these packets into very small pieces, it would cause a kernel crash on the
receiving node during packet reassembly. (CVE-2007-6282, Important)

* a potential denial of service attack was discovered in the Linux kernel
PWC USB video driver. A local unprivileged user could use this flaw to
bring the kernel USB subsystem into the busy-waiting state, causing a
denial of service. (CVE-2007-5093, Low)

As well, these updated packages fix the following bugs:

* in certain situations, a kernel hang and a possible panic occurred when
disabling the cpufreq daemon. This may have prevented system reboots from
completing successfully.

* continual "softlockup" messages, which occurred on the guest's console
after a successful save and restore of a Red Hat Enterprise Linux 5
para-virtualized guest, have been resolved.

* in the previous kernel packages, the kernel may not have reclaimed NFS
locks after a system reboot.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6282</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1615</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080275"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080287" severity="high">
    <xccdf:title>RHSA-2008:0287: libxslt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libxslt is a C library, based on libxml, for parsing of XML files into
other textual formats (eg HTML, plain text and other XML representations of
the underlying data). It uses the standard XSLT stylesheet transformation
mechanism and, being written in plain ANSI C, is designed to be simple to
incorporate into other applications

Anthony de Almeida Lopes reported the libxslt library did not properly
process long "transformation match" conditions in the XSL stylesheet files.
An attacker could create a malicious XSL file that would cause a crash, or,
possibly, execute and arbitrary code with the privileges of the application
using libxslt library to perform XSL transformations. (CVE-2008-1767)

All users are advised to upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1767</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080287"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080288" severity="high">
    <xccdf:title>RHSA-2008:0288: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A heap-based buffer overflow flaw was found in the way Samba clients handle
over-sized packets. If a client connected to a malicious Samba server, it
was possible to execute arbitrary code as the Samba client user. It was
also possible for a remote user to send a specially crafted print request
to a Samba server that could result in the server executing the vulnerable
client code, resulting in arbitrary code execution with the permissions of
the Samba server. (CVE-2008-1105)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1105</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080288"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080290" severity="high">
    <xccdf:title>RHSA-2008:0290: samba security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A heap-based buffer overflow flaw was found in the way Samba clients handle
over-sized packets. If a client connected to a malicious Samba server, it
was possible to execute arbitrary code as the Samba client user. It was
also possible for a remote user to send a specially crafted print request
to a Samba server that could result in the server executing the vulnerable
client code, resulting in arbitrary code execution with the permissions of
the Samba server. (CVE-2008-1105)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

This update also addresses two issues which prevented Samba from joining
certain Windows domains with tightened security policies, and prevented
certain signed SMB content from working as expected:

* when some Windows® 2000-based domain controllers were set to use
mandatory signing, Samba clients would drop the connection because of an
error when generating signatures. This presented as a "Server packet had
invalid SMB signature" error to the Samba client. This update corrects the
signature generation error.

* Samba servers using the "net ads join" command to connect to a Windows
Server® 2003-based domain would fail with "failed to get schannel session
key from server" and "NT_STATUS_ACCESS_DENIED" errors. This update
correctly binds to the NETLOGON share, allowing Samba servers to connect to
the domain properly.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1105</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080290"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080295" severity="low">
    <xccdf:title>RHSA-2008:0295: vsftpd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The vsftpd package includes a Very Secure File Transfer Protocol (FTP)
daemon.

A memory leak was discovered in the vsftpd daemon. An attacker who is able
to connect to an FTP service, either as an authenticated or anonymous user,
could cause vsftpd to allocate all available memory if the "deny_file"
option was enabled in vsftpd.conf. (CVE-2007-5962)

As well, this updated package fixes following bugs:

* a race condition could occur even when the "lock_upload_files" option is
set. When uploading two files simultaneously, the result was a combination
of the two files. This resulted in uploaded files becoming corrupted. In
these updated packages, uploading two files simultaneously will result in a
file that is identical to the last uploaded file.

* when the "userlist_enable" option is used, failed log in attempts as a
result of the user not being in the list of allowed users, or being in the
list of denied users, will not be logged. In these updated packages, a new
"userlist_log=YES" option can be configured in vsftpd.conf, which will log
failed log in attempts in these situations.

* vsftpd did not support usernames that started with an underscore or a
period character. Usernames starting with an underscore or a period are
supported in these updated packages.

* using wildcards in conjunction with the "ls" command did not return all
the file names it should. For example, if you FTPed into a directory
containing three files -- A1, A21 and A11 -- and ran the "ls *1" command,
only the file names A1 and A21 were returned. These updated packages use
greedier code that continues to speculatively scan for items even after
matches have been found.

* when the "user_config_dir" option is enabled in vsftpd.conf, and the
user-specific configuration file did not exist, the following error
occurred after a user entered their password during the log in process:

500 OOPS: reading non-root config file

This has been resolved in this updated package.

All vsftpd users are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0295</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5962</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080295"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080297" severity="low">
    <xccdf:title>RHSA-2008:0297: dovecot security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.

A flaw was discovered in the way Dovecot handled the "mail_extra_groups"
option. An authenticated attacker with local shell access could leverage
this flaw to read, modify, or delete other users mail that is stored on
the mail server. (CVE-2008-1199)

This issue did not affect the default Red Hat Enterprise Linux 5 Dovecot
configuration. This update adds two new configuration options --
"mail_privileged_group" and "mail_access_groups" -- to minimize the usage
of additional privileges.

A directory traversal flaw was discovered in Dovecot's zlib plug-in. An
authenticated user could use this flaw to view other compressed mailboxes
with the permissions of the Dovecot process. (CVE-2007-2231)

A flaw was found in the Dovecot ACL plug-in. User with only insert
permissions for a mailbox could use the "COPY" and "APPEND" commands to set
additional message flags. (CVE-2007-4211)

A flaw was found in a way Dovecot cached LDAP query results in certain
configurations. This could possibly allow authenticated users to log in as
a different user who has the same password. (CVE-2007-6598)

As well, this updated package fixes the following bugs:

* configuring "userdb" and "passdb" to use LDAP caused Dovecot to hang. A
segmentation fault may have occurred. In this updated package, using an
LDAP backend for "userdb" and "passdb" no longer causes Dovecot to hang.

* the Dovecot "login_process_size" limit was configured for 32-bit systems.
On 64-bit systems, when Dovecot was configured to use either IMAP or POP3,
the log in processes crashed with out-of-memory errors. Errors such as the
following were logged:

pop3-login: pop3-login: error while loading shared libraries:
libsepol.so.1: failed to map segment from shared object: Cannot allocate
memory

In this updated package, the "login_process_size" limit is correctly
configured on 64-bit systems, which resolves this issue.

Note: this updated package upgrades dovecot to version 1.0.7. For
further details, refer to the Dovecot changelog:
http://koji.fedoraproject.org/koji/buildinfo?buildID=23397

Users of dovecot are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0297</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1199</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080297"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080300" severity="medium">
    <xccdf:title>RHSA-2008:0300: bind security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

It was discovered that the bind packages created the "rndc.key" file with
insecure file permissions. This allowed any local user to read the content
of this file. A local user could use this flaw to control some aspects of
the named daemon by using the rndc utility, for example, stopping the named
daemon. This problem did not affect systems with the bind-chroot package
installed. (CVE-2007-6283)

A buffer overflow flaw was discovered in the "inet_network()" function, as
implemented by libbind. An attacker could use this flaw to crash an
application calling this function, with an argument provided from an
untrusted source. (CVE-2008-0122)

As well, these updated packages fix the following bugs:

* when using an LDAP backend, missing function declarations caused
segmentation faults, due to stripped pointers on machines where pointers
are longer than integers.

* starting named may have resulted in named crashing, due to a race
condition during D-BUS connection initialization. This has been resolved in
these updated packages.

* the named init script returned incorrect error codes, causing the
"status" command to return an incorrect status. In these updated packages,
the named init script is Linux Standard Base (LSB) compliant.

* in these updated packages, the "rndc [command] [zone]" command, where
[command] is an rndc command, and [zone] is the specified zone, will find
the [zone] if the zone is unique to all views.

* the default named log rotation script did not work correctly when using
the bind-chroot package. In these updated packages, installing
bind-chroot creates the symbolic link "/var/log/named.log", which points
to "/var/named/chroot/var/log/named.log", which resolves this issue.

* a previous bind update incorrectly changed the permissions on the
"/etc/openldap/schema/dnszone.schema" file to mode 640, instead of mode
644, which resulted in OpenLDAP not being able to start. In these updated
packages, the permissions are correctly set to mode 644.

* the "checkconfig" parameter was missing in the named usage report. For
example, running the "service named" command did not return "checkconfig"
in the list of available options.

* due to a bug in the named init script not handling the rndc return value
correctly, the "service named stop" and "service named restart" commands
failed on certain systems.

* the bind-chroot spec file printed errors when running the "%pre" and
"%post" sections. Errors such as the following occurred:

Locating //etc/named.conf failed:
[FAILED]

This has been resolved in these updated packages.

* installing the bind-chroot package creates a "/dev/random" file in the
chroot environment; however, the "/dev/random" file had an incorrect
SELinux label. Starting named resulted in an 'avc: denied { getattr } for
pid=[pid] comm="named" path="/dev/random"' error being logged. The
"/dev/random" file has the correct SELinux label in these updated packages.

* in certain situations, running the "bind +trace" command resulted in
random segmentation faults.

As well, these updated packages add the following enhancements:

* support has been added for GSS-TSIG (RFC 3645).

* the "named.root" file has been updated to reflect the new address for
L.ROOT-SERVERS.NET.

* updates BIND to the latest 9.3 maintenance release.

All users of bind are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0300</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0122</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080300"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080364" severity="low">
    <xccdf:title>RHSA-2008:0364: mysql security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

MySQL did not require privileges such as "SELECT" for the source table in a
"CREATE TABLE LIKE" statement. An authenticated user could obtain sensitive
information, such as the table structure. (CVE-2007-3781)

A flaw was discovered in MySQL that allowed an authenticated user to gain
update privileges for a table in another database, via a view that refers
to the external table. (CVE-2007-3782)

MySQL did not require the "DROP" privilege for "RENAME TABLE" statements.
An authenticated user could use this flaw to rename arbitrary tables.
(CVE-2007-2691)

A flaw was discovered in the mysql_change_db function when returning from
SQL SECURITY INVOKER stored routines. An authenticated user could use this
flaw to gain database privileges. (CVE-2007-2692)

MySQL allowed an authenticated user to bypass logging mechanisms via SQL
queries that contain the NULL character, which were not properly handled by
the mysql_real_query function. (CVE-2006-0903)

MySQL allowed an authenticated user to access a table through a previously
created MERGE table, even after the user's privileges were revoked from
the original table, which might violate intended security policy. This is
addressed by allowing the MERGE storage engine to be disabled, which can
be done by running mysqld with the "--skip-merge" option. (CVE-2006-4031)

MySQL evaluated arguments in the wrong security context, which allowed an
authenticated user to gain privileges through a routine that had been made
available using "GRANT EXECUTE". (CVE-2006-4227)

Multiple flaws in MySQL allowed an authenticated user to cause the MySQL
daemon to crash via crafted SQL queries. This only caused a temporary
denial of service, as the MySQL daemon is automatically restarted after the
crash. (CVE-2006-7232, CVE-2007-1420, CVE-2007-2583)

As well, these updated packages fix the following bugs:

* a separate counter was used for "insert delayed" statements, which caused
rows to be discarded. In these updated packages, "insert delayed"
statements no longer use a separate counter, which resolves this issue.

* due to a bug in the Native POSIX Thread Library, in certain situations,
"flush tables" caused a deadlock on tables that had a read lock. The mysqld
daemon had to be killed forcefully. Now, "COND_refresh" has been replaced
with "COND_global_read_lock", which resolves this issue.

* mysqld crashed if a query for an unsigned column type contained a
negative value for a "WHERE [column] NOT IN" subquery.

* in master and slave server situations, specifying "on duplicate key
update" for "insert" statements did not update slave servers.

* in the mysql client, empty strings were displayed as "NULL". For
example, running "insert into [table-name] values (' ');" resulted in a
"NULL" entry being displayed when querying the table using "select * from
[table-name];".

* a bug in the optimizer code resulted in certain queries executing much
slower than expected.

* on 64-bit PowerPC architectures, MySQL did not calculate the thread stack
size correctly, which could have caused MySQL to crash when overly-complex
queries were used.

Note: these updated packages upgrade MySQL to version 5.0.45. For a full
list of bug fixes and enhancements, refer to the MySQL release notes:
http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0.html

All mysql users are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-0903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4227</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2691</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2692</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3782</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080364"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080389" severity="low">
    <xccdf:title>RHSA-2008:0389: nss_ldap security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nss_ldap package contains the nss_ldap and pam_ldap modules. The
nss_ldap module is a plug-in which allows applications to retrieve
information about users and groups from a directory server. The pam_ldap
module allows PAM-aware applications to use a directory server to verify
user passwords.

A race condition was discovered in nss_ldap which affected certain
applications which make LDAP connections, such as Dovecot. This could cause
nss_ldap to answer a request for information about one user with
information about a different user. (CVE-2007-5794)

In addition, these updated packages fix the following bugs:

* a build error prevented the nss_ldap module from being able to use DNS to
discover the location of a directory server. For example, when the
/etc/nsswitch.conf configuration file was configured to use "ldap", but no
"host" or "uri" option was configured in the /etc/ldap.conf configuration
file, no directory server was contacted, and no results were returned.

* the "port" option in the /etc/ldap.conf configuration file on client
machines was ignored. For example, if a directory server which you were
attempting to use was listening on a non-default port (i.e. not ports 389
or 636), it was only possible to use that directory server by including the
port number in the "uri" option. In this updated package, the "port" option
works as expected.

* pam_ldap failed to change an expired password if it had to follow a
referral to do so, which could occur, for example, when using a slave
directory server in a replicated environment. An error such as the
following occurred after entering a new password: "LDAP password
information update failed: Can't contact LDAP server Insufficient 'write'
privilege to the 'userPassword' attribute"

This has been resolved in this updated package.

* when the "pam_password exop_send_old" password-change method was
configured in the /etc/ldap.conf configuration file, a logic error in the
pam_ldap module caused client machines to attempt to change a user's
password twice. First, the pam_ldap module attempted to change the password
using the "exop" request, and then again using an LDAP modify request.

* on Red Hat Enterprise Linux 5.1, rebuilding nss_ldap-253-5.el5 when the
krb5-*-1.6.1-17.el5 packages were installed failed due to an error such as
the following:

	+ /builddir/build/SOURCES/dlopen.sh ./nss_ldap-253/nss_ldap.so
	dlopen() of "././nss_ldap-253/nss_ldap.so" failed:
	./././nss_ldap-253/nss_ldap.so: undefined symbol: request_key
	error: Bad exit status from /var/tmp/rpm-tmp.62652 (%build)

The missing libraries have been added, which resolves this issue.

When recursively enumerating the set of members in a given group, the
module would allocate insufficient space for storing the set of member
names if the group itself contained other groups, thus corrupting the heap.
This update includes a backported fix for this bug.

Users of nss_ldap should upgrade to these updated packages, which contain
backported patches to correct this issue and fix these bugs.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5794</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080389"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080485" severity="low">
    <xccdf:title>RHSA-2008:0485: compiz security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Compiz is an OpenGL-based window and compositing manager.

Most screen savers create a top-level fullscreen window to cover the
desktop, and grab the input with that window. Compiz has an option to
un-redirect that window, but in some cases, this breaks the grab and
compromises the locked screen. (CVE-2007-3920)

Users of compiz are advised to upgrade to these updated packages, which
remove this option to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3920</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080485"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080486" severity="medium">
    <xccdf:title>RHSA-2008:0486: nfs-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils package provides a daemon for the kernel NFS server and
related tools.

A flaw was found in the nfs-utils package build. The nfs-utils package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2008-1376)

Users of nfs-utils are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1376</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080486"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080489" severity="high">
    <xccdf:title>RHSA-2008:0489: gnutls security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS Library provides support for cryptographic algorithms and
protocols such as TLS. GnuTLS includes libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Flaws were found in the way GnuTLS handles malicious client connections. A
malicious remote client could send a specially crafted request to a service
using GnuTLS that could cause the service to crash. (CVE-2008-1948,
CVE-2008-1949, CVE-2008-1950)

We believe it is possible to leverage the flaw CVE-2008-1948 to execute
arbitrary code but have been unable to prove this at the time of releasing
this advisory. Red Hat Enterprise Linux 5 includes applications, such as
CUPS, that would be directly vulnerable to any such an exploit, however.
Consequently, we have assigned it critical severity.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0489</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1948</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1949</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1950</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080489"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080492" severity="high">
    <xccdf:title>RHSA-2008:0492: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS Library provides support for cryptographic algorithms and
protocols such as TLS. GnuTLS includes libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Flaws were found in the way GnuTLS handles malicious client connections. A
malicious remote client could send a specially crafted request to a service
using GnuTLS that could cause the service to crash. (CVE-2008-1948,
CVE-2008-1949, CVE-2008-1950)

We believe it is possible to leverage the flaw CVE-2008-1948 to execute
arbitrary code but have been unable to prove this at the time of releasing
this advisory. Red Hat Enterprise Linux 4 does not ship with any
applications directly affected by this flaw. Third-party software which
runs on Red Hat Enterprise Linux 4 could, however, be affected by this
vulnerability. Consequently, we have assigned it important severity.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1948</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1949</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1950</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080492"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080497" severity="high">
    <xccdf:title>RHSA-2008:0497: sblim security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SBLIM stands for Standards-Based Linux Instrumentation for Manageability.
It consists of a set of standards-based, Web-Based Enterprise Management
(WBEM) modules that use the Common Information Model (CIM) standard to
gather and provide systems management information, events, and methods to
local or networked consumers via a CIM object services broker using the
CMPI (Common Manageability Programming Interface) standard. This package
provides a set of core providers and development tools for systems
management applications.

It was discovered that certain sblim libraries had an RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) header.
This RPATH pointed to a sub-directory of a world-writable, temporary
directory. A local user could create a file with the same name as a library
required by sblim (such as libc.so) and place it in the directory defined
in the RPATH. This file could then execute arbitrary code with the
privileges of the user running an application that used sblim (eg
tog-pegasus). (CVE-2008-1951)

Users are advised to upgrade to these updated sblim packages, which resolve
this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1951</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080497"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080498" severity="medium">
    <xccdf:title>RHSA-2008:0498: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw leading to a heap buffer overflow was discovered
in the Portable Network Graphics (PNG) decoding routines used by the CUPS
image converting filters "imagetops" and "imagetoraster". An attacker could
create a malicious PNG file that could possibly execute arbitrary code as
the "lp" user if the file was printed. (CVE-2008-1722)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1722</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080498"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080503" severity="high">
    <xccdf:title>RHSA-2008:0503: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xorg-x11 packages contain X.Org, an open source implementation of the X
Window System. It provides the basic low-level functionality that
full-fledged graphical user interfaces are designed upon.

An input validation flaw was discovered in X.org's Security and Record
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or, potentially, execute arbitrary code with
root privileges on the X.Org server. (CVE-2008-1377)

Multiple integer overflow flaws were found in X.org's Render extension. A
malicious authorized client could exploit these issues to cause a denial of
service (crash) or, potentially, execute arbitrary code with root
privileges on the X.Org server. (CVE-2008-2360, CVE-2008-2361)

An input validation flaw was discovered in X.org's MIT-SHM extension. A
client connected to the X.org server could read arbitrary server memory.
This could result in the sensitive data of other users of the X.org server
being disclosed. (CVE-2008-1379)

Users of xorg-x11 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2360</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2361</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080503"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080504" severity="high">
    <xccdf:title>RHSA-2008:0504: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
basic low-level functionality that full-fledged graphical user interfaces
are designed upon.

An input validation flaw was discovered in X.org's Security and Record
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or, potentially, execute arbitrary code with
root privileges on the X.Org server. (CVE-2008-1377)

Multiple integer overflow flaws were found in X.org's Render extension. A
malicious authorized client could exploit these issues to cause a denial of
service (crash) or, potentially, execute arbitrary code with root
privileges on the X.Org server. (CVE-2008-2360, CVE-2008-2361,
CVE-2008-2362)

An input validation flaw was discovered in X.org's MIT-SHM extension. A
client connected to the X.org server could read arbitrary server memory.
This could result in the sensitive data of other users of the X.org server
being disclosed. (CVE-2008-1379)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2360</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2361</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2362</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080504"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080508" severity="high">
    <xccdf:title>RHSA-2008:0508: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* A security flaw was found in the Linux kernel memory copy routines, when
running on certain AMD64 systems. If an unsuccessful attempt to copy kernel
memory from source to destination memory locations occurred, the copy
routines did not zero the content at the destination memory location. This
could allow a local unprivileged user to view potentially sensitive data.
(CVE-2008-2729, Important)

* Alexey Dobriyan discovered a race condition in the Linux kernel
process-tracing system call, ptrace. A local unprivileged user could
use this flaw to cause a denial of service (kernel hang).
(CVE-2008-2365, Important)

* Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and
64-bit emulation. This could allow a local unprivileged user to prepare and
run a specially crafted binary, which would use this deficiency to leak
uninitialized and potentially sensitive data. (CVE-2008-0598, Important)

* It was discovered that the Linux kernel handled string operations in the
opposite way to the GNU Compiler Collection (GCC). This could allow a local
unprivileged user to cause memory corruption. (CVE-2008-1367, Low)

As well, these updated packages fix the following bug:

* On systems with a large number of CPUs (more than 16), multiple
applications calling the "times()" system call may have caused a system
hang.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1367</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2729</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080508"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080514" severity="high">
    <xccdf:title>RHSA-2008:0514: evolution security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If the Itip Formatter plug-in was disabled and a user opened a mail
with a carefully crafted iCalendar attachment, arbitrary code could be
executed as the user running Evolution. (CVE-2008-1108)

Note: the Itip Formatter plug-in, which allows calendar information
(attachments with a MIME type of "text/calendar") to be displayed as part
of the e-mail message, is enabled by default.

A heap-based buffer overflow flaw was found in the way Evolution parsed
iCalendar attachments with an overly long "DESCRIPTION" property string. If
a user responded to a carefully crafted iCalendar attachment in a
particular way, arbitrary code could be executed as the user running
Evolution. (CVE-2008-1109).

The particular response required to trigger this vulnerability was as
follows:

1. Receive the carefully crafted iCalendar attachment.
2. Accept the associated meeting.
3. Open the calender the meeting was in.
4. Reply to the sender.

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing these issues.

All Evolution users should upgrade to these updated packages, which contain
backported patches which resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0514</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1109</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080514"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080515" severity="high">
    <xccdf:title>RHSA-2008:0515: evolution28 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If the Itip Formatter plug-in was disabled and a user opened a mail
with a carefully crafted iCalendar attachment, arbitrary code could be
executed as the user running Evolution. (CVE-2008-1108)

Note: the Itip Formatter plug-in, which allows calendar information
(attachments with a MIME type of "text/calendar") to be displayed as part
of the e-mail message, is enabled by default.

A heap-based buffer overflow flaw was found in the way Evolution parsed
iCalendar attachments with an overly long "DESCRIPTION" property string. If
a user responded to a carefully crafted iCalendar attachment in a
particular way, arbitrary code could be executed as the user running
Evolution. (CVE-2008-1109).

The particular response required to trigger this vulnerability was as
follows:

1. Receive the carefully crafted iCalendar attachment.
2. Accept the associated meeting.
3. Open the calender the meeting was in.
4. Reply to the sender.

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing these issues.

All Evolution users should upgrade to these updated packages, which contain
backported patches which resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1109</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080515"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080516" severity="high">
    <xccdf:title>RHSA-2008:0516: evolution security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If mail which included a carefully crafted iCalendar attachment was
opened, arbitrary code could be executed as the user running Evolution.
(CVE-2008-1108)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

All users of Evolution should upgrade to these updated packages, which
contains a backported patch which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080516"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080519" severity="high">
    <xccdf:title>RHSA-2008:0519: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* A security flaw was found in the Linux kernel memory copy routines, when
running on certain AMD64 systems. If an unsuccessful attempt to copy kernel
memory from source to destination memory locations occurred, the copy
routines did not zero the content at the destination memory location. This
could allow a local unprivileged user to view potentially sensitive data.
(CVE-2008-2729, Important)

* Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and
64-bit emulation. This could allow a local unprivileged user to prepare and
run a specially crafted binary, which would use this deficiency to leak
uninitialized and potentially sensitive data. (CVE-2008-0598, Important)

* Brandon Edwards discovered a missing length validation check in the Linux
kernel DCCP module reconciliation feature. This could allow a local
unprivileged user to cause a heap overflow, gaining privileges for
arbitrary code execution. (CVE-2008-2358, Moderate)

As well, these updated packages fix the following bug:

* Due to a regression, "gettimeofday" may have gone backwards on certain
x86 hardware. This issue was quite dangerous for time-sensitive systems,
such as those used for transaction systems and databases, and may have
caused applications to produce incorrect results, or even crash.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2358</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2729</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080519"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080522" severity="high">
    <xccdf:title>RHSA-2008:0522: perl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

A flaw was found in Perl's regular expression engine. A specially crafted
regular expression with Unicode characters could trigger a buffer overflow,
causing Perl to crash, or possibly execute arbitrary code with the
privileges of the user running Perl. (CVE-2008-1927)

Users of perl are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1927</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080522"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080529" severity="medium">
    <xccdf:title>RHSA-2008:0529: net-snmp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

A flaw was found in the way Net-SNMP checked an SNMPv3 packet's Keyed-Hash
Message Authentication Code (HMAC). An attacker could use this flaw to
spoof an authenticated SNMPv3 packet. (CVE-2008-0960)

A buffer overflow was found in the Perl bindings for Net-SNMP. This could
be exploited if an attacker could convince an application using the
Net-SNMP Perl module to connect to a malicious SNMP agent. (CVE-2008-2292)

All users of net-snmp should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2292</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080529"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080533" severity="high">
    <xccdf:title>RHSA-2008:0533: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.

The DNS protocol protects against spoofing attacks by requiring an attacker
to predict both the DNS transaction ID and UDP source port of a request. In
recent years, a number of papers have found problems with DNS
implementations which make it easier for an attacker to perform DNS
cache-poisoning attacks.

Previous versions of BIND did not use randomized UDP source ports. If an
attacker was able to predict the random DNS transaction ID, this could make
DNS cache-poisoning attacks easier. In order to provide more resilience,
BIND has been updated to use a range of random UDP source ports.
(CVE-2008-1447)

Note: This errata also updates SELinux policy on Red Hat Enterprise Linux 4
and 5 to allow BIND to use random UDP source ports.

Users of BIND are advised to upgrade to these updated packages, which
contain a backported patch to add this functionality.

Red Hat would like to thank Dan Kaminsky for reporting this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080533"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080537" severity="high">
    <xccdf:title>RHSA-2008:0537: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Sean Larsson found a heap overflow flaw in the OpenOffice memory allocator.
If a carefully crafted file was opened by a victim, an attacker could use
the flaw to crash OpenOffice.org or, possibly, execute arbitrary code.
(CVE-2008-2152)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2152</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080537"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080538" severity="high">
    <xccdf:title>RHSA-2008:0538: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Sean Larsson found a heap overflow flaw in the OpenOffice memory allocator.
If a carefully crafted file was opened by a victim, an attacker could use
the flaw to crash OpenOffice.org or, possibly, execute arbitrary code.
(CVE-2008-2152)

It was discovered that certain libraries in the Red Hat Enterprise Linux 3
and 4 openoffice.org packages had an insecure relative RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) header.
A local user able to convince another user to run OpenOffice in an
attacker-controlled directory, could run arbitrary code with the privileges
of the victim. (CVE-2008-2366)

All users of openoffice.org are advised to upgrade to these updated
packages, which contain backported fixes which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2366</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080538"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080544" severity="medium">
    <xccdf:title>RHSA-2008:0544: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

It was discovered that the PHP escapeshellcmd() function did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmd() and execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)

PHP functions htmlentities() and htmlspecialchars() did not properly
recognize partial multi-byte sequences. Certain sequences of bytes could be
passed through these functions without being correctly HTML-escaped.
Depending on the browser being used, an attacker could use this flaw to
conduct cross-site scripting attacks. (CVE-2007-5898)

A PHP script which used the transparent session ID configuration option, or
which used the output_add_rewrite_var() function, could leak session
identifiers to external web sites. If a page included an HTML form with an
ACTION attribute referencing a non-local URL, the user's session ID would
be included in the form data passed to that URL. (CVE-2007-5899)

It was discovered that PHP fnmatch() function did not restrict the length
of the string argument. An attacker could use this flaw to crash the PHP
interpreter where a script used fnmatch() on untrusted input data.
(CVE-2007-4782)

It was discovered that PHP did not properly seed its pseudo-random number
generator used by functions such as rand() and mt_rand(), possibly allowing
an attacker to easily predict the generated pseudo-random values.
(CVE-2008-2107, CVE-2008-2108)

Users of PHP should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5899</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2107</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080544"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080545" severity="medium">
    <xccdf:title>RHSA-2008:0545: php security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

It was discovered that the PHP escapeshellcmd() function did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmd() and execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)

The PHP functions htmlentities() and htmlspecialchars() did not properly
recognize partial multi-byte sequences. Certain sequences of bytes could be
passed through these functions without being correctly HTML-escaped.
Depending on the browser being used, an attacker could use this flaw to
conduct cross-site scripting attacks. (CVE-2007-5898)

A PHP script which used the transparent session ID configuration option, or
which used the output_add_rewrite_var() function, could leak session
identifiers to external web sites. If a page included an HTML form with an
ACTION attribute referencing a non-local URL, the user's session ID would
be included in the form data passed to that URL. (CVE-2007-5899)

It was discovered that the PHP fnmatch() function did not restrict the
length of the string argument. An attacker could use this flaw to crash the
PHP interpreter where a script used fnmatch() on untrusted input data.
(CVE-2007-4782)

It was discovered that PHP did not properly seed its pseudo-random number
generator used by functions such as rand() and mt_rand(), possibly allowing
an attacker to easily predict the generated pseudo-random values.
(CVE-2008-2107, CVE-2008-2108)

As well, these updated packages fix the following bug:

* after 2008-01-01, when using PEAR version 1.3.6 or older, it was not
possible to use the PHP Extension and Application Repository (PEAR) to
upgrade or install packages. In these updated packages, PEAR has been
upgraded to version 1.4.9, which restores support for the current
pear.php.net update server. The following changes were made to the PEAR
packages included in php-pear: Console_Getopt and Archive_Tar are now
included by default, and XML_RPC has been upgraded to version 1.5.0.

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5899</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2107</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080545"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080547" severity="high">
    <xccdf:title>RHSA-2008:0547: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause SeaMonkey
to crash or, potentially, execute arbitrary code as the user running
SeaMonkey. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in SeaMonkey. A web page
containing malicious content could cause SeaMonkey to reveal the contents
of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
SeaMonkey. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way SeaMonkey escaped a listing of local file
names. If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running SeaMonkey. (CVE-2008-2808)

A flaw was found in the way SeaMonkey displayed information about
self-signed certificates. It was possible for a self-signed certificate to
contain multiple alternate name entries, which were not all displayed to
the user, allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080547"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080549" severity="high">
    <xccdf:title>RHSA-2008:0549: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause Firefox
to crash or, potentially, execute arbitrary code as the user running
Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Firefox. A web page
containing malicious content could cause Firefox to reveal the contents of
a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Firefox. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Firefox escaped a listing of local file names.
If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Firefox. (CVE-2008-2808)

A flaw was found in the way Firefox displayed information about self-signed
certificates. It was possible for a self-signed certificate to contain
multiple alternate name entries, which were not all displayed to the user,
allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All Mozilla Firefox users should upgrade to this updated package, which
contains backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080549"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080556" severity="high">
    <xccdf:title>RHSA-2008:0556: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files, as well as efficiently load, hint and render individual
glyphs.

Multiple flaws were discovered in FreeType's Printer Font Binary (PFB)
font-file format parser. If a user loaded a carefully crafted font-file
with a program linked against FreeType, it could cause the application to
crash, or possibly execute arbitrary code. (CVE-2008-1806, CVE-2008-1807,
CVE-2008-1808)

Note: the flaw in FreeType's TrueType Font (TTF) font-file format parser,
covered by CVE-2008-1808, did not affect the freetype packages as shipped
in Red Hat Enterprise Linux 3, 4, and 5, as they are not compiled with TTF
Byte Code Interpreter (BCI) support.

Users of freetype should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1808</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080556"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080561" severity="medium">
    <xccdf:title>RHSA-2008:0561: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

Multiple integer overflows leading to a heap overflow were discovered in
the array- and string-handling code used by Ruby. An attacker could use
these flaws to crash a Ruby application or, possibly, execute arbitrary
code with the privileges of the Ruby application using untrusted inputs in
array or string operations. (CVE-2008-2376, CVE-2008-2662, CVE-2008-2663,
CVE-2008-2725, CVE-2008-2726)

It was discovered that Ruby used the alloca() memory allocation function in
the format (%) method of the String class without properly restricting
maximum string length. An attacker could use this flaw to crash a Ruby
application or, possibly, execute arbitrary code with the privileges of the
Ruby application using long, untrusted strings as format strings.
(CVE-2008-2664)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.

Users of Ruby should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2662</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2663</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2726</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080561"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080569" severity="high">
    <xccdf:title>RHSA-2008:0569: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause Firefox
to crash or, potentially, execute arbitrary code as the user running
Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Firefox. A web page
containing malicious content could cause Firefox to reveal the contents of
a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Firefox. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Firefox escaped a listing of local file names.
If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Firefox. (CVE-2008-2808)

A flaw was found in the way Firefox displayed information about self-signed
certificates. It was possible for a self-signed certificate to contain
multiple alternate name entries, which were not all displayed to the user,
allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All Mozilla Firefox users should upgrade to these updated packages, which
contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080569"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080575" severity="medium">
    <xccdf:title>RHSA-2008:0575: rdesktop security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.

An integer underflow and integer signedness issue were discovered in the
rdesktop. If an attacker could convince a victim to connect to a malicious
RDP server, the attacker could cause the victim's rdesktop to crash or,
possibly, execute an arbitrary code. (CVE-2008-1801, CVE-2008-1803)

Users of rdesktop should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1803</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080575"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080580" severity="medium">
    <xccdf:title>RHSA-2008:0580: vim security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Vim (Visual editor IMproved) is an updated and improved version of the vi
editor.

Several input sanitization flaws were found in Vim's keyword and tag
handling. If Vim looked up a document's maliciously crafted tag or keyword,
it was possible to execute arbitrary code as the user running Vim.
(CVE-2008-4101)

Multiple security flaws were found in netrw.vim, the Vim plug-in providing
file reading and writing over the network. If a user opened a specially
crafted file or directory with the netrw plug-in, it could result in
arbitrary code execution as the user running Vim. (CVE-2008-3076)

A security flaw was found in zip.vim, the Vim plug-in that handles ZIP
archive browsing. If a user opened a ZIP archive using the zip.vim plug-in,
it could result in arbitrary code execution as the user running Vim.
(CVE-2008-3075)

A security flaw was found in tar.vim, the Vim plug-in which handles TAR
archive browsing. If a user opened a TAR archive using the tar.vim plug-in,
it could result in arbitrary code execution as the user runnin Vim.
(CVE-2008-3074)

Several input sanitization flaws were found in various Vim system
functions. If a user opened a specially crafted file, it was possible to
execute arbitrary code as the user running Vim. (CVE-2008-2712)

Ulf Härnhammar, of Secunia Research, discovered a format string flaw in
Vim's help tag processor. If a user was tricked into executing the
"helptags" command on malicious data, arbitrary code could be executed with
the permissions of the user running Vim. (CVE-2007-2953)

All Vim users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2953</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080581" severity="medium">
    <xccdf:title>RHSA-2008:0581: bluez-libs and bluez-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The bluez-libs package contains libraries for use in Bluetooth
applications. The bluez-utils package contains Bluetooth daemons and utilities.

An input validation flaw was found in the Bluetooth Session Description
Protocol (SDP) packet parser used by the Bluez Bluetooth utilities. A
Bluetooth device with an already-established trust relationship, or a local
user registering a service record via a UNIX® socket or D-Bus interface,
could cause a crash, or possibly execute arbitrary code with privileges of
the hcid daemon. (CVE-2008-2374)

Users of bluez-libs and bluez-utils are advised to upgrade to these updated
packages, which contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080581"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080583" severity="high">
    <xccdf:title>RHSA-2008:0583: openldap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.

A denial of service flaw was found in the way the OpenLDAP slapd daemon
processed certain network messages. An unauthenticated remote attacker
could send a specially crafted request that would crash the slapd daemon.
(CVE-2008-2952)

Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2952</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080583"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080584" severity="high">
    <xccdf:title>RHSA-2008:0584: pidgin security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is a multi-protocol Internet Messaging client.

An integer overflow flaw was found in Pidgin's MSN protocol handler. If a
user received a malicious MSN message, it was possible to execute arbitrary
code with the permissions of the user running Pidgin. (CVE-2008-2927)

Note: the default Pidgin privacy setting only allows messages from users in
the buddy list. This prevents arbitrary MSN users from exploiting this
flaw.

This update also addresses the following bug:

* when attempting to connect to the ICQ network, Pidgin would fail to
connect, present an alert saying the "The client version you are using is
too old", and de-activate the ICQ account. This update restores Pidgin's
ability to connect to the ICQ network.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2927</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080584"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080597" severity="high">
    <xccdf:title>RHSA-2008:0597: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

An integer overflow flaw was found in the way Firefox displayed certain web
content. A malicious web site could cause Firefox to crash, or execute
arbitrary code with the permissions of the user running Firefox.
(CVE-2008-2785)

A flaw was found in the way Firefox handled certain command line URLs. If
another application passed Firefox a malformed URL, it could result in
Firefox executing local malicious content with chrome privileges.
(CVE-2008-2933)

All firefox users should upgrade to these updated packages, which contain
Firefox 3.0.1 that corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3198</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080597"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080598" severity="high">
    <xccdf:title>RHSA-2008:0598: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

An integer overflow flaw was found in the way Firefox displayed certain web
content. A malicious web site could cause Firefox to crash, or execute
arbitrary code with the permissions of the user running Firefox.
(CVE-2008-2785)

A flaw was found in the way Firefox handled certain command line URLs. If
another application passed Firefox a malformed URL, it could result in
Firefox executing local malicious content with chrome privileges.
(CVE-2008-2933)

All firefox users should upgrade to this updated package, which contains
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2933</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080598"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080599" severity="high">
    <xccdf:title>RHSA-2008:0599: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

An integer overflow flaw was found in the way SeaMonkey displayed certain
web content. A malicious web site could cause SeaMonkey to crash or execute
arbitrary code with the permissions of the user running SeaMonkey.
(CVE-2008-2785)

All seamonkey users should upgrade to these updated packages, which contain
a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2785</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080599"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080607" severity="high">
    <xccdf:title>RHSA-2008:0607: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issue:

* a possible kernel memory leak was found in the Linux kernel Simple
Internet Transition (SIT) INET6 implementation. This could allow a local
unprivileged user to cause a denial of service. (CVE-2008-2136, Important)

As well, these updated packages fix the following bugs:

* a possible kernel hang on hugemem systems, due to a bug in NFS, which may
have caused systems to become unresponsive, has been resolved.

* an inappropriate exit condition occurred in the architecture-specific
"mmap()" realization, which fell into an infinite loop under certain
conditions. On 64-bit systems, this issue may have manifested itself to
users as a soft lockup, or process hangs.

* due to a bug in hardware initialization in the "ohci_hcd" kernel module,
the kernel may have failed with a NULL pointer dereference. On 64-bit
PowerPC systems, this may have caused booting to fail, and drop to xmon. On
other platforms, a kernel oops occurred.

* due to insufficient locks in task termination code, a panic may have
occurred in the "sys_times()" system call on SMP machines.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0607</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2136</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080607"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080612" severity="high">
    <xccdf:title>RHSA-2008:0612: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a possible kernel memory leak was found in the Linux kernel Simple
Internet Transition (SIT) INET6 implementation. This could allow a local
unprivileged user to cause a denial of service. (CVE-2008-2136, Important)

* a flaw was found in the Linux kernel setrlimit system call, when setting
RLIMIT_CPU to a certain value. This could allow a local unprivileged user
to bypass the CPU time limit. (CVE-2008-1294, Moderate)

* multiple NULL pointer dereferences were found in various Linux kernel
network drivers. These drivers were missing checks for terminal validity,
which could allow privilege escalation. (CVE-2008-2812, Moderate)

These updated packages fix the following bugs:

* the GNU libc stub resolver is a minimal resolver that works with Domain
Name System (DNS) servers to satisfy requests from applications for names.
The GNU libc stub resolver did not specify a source UDP port, and therefore
used predictable port numbers. This could have made DNS spoofing attacks
easier.

The Linux kernel has been updated to implement random UDP source ports
where none are specified by an application. This allows applications, such
as those using the GNU libc stub resolver, to use random UDP source ports,
helping to make DNS spoofing attacks harder.

* when using certain hardware, a bug in UART_BUG_TXEN may have caused
incorrect hardware detection, causing data flow to "/dev/ttyS1" to hang.

* a 50-75% drop in NFS server rewrite performance, compared to Red Hat
Enterprise Linux 4.6, has been resolved.

* due a bug in the fast userspace mutex code, while one thread fetched a
pointer, another thread may have removed it, causing the first thread to
fetch the wrong pointer, possibly causing a system crash.

* on certain Hitachi hardware, removing the "uhci_hcd" module caused a
kernel oops, and the following error:

BUG: warning at arch/ia64/kernel/iosapic.c:1001/iosapic_unregister_intr()

Even after the "uhci_hcd" module was reloaded, there was no access to USB
devices. As well, on systems that have legacy interrupts,
"acpi_unregister_gsi" incorrectly called "iosapci_unregister_intr()",
causing warning messages to be logged.

* when a page was mapped with mmap(), and "PROT_WRITE" was the only
"prot" argument, the first read of that page caused a segmentation fault.
If the page was read after it was written to, no fault occurred. This was
incompatible with the Red Hat Enterprise Linux 4 behavior.

* due to a NULL pointer dereference in powernowk8_init(), a panic may
have occurred.

* certain error conditions handled by the bonding sysfs interface could
have left rtnl_lock() unbalanced, either by locking and returning without
unlocking, or by unlocking when it did not lock, possibly causing a
"kernel: RTNL: assertion failed at net/core/fib_rules.c" error.

* the kernel currently expects a maximum of six Machine Check Exception
(MCE) banks to be exposed by a CPU. Certain CPUs have 7 or more, which may
have caused the MCE to be incorrectly reported.

* a race condition in UNIX domain sockets may have caused recv() to return
zero. For clusters, this may have caused unexpected failovers.

* msgrcv() frequently returned an incorrect "ERESTARTNOHAND (514)" error
number.

* on certain Intel Itanium-based systems, when kdump was configured to halt
the system after a dump operation, after the "System halted." output, the
kernel continued to output endless "soft lockup" messages.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1294</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2812</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080612"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080616" severity="medium">
    <xccdf:title>RHSA-2008:0616: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Multiple flaws were found in the processing of malformed JavaScript
content. An HTML mail containing such malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code as the user
running Thunderbird. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed HTML content. An
HTML mail containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code as the user running Thunderbird.
(CVE-2008-2785, CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed HTML content was displayed.
An HTML mail containing specially-crafted content could, potentially, trick
a Thunderbird user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Thunderbird. An HTML mail
containing malicious content could cause Thunderbird to reveal the contents
of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Thunderbird. A malicious extension could read uninitialized memory,
possibly leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Thunderbird escaped a listing of local file
names. If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Thunderbird. (CVE-2008-2808)

A flaw was found in the way Thunderbird displayed information about
self-signed certificates. It was possible for a self-signed certificate to
contain multiple alternate name entries, which were not all displayed to
the user, allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2811</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080616"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080617" severity="medium">
    <xccdf:title>RHSA-2008:0617: vim security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Vim (Visual editor IMproved) is an updated and improved version of the vi
editor.

Several input sanitization flaws were found in Vim's keyword and tag
handling. If Vim looked up a document's maliciously crafted tag or keyword,
it was possible to execute arbitrary code as the user running Vim.
(CVE-2008-4101)

A heap-based overflow flaw was discovered in Vim's expansion of file name
patterns with shell wildcards. An attacker could create a specially-crafted
file or directory name that, when opened by Vim, caused the application to
crash or, possibly, execute arbitrary code. (CVE-2008-3432)

Several input sanitization flaws were found in various Vim system
functions. If a user opened a specially crafted file, it was possible to
execute arbitrary code as the user running Vim. (CVE-2008-2712)

Ulf Härnhammar, of Secunia Research, discovered a format string flaw in
Vim's help tag processor. If a user was tricked into executing the
"helptags" command on malicious data, arbitrary code could be executed with
the permissions of the user running Vim. (CVE-2007-2953)

All Vim users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0617</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2953</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4101</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080617"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080648" severity="high">
    <xccdf:title>RHSA-2008:0648: tomcat security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A cross-site scripting vulnerability was discovered in the
HttpServletResponse.sendError() method. A remote attacker could inject
arbitrary web script or HTML via forged HTTP headers. (CVE-2008-1232)

An additional cross-site scripting vulnerability was discovered in the host
manager application. A remote attacker could inject arbitrary web script or
HTML via the hostname parameter. (CVE-2008-1947)

A traversal vulnerability was discovered when using a RequestDispatcher
in combination with a servlet or JSP. A remote attacker could utilize a
specially-crafted request parameter to access protected web resources.
(CVE-2008-2370)

An additional traversal vulnerability was discovered when the
"allowLinking" and "URIencoding" settings were activated. A remote attacker
could use a UTF-8-encoded request to extend their privileges and obtain
local files accessible to the Tomcat process. (CVE-2008-2938)

Users of tomcat should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2938</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080648"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080649" severity="medium">
    <xccdf:title>RHSA-2008:0649: libxslt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libxslt is a library for transforming XML files into other XML files using
the standard XSLT stylesheet transformation mechanism.

A heap buffer overflow flaw was discovered in the RC4 libxslt library
extension. An attacker could create a malicious XSL file that would cause a
crash, or, possibly, execute arbitrary code with the privileges of the
application using the libxslt library to perform XSL transformations on
untrusted XSL style sheets. (CVE-2008-2935)

Red Hat would like to thank Chris Evans for reporting this vulnerability.

All libxslt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0649</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2935</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080649"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080665" severity="medium">
    <xccdf:title>RHSA-2008:0665: Updated kernel packages for Red Hat Enterprise Linux 4.7 (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Kernel Feature Support: 
* iostat displays I/O performance for partitions
* I/O task accounting added to getrusage(), allowing comprehensive core
statistics
* page cache pages count added to show_mem() output
* tux O_ATOMICLOOKUP flag removed from the open() system call: replaced
with O_CLOEXEC
* the kernel now exports process limit information to /proc/[PID]/limits
* implement udp_poll() to reduce likelihood of false positives returned
from select()
* the TCP_RTO_MIN parameter can now be configured to a maximum of 3000
milliseconds. This is configured using "ip route"
* update CIFS to version 1.50

Added Features:
* nfs.enable_ino64 boot command line parameter: enable and disable 32-bit
inode numbers when using NFS
* tick "divider" kernel boot parameter: reduce CPU overhead, and increase
efficiency at the cost of lowering timing accuracy
* /proc/sys/vm/nfs-writeback-lowmem-only tunable parameter: resolve NFS
read performance
* /proc/sys/vm/write-mapped tunable option, allowing the option of faster
NFS reads
* support for Large Receive Offload as a networking module
* core dump masking, allowing a core dump process to skip the shared memory
segments of a process

Virtualization:
* para-virtualized network and block device drivers, to increase
fully-virtualized guest performance
* support for more than three VNIF numbers per guest domain

Platform Support:
* AMD ATI SB800 SATA controller, AMD ATI SB600 and SB700 40-pin IDE cable
* 64-bit DMA support on AMD ATI SB700
* PCI device IDs to support Intel ICH10
* /dev/msr[0-n] device files
* powernow-k8 as a module
* SLB shadow buffer support for IBM POWER6 systems
* support for CPU frequencies greater than 32-bit on IBM POWER5, IBM POWER6
* floating point load and store handler for IBM POWER6

Added Drivers and Updates:
* ixgbe 1.1.18, for the Intel 82598 10GB ethernet controller
* bnx2x 1.40.22, for network adapters on the Broadcom 5710 chipset
* dm-hp-sw 1.0.0, for HP Active/Standby
* zfcp version and bug fixes
* qdio to fix FCP/SCSI write I/O expiring on LPARs
* cio bug fixes
* eHEA latest upstream, and netdump and netconsole support
* ipr driver support for dual SAS RAID controllers
* correct CPU cache info and SATA support for Intel Tolapai
* i5000_edac support for Intel 5000 chipsets
* i3000_edac support for Intel 3000 and 3010 chipsets
* add i2c_piix4 module on 64-bit systems to support AMD ATI SB600, 700
and 800
* i2c-i801 support for Intel Tolapai
* qla4xxx: 5.01.01-d2 to 5.01.02-d4-rhel4.7-00
* qla2xxx: 8.01.07-d4 to 8.01.07-d4-rhel4.7-02
* cciss: 2.6.16 to 2.6.20
* mptfusion: 3.02.99.00rh to 3.12.19.00rh
* lpfc:0: 8.0.16.34 to 8.0.16.40
* megaraid_sas: 00.00.03.13 to 00.00.03.18-rh1
* stex: 3.0.0.1 to  3.6.0101.2
* arcmsr: 1.20.00.13 to 1.20.00.15.rh4u7
* aacraid: 1.1-5[2441] to 1.1.5[2455]

Miscellaneous Updates:
* OFED 1.3 support
* wacom driver to add support for Cintiq 20WSX, Wacom Intuos3 12x19, 12x12
and 4x6 tablets
* sata_svw driver to support Broadcom HT-1100 chipsets
* libata to un-blacklist Hitachi drives to enable NCQ
* ide driver allows command line option to disable ide drivers
* psmouse support for cortps protocol

These updated packages fix the following security issues:

* NULL pointer access due to missing checks for terminal validity.
(CVE-2008-2812, Moderate)

* a security flaw was found in the Linux kernel Universal Disk Format file
system. (CVE-2006-4145, Low)

For further details, refer to the latest Red Hat Enterprise Linux 4.7
release notes: redhat.com/docs/manuals/enterprise</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0665</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2812</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080665"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080680" severity="medium">
    <xccdf:title>RHSA-2008:0680: vsftpd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux and Unix-like systems.

The version of vsftpd as shipped in Red Hat Enterprise Linux 4 when used in
combination with Pluggable Authentication Modules (PAM) had a memory leak
on an invalid authentication attempt. Since vsftpd prior to version 2.0.5
allows any number of invalid attempts on the same connection this memory
leak could lead to an eventual DoS. (CVE-2008-2375)

This update mitigates this security issue by including a backported patch
which terminates a session after a given number of failed log in attempts.
The default number of attempts is 3 and this can be configured using the
"max_login_fails" directive.

This package also addresses the following bugs:

* when uploading unique files, a bug in vsftpd caused the file to be saved
with a suffix '.1' even when no previous file with that name existed. This
issues is resolved in this package.

* when vsftpd was run through the init script, it was possible for the init
script to print an 'OK' message, even though the vsftpd may not have
started. The init script no longer produces a false verification with this
update.

* vsftpd only supported usernames with a maximum length of 32 characters.
The updated package now supports usernames up to 128 characters long.

* a system flaw meant vsftpd output could become dependent on the timing or
sequence of other events, even when the "lock_upload_files" option was set.
If a file, filename.ext, was being uploaded and a second transfer of the
file, filename.ext, was started before the first transfer was finished, the
resultant uploaded file was a corrupt concatenation of the latter upload
and the tail of the earlier upload. With this updated package, vsftpd
allows the earlier upload to complete before overwriting with the latter
upload, fixing the issue.

* the 'lock_upload_files' option was not documented in the manual page. A
new manual page describing this option is included in this package.

* vsftpd did not support usernames that started with an underscore or a
period character. These special characters are now allowed at the beginning
of a username.

* when storing a unique file, vsftpd could cause an error for some clients.
This is rectified in this package.

* vsftpd init script was found to not be Linux Standards Base compliant.
This update corrects their exit codes to conform to the standard.

All vsftpd users are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2375</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080680"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080715" severity="low">
    <xccdf:title>RHSA-2008:0715: nss_ldap security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nss_ldap package contains the nss_ldap and pam_ldap modules. The
nss_ldap module is a plug-in which allows applications to retrieve
information about users and groups from a directory server. The pam_ldap
module allows PAM-aware applications to use a directory server to verify
user passwords.

A race condition was discovered in nss_ldap, which affected certain
applications that make LDAP connections, such as Dovecot. This could cause
nss_ldap to answer a request for information about one user with the
information about a different user. (CVE-2007-5794)

As well, this updated package fixes the following bugs:

* in certain situations, on Itanium(R) architectures, when an application
performed an LDAP lookup for a highly populated group, for example,
containing more than 150 members, the application crashed, or may have
caused a segmentation fault. As well, this issue may have caused commands,
such as "ls", to return a "ber_free_buf: Assertion" error.

* when an application enumerated members of a netgroup, the nss_ldap
module returned a successful status result and the netgroup name, even
when the netgroup did not exist. This behavior was not consistent with
other modules. In this updated package, nss_ldap no longer returns a
successful status when the netgroup does not exist.

* in master and slave server environments, with systems that were
configured to use a read-only directory server, if user log in attempts
were denied because their passwords had expired, and users attempted to
immediately change their passwords, the replication server returned an LDAP
referral, instructing the pam_ldap module to resissue its request to a
different server; however, the pam_ldap module failed to do so. In these
situations, an error such as the following occurred:

LDAP password information update failed: Can't contact LDAP server
Insufficient 'write' privilege to the 'userPassword' attribute of entry
[entry]

In this updated package, password changes are allowed when binding against
a slave server, which resolves this issue.

* when a system used a directory server for naming information, and
"nss_initgroups_ignoreusers root" was configured in "/etc/ldap.conf",
dbus-daemon-1 would hang. Running the "service messagebus start" command
did not start the service, and it did not fail, which would stop the boot
process if it was not cancelled.

As well, this updated package upgrades nss_ldap to the version as shipped
with Red Hat Enterprise Linux 5.

Users of nss_ldap are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5794</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080715"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080725" severity="medium">
    <xccdf:title>RHSA-2008:0725: rdesktop security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.

An integer underflow vulnerability was discovered in the rdesktop. If an
attacker could convince a victim to connect to a malicious RDP server, the
attacker could cause the victim's rdesktop to crash or, possibly, execute
an arbitrary code. (CVE-2008-1801)

Additionally, the following bug was fixed:

A missing command line option caused rdesktop to fail when using the krdc
remote desktop utility. Using krdc to connect to a terminal server resulted
in errors such as the following:

The version of rdesktop you are using ([version]) is too old:

rdesktop [version] or greater is required. A working patch for rdesktop
[version] can be found in KDE CVS.

In this updated package, krdc successfully connects to terminal servers.

Users of rdesktop should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1801</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080725"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080768" severity="medium">
    <xccdf:title>RHSA-2008:0768: mysql security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

MySQL did not correctly check directories used as arguments for the DATA
DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated
attacker could elevate their access privileges to tables created by other
database users. Note: this attack does not work on existing tables. An
attacker can only elevate their access to another user's tables as the
tables are created. As well, the names of these created tables need to be
predicted correctly for this attack to succeed. (CVE-2008-2079)

MySQL did not require the "DROP" privilege for "RENAME TABLE" statements.
An authenticated user could use this flaw to rename arbitrary tables.
(CVE-2007-2691)

MySQL allowed an authenticated user to access a table through a previously
created MERGE table, even after the user's privileges were revoked from the
original table, which might violate intended security policy. This is
addressed by allowing the MERGE storage engine to be disabled, which can be
done by running mysqld with the "--skip-merge" option. (CVE-2006-4031)

A flaw in MySQL allowed an authenticated user to cause the MySQL daemon to
crash via crafted SQL queries. This only caused a temporary denial of
service, as the MySQL daemon is automatically restarted after the crash.
(CVE-2006-3469)

As well, these updated packages fix the following bugs:

* in the previous mysql packages, if a column name was referenced more
than once in an "ORDER BY" section of a query, a segmentation fault
occurred.

* when MySQL failed to start, the init script returned a successful (0)
exit code. When using the Red Hat Cluster Suite, this may have caused
cluster services to report a successful start, even when MySQL failed to
start. In these updated packages, the init script returns the correct exit
codes, which resolves this issue.

* it was possible to use the mysqld_safe command to specify invalid port
numbers (higher than 65536), causing invalid ports to be created, and, in
some cases, a "port number definition: unsigned short" error. In these
updated packages, when an invalid port number is specified, the default
port number is used.

* when setting "myisam_repair_threads &gt; 1", any repair set the index
cardinality to "1", regardless of the table size.

* the MySQL init script no longer runs "chmod -R" on the entire database
directory tree during every startup.

* when running "mysqldump" with the MySQL 4.0 compatibility mode option,
"--compatible=mysql40", mysqldump created dumps that omitted the
"auto_increment" field.

As well, the MySQL init script now uses more reliable methods for
determining parameters, such as the data directory location.

Note: these updated packages upgrade MySQL to version 4.1.22. For a full
list of bug fixes and enhancements, refer to the MySQL release notes:
http://dev.mysql.com/doc/refman/4.1/en/news-4-1-22.html

All mysql users are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-3469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2691</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2079</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080768"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080780" severity="low">
    <xccdf:title>RHSA-2008:0780: coreutils security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The coreutils package contains the core GNU utilities. It is the
combination of the old GNU fileutils, sh-utils, and textutils packages.

The coreutils packages were found to not use the pam_succeed_if Pluggable
Authentication Module (PAM) correctly in the configuration file for the
"su" command. Any local user could use this command to change to a locked
or expired user account if the target account's password was known to the
user running "su". These updated packages, correctly, only allow the root
user to switch to locked or expired accounts using "su". (CVE-2008-1946)

All users of coreutils are advised to upgrade to this updated package,
which resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1946</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080780"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080789" severity="medium">
    <xccdf:title>RHSA-2008:0789: dnsmasq security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dnsmasq is lightweight DNS forwarder and DHCP server. It is designed to
provide DNS and, optionally, DHCP, to a small network.

The dnsmasq DNS resolver used a fixed source UDP port. This could have made
DNS spoofing attacks easier. dnsmasq has been updated to use random UDP
source ports, helping to make DNS spoofing attacks harder. (CVE-2008-1447)

All dnsmasq users are advised to upgrade to this updated package, that
upgrades dnsmasq to version 2.45, which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080789"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080815" severity="medium">
    <xccdf:title>RHSA-2008:0815: yum-rhn-plugin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The yum-rhn-plugin provides support for yum to securely access a Red Hat
Network (RHN) server for software updates.

It was discovered that yum-rhn-plugin did not verify the SSL certificate
for all communication with a Red Hat Network server. An attacker able to
redirect the network communication between a victim and an RHN server could
use this flaw to provide malicious repository metadata. This metadata could
be used to block the victim from receiving specific security updates.
(CVE-2008-3270)

This flaw did not allow an attacker to install malicious packages. Package
signatures were verified and only packages signed with a trusted Red Hat
GPG key were installed.

Red Hat would like to thank Justin Cappos and Justin Samuel for discussing
various package update mechanism flaws which led to our discovery of this
issue.

Users of yum-rhn-plugin are advised to upgrade to this updated packages,
which resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3270</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080815"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080818" severity="medium">
    <xccdf:title>RHSA-2008:0818: hplip security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The hplip (Hewlett-Packard Linux Imaging and Printing) packages provide
drivers for Hewlett-Packard printers and multifunction peripherals.

A flaw was discovered in the hplip alert-mailing functionality. A local
attacker could elevate their privileges by using specially-crafted packets
to trigger alert mails, which are sent by the root account. (CVE-2008-2940)

A flaw was discovered in the hpssd message parser. By sending
specially-crafted packets, a local attacker could cause a denial of
service, stopping the hpssd process. (CVE-2008-2941)

Users of hplip should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0818</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2941</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080818"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080835" severity="high">
    <xccdf:title>RHSA-2008:0835: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

A numeric truncation error was found in the OpenOffice.org memory
allocator. If a carefully crafted file was opened by a victim, an attacker
could use this flaw to crash OpenOffice.org or, possibly, execute arbitrary
code. (CVE-2008-3282)

All users of openoffice.org are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080835"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080836" severity="medium">
    <xccdf:title>RHSA-2008:0836: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A denial of service flaw was found in the way libxml2 processes certain
content. If an application linked against libxml2 processes malformed XML
content, it could cause the application to stop responding. (CVE-2008-3281)

Red Hat would like to thank Andreas Solberg for responsibly disclosing this
issue.

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3281</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080836"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080839" severity="medium">
    <xccdf:title>RHSA-2008:0839: postfix security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the way Postfix dereferences symbolic links. If a local
user has write access to a mail spool directory with no root mailbox, it
may be possible for them to append arbitrary data to files that root has
write permission to. (CVE-2008-2936)

Red Hat would like to thank Sebastian Krahmer for responsibly disclosing
this issue.

All users of postfix should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2936</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080839"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080847" severity="high">
    <xccdf:title>RHSA-2008:0847: libtiff security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

Additionally, these updated packages fix the following bug:

* the libtiff packages included manual pages for the sgi2tiff and tiffsv
commands, which are not included in these packages. These extraneous manual
pages were removed.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2327</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080847"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080848" severity="high">
    <xccdf:title>RHSA-2008:0848: libtiff security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

A buffer overflow flaw was discovered in the tiff2pdf conversion program
distributed with libtiff. An attacker could create a TIFF file containing
UTF-8 characters that would, when converted to PDF format, cause tiff2pdf
to crash, or, possibly, execute arbitrary code. (CVE-2006-2193)

Additionally, these updated packages fix the following bug:

* the libtiff packages included manual pages for the sgi2tiff and tiffsv
commands, which are not included in these packages. These extraneous manual
pages were removed.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2327</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080848"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080849" severity="high">
    <xccdf:title>RHSA-2008:0849: ipsec-tools security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.

Two denial of service flaws were found in the ipsec-tools racoon daemon. It
was possible for a remote attacker to cause the racoon daemon to consume
all available memory. (CVE-2008-3651, CVE-2008-3652)

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches that resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3651</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3652</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080849"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080855" severity="high">
    <xccdf:title>RHSA-2008:0855: openssh security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. 

Last week Red Hat detected an intrusion on certain of its computer systems
and took immediate action. While the investigation into the intrusion is
on-going, our initial focus  was to review and test the distribution
channel we use with our customers, Red Hat Network (RHN) and its associated
security measures. Based on these efforts, we remain highly confident that
our systems and processes prevented the intrusion from compromising RHN or
the content distributed via RHN and accordingly believe that customers who
keep their systems updated using Red Hat Network are not at risk.  We are
issuing this alert primarily for those who may obtain Red Hat binary
packages via channels other than those of official Red Hat subscribers.

In connection with the incident, the intruder was able to sign a small
number of OpenSSH packages relating only to Red Hat Enterprise Linux 4
(i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64
architecture only).  As a precautionary measure, we are releasing an
updated version of these packages, and have published a list of the
tampered packages and how to detect them at
http://www.redhat.com/security/data/openssh-blacklist.html

To reiterate, our processes and efforts to date indicate that packages
obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are
not at risk.

These packages also fix a low severity flaw in the way ssh handles X11
cookies when creating X11 forwarding connections.  When ssh was unable to
create untrusted cookie, ssh used a trusted cookie instead, possibly
allowing the administrative user of a untrusted remote server, or untrusted
application run on the remote server, to gain unintended access to a users
local X server. (CVE-2007-4752)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0855</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3844</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080855"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080879" severity="high">
    <xccdf:title>RHSA-2008:0879: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-4067,
CVE-2008-4068)

A flaw was found in the way Firefox handles mouse click events. A web page
containing specially crafted JavaScript code could move the content window
while a mouse-button was pressed, causing any item under the pointer to be
dragged. This could, potentially, cause the user to perform an unsafe
drag-and-drop action. (CVE-2008-3837)

A flaw was found in Firefox that caused certain characters to be stripped
from JavaScript code. This flaw could allow malicious JavaScript to bypass
or evade script filters. (CVE-2008-4065)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.2. You can find a link to the Mozilla
advisories in the References section.

All firefox users should upgrade to this updated package, which contains
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0879</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4068</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080879"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080882" severity="high">
    <xccdf:title>RHSA-2008:0882: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061,
CVE-2008-4062)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-3835,
CVE-2008-4067, CVE-2008-4068, CVE-2008-4069)

A flaw was found in the way SeaMonkey handles mouse click events. A web page
containing specially crafted JavaScript code could move the content window
while a mouse-button was pressed, causing any item under the pointer to be
dragged. This could, potentially, cause the user to perform an unsafe
drag-and-drop action. (CVE-2008-3837)

A flaw was found in SeaMonkey that caused certain characters to be stripped
from JavaScript code. This flaw could allow malicious JavaScript to bypass
or evade script filters. (CVE-2008-4065, CVE-2008-4066)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4069</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080882"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080884" severity="high">
    <xccdf:title>RHSA-2008:0884: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A heap-based buffer overflow flaw was found in the way libxml2 handled long
XML entity names. If an application linked against libxml2 processed
untrusted malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-3529)

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3529</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080884"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080885" severity="high">
    <xccdf:title>RHSA-2008:0885: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a missing capability check was found in the Linux kernel do_change_type
routine. This could allow a local unprivileged user to gain privileged
access or cause a denial of service. (CVE-2008-2931, Important)

* a flaw was found in the Linux kernel Direct-IO implementation. This could
allow a local unprivileged user to cause a denial of service.
(CVE-2007-6716, Important)

* Tobias Klein reported a missing check in the Linux kernel Open Sound
System (OSS) implementation. This deficiency could lead to a possible
information leak. (CVE-2008-3272, Moderate)

* a deficiency was found in the Linux kernel virtual filesystem (VFS)
implementation. This could allow a local unprivileged user to attempt file
creation within deleted directories, possibly causing a denial of service.
(CVE-2008-3275, Moderate)

* a flaw was found in the Linux kernel tmpfs implementation. This could
allow a local unprivileged user to read sensitive information from the
kernel. (CVE-2007-6417, Moderate)

Bug fixes:

* when copying a small IPoIB packet from the original skb it was received
in to a new, smaller skb, all fields in the new skb were not initialized.
This may have caused a kernel oops.

* previously, data may have been written beyond the end of an array,
causing memory corruption on certain systems, resulting in hypervisor
crashes during context switching.

* a kernel crash may have occurred on heavily-used Samba servers after 24
to 48 hours of use.

* under heavy memory pressure, pages may have been swapped out from under
the SGI Altix XPMEM driver, causing silent data corruption in the kernel.

* the ixgbe driver is untested, but support was advertised for the Intel
82598 network card. If this card was present when the ixgbe driver was
loaded, a NULL pointer dereference and a panic occurred.

* on certain systems, if multiple InfiniBand queue pairs simultaneously
fell into an error state, an overrun may have occurred, stopping traffic.

* with bridging, when forward delay was set to zero, setting an interface
to the forwarding state was delayed by one or possibly two timers,
depending on whether STP was enabled. This may have caused long delays in
moving an interface to the forwarding state. This issue caused packet loss
when migrating virtual machines, preventing them from being migrated
without interrupting applications.

* on certain multinode systems, IPMI device nodes were created in reverse
order of where they physically resided.

* process hangs may have occurred while accessing application data files
via asynchronous direct I/O system calls.

* on systems with heavy lock traffic, a possible deadlock may have caused
anything requiring locks over NFS to stop, or be very slow. Errors such as
"lockd: server [IP] not responding, timed out" were logged on client
systems.

* unexpected removals of USB devices may have caused a NULL pointer
dereference in kobject_get_path.

* on Itanium-based systems, repeatedly creating and destroying Windows
guests may have caused Dom0 to crash, due to the "XENMEM_add_to_physmap"
hypercall, used by para-virtualized drivers on HVM, being SMP-unsafe.

* when using an MD software RAID, crashes may have occurred when devices
were removed or changed while being iterated through. Correct locking is
now used.

* break requests had no effect when using "Serial Over Lan" with the Intel
82571 network card. This issue may have caused log in problems.

* on Itanium-based systems, module_free() referred the first parameter
before checking it was valid. This may have caused a kernel panic when
exiting SystemTap.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2931</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3275</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080885"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080890" severity="medium">
    <xccdf:title>RHSA-2008:0890: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network, it could crash or, possibly, execute
arbitrary code as the user running Wireshark. (CVE-2008-3146)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malformed dump file. (CVE-2008-1070, CVE-2008-1071, CVE-2008-1072,
CVE-2008-1561, CVE-2008-1562, CVE-2008-1563, CVE-2008-3137, CVE-2008-3138,
CVE-2008-3141, CVE-2008-3145, CVE-2008-3932, CVE-2008-3933, CVE-2008-3934)

Additionally, this update changes the default Pluggable Authentication
Modules (PAM) configuration to always prompt for the root password before
each start of Wireshark. This avoids unintentionally running Wireshark with
root privileges.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.3, and resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3932</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3934</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080890"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080892" severity="high">
    <xccdf:title>RHSA-2008:0892: xen security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain tools for managing the virtual machine monitor in
Red Hat Virtualization.

It was discovered that the hypervisor's para-virtualized framebuffer (PVFB)
backend failed to validate the frontend's framebuffer description properly.
This could allow a privileged user in the unprivileged domain (DomU) to
cause a denial of service, or, possibly, elevate privileges to the
privileged domain (Dom0). (CVE-2008-1952)

A flaw was found in the QEMU block format auto-detection, when running
fully-virtualized guests and using Qemu images written on removable media
(USB storage, 3.5" disks). Privileged users of such fully-virtualized
guests (DomU), with a raw-formatted disk image, were able to write a header
to that disk image describing another format. This could allow such guests
to read arbitrary files in their hypervisor's host (Dom0). (CVE-2008-1945)

Additionally, the following bug is addressed in this update:

* The qcow-create command terminated when invoked due to glibc bounds
checking on the realpath() function.

Users of xen are advised to upgrade to these updated packages, which
resolve these security issues and fix this bug.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0892</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1945</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1952</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080892"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080893" severity="medium">
    <xccdf:title>RHSA-2008:0893: bzip2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Bzip2 is a freely available, high-quality data compressor. It provides both
stand-alone compression and decompression utilities, as well as a shared
library for use with other programs.

A buffer over-read flaw was discovered in the bzip2 decompression routine.
This issue could cause an application linked against the libbz2 library to
crash when decompressing malformed archives. (CVE-2008-1372)

Users of bzip2 should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1372</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080893"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080897" severity="medium">
    <xccdf:title>RHSA-2008:0897: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

The Ruby DNS resolver library, resolv.rb, used predictable transaction IDs
and a fixed source port when sending DNS requests. A remote attacker could
use this flaw to spoof a malicious reply to a DNS query. (CVE-2008-3905)

Ruby's XML document parsing module (REXML) was prone to a denial of service
attack via XML documents with large XML entity definitions recursion. A
specially-crafted XML file could cause a Ruby application using the REXML
module to use an excessive amount of CPU and memory. (CVE-2008-3790)

An insufficient "taintness" check flaw was discovered in Ruby's DL module,
which provides direct access to the C language functions. An attacker could
use this flaw to bypass intended safe-level restrictions by calling
external C functions with the arguments from an untrusted tainted inputs.
(CVE-2008-3657)

A denial of service flaw was discovered in WEBrick, Ruby's HTTP server
toolkit. A remote attacker could send a specially-crafted HTTP request to a
WEBrick server that would cause the server to use an excessive amount of
CPU time. (CVE-2008-3656)

A number of flaws were found in the safe-level restrictions in Ruby. It
was possible for an attacker to create a carefully crafted malicious script
that can allow the bypass of certain safe-level restrictions. (CVE-2008-3655)

A denial of service flaw was found in Ruby's regular expression engine. If
a Ruby script tried to process a large amount of data via a regular
expression, it could cause Ruby to enter an infinite-loop and crash.
(CVE-2008-3443)

Users of ruby should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0897</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3905</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080897"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080907" severity="medium">
    <xccdf:title>RHSA-2008:0907: pam_krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware
applications to use Kerberos to verify user identities by obtaining user
credentials at log in time.

A flaw was found in the pam_krb5 "existing_ticket" configuration option. If
a system is configured to use an existing credential cache via the
"existing_ticket" option, it may be possible for a local user to gain
elevated privileges by using a different, local user's credential cache.
(CVE-2008-3825)

Red Hat would like to thank Stéphane Bertin for responsibly disclosing this
issue.

Users of pam_krb5 should upgrade to this updated package, which contains a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3825</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080907"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080908" severity="medium">
    <xccdf:title>RHSA-2008:0908: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060,
CVE-2008-4061, CVE-2008-4062)

Several flaws were found in the way malformed HTML mail content was
displayed. An HTML mail message containing specially crafted content could
potentially trick a Thunderbird user into surrendering sensitive
information. (CVE-2008-3835, CVE-2008-4067, CVE-2008-4068)

A flaw was found in Thunderbird that caused certain characters to be
stripped from JavaScript code. This flaw could allow malicious JavaScript
to bypass or evade script filters. (CVE-2008-4065, CVE-2008-4066)

Note: JavaScript support is disabled by default in Thunderbird; the above
issue is not exploitable unless JavaScript is enabled.

A heap based buffer overflow flaw was found in the handling of cancelled
newsgroup messages. If the user cancels a specially crafted newsgroup
message it could cause Thunderbird to crash or, potentially, execute
arbitrary code as the user running Thunderbird. (CVE-2008-4070)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4070</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080908"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080937" severity="high">
    <xccdf:title>RHSA-2008:0937: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A buffer overflow flaw was discovered in the SGI image format decoding
routines used by the CUPS image converting filter "imagetops". An attacker
could create a malicious SGI image file that could, possibly, execute
arbitrary code as the "lp" user if the file was printed. (CVE-2008-3639)

An integer overflow flaw leading to a heap buffer overflow was discovered
in the Text-to-PostScript "texttops" filter. An attacker could create a
malicious text file that could, possibly, execute arbitrary code as the
"lp" user if the file was printed. (CVE-2008-3640)

An insufficient buffer bounds checking flaw was discovered in the
HP-GL/2-to-PostScript "hpgltops" filter. An attacker could create a
malicious HP-GL/2 file that could, possibly, execute arbitrary code as the
"lp" user if the file was printed. (CVE-2008-3641)

Red Hat would like to thank regenrecht for reporting these issues.

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3639</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3641</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080937"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080939" severity="high">
    <xccdf:title>RHSA-2008:0939: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

SureRun Security Team discovered an integer overflow flaw leading to a heap
buffer overflow in the Windows Metafile (WMF) image format parser. An
attacker could create a carefully crafted document containing a malicious
WMF file that could cause OpenOffice.org to crash, or, possibly, execute
arbitrary code if opened by a victim. (CVE-2008-2237)

Multiple integer overflow flaws were found in the Enhanced Windows Metafile
(EMF) parser. An attacker could create a carefully crafted document
containing a malicious EMF file that could cause OpenOffice.org to crash,
or, possibly, execute arbitrary code if opened by a victim. (CVE-2008-2238)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2238</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080939"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080946" severity="medium">
    <xccdf:title>RHSA-2008:0946: ed security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ed is a line-oriented text editor, used to create, display, and modify
text files (both interactively and via shell scripts).

A heap-based buffer overflow was discovered in the way ed, the GNU line
editor, processed long file names. An attacker could create a file with a
specially-crafted name that could possibly execute an arbitrary code when
opened in the ed editor. (CVE-2008-3916)

Users of ed should upgrade to this updated package, which contains
a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0946</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3916</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080946"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080957" severity="high">
    <xccdf:title>RHSA-2008:0957: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* the Xen implementation did not prevent applications running in a
para-virtualized guest from modifying CR4 TSC. This could cause a local
denial of service. (CVE-2007-5907, Important)

* Tavis Ormandy reported missing boundary checks in the Virtual Dynamic
Shared Objects (vDSO) implementation. This could allow a local unprivileged
user to cause a denial of service or escalate privileges. (CVE-2008-3527,
Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could allow a local unprivileged user to
obtain access to privileged information. (CVE-2008-4210, CVE-2008-3833,
Important)

* a flaw was found in the Linux kernel splice implementation. This could
cause a local denial of service when there is a certain failure in the
add_to_page_cache_lru() function. (CVE-2008-4302, Important)

* a flaw was found in the Linux kernel when running on AMD64 systems.
During a context switch, EFLAGS were being neither saved nor restored. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2006-5755, Low)

* a flaw was found in the Linux kernel virtual memory implementation. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2008-2372, Low)

* an integer overflow was discovered in the Linux kernel Datagram
Congestion Control Protocol (DCCP) implementation. This could allow a
remote attacker to cause a denial of service. By default, remote DCCP is
blocked by SELinux. (CVE-2008-3276, Low)

In addition, these updated packages fix the following bugs:

* random32() seeding has been improved. 

* in a multi-core environment, a race between the QP async event-handler
and the destro_qp() function could occur. This led to unpredictable results
during invalid memory access, which could lead to a kernel crash.

* a format string was omitted in the call to the request_module() function.

* a stack overflow caused by an infinite recursion bug in the binfmt_misc
kernel module was corrected.

* the ata_scsi_rbuf_get() and ata_scsi_rbuf_put() functions now check for
scatterlist usage before calling kmap_atomic().

* a sentinel NUL byte was added to the device_write() function to ensure
that lspace.name is NUL-terminated.

* in the character device driver, a range_is_allowed() check was added to
the read_mem() and write_mem() functions. It was possible for an
illegitimate application to bypass these checks, and access /dev/mem beyond
the 1M limit by calling mmap_mem() instead. Also, the parameters of
range_is_allowed() were changed to cleanly handle greater than 32-bits of
physical address on 32-bit architectures.

* some of the newer Nehalem-based systems declare their CPU DSDT entries as
type "Alias". During boot, this caused an "Error attaching device data"
message to be logged.

* the evtchn event channel device lacked locks and memory barriers. This
has led to xenstore becoming unresponsive on the Itanium® architecture.

* sending of gratuitous ARP packets in the Xen frontend network driver is
now delayed until the backend signals that its carrier status has been
processed by the stack.

* on forcedeth devices, whenever setting ethtool parameters for link speed,
the device could stop receiving interrupts.

* the CIFS 'forcedirectio' option did not allow text to be appended to files.

* the gettimeofday() function returned a backwards time on Intel® 64.

* residual-count corrections during UNDERRUN handling were added to the
qla2xxx driver.                                                   

* the fix for a small quirk was removed for certain Adaptec controllers for
which it caused problems.

* the "xm trigger init" command caused a domain panic if a userland
application was running on a guest on the Intel® 64 architecture.

Users of kernel should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-5755</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3276</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4302</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080957"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080965" severity="high">
    <xccdf:title>RHSA-2008:0965: lynx security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Lynx is a text-based Web browser.

An arbitrary command execution flaw was found in the Lynx "lynxcgi:" URI
handler. An attacker could create a web page redirecting to a malicious URL
that could execute arbitrary code as the user running Lynx in the
non-default "Advanced" user mode. (CVE-2008-4690)

Note: In these updated lynx packages, Lynx will always prompt users before
loading a "lynxcgi:" URI. Additionally, the default lynx.cfg configuration
file now marks all "lynxcgi:" URIs as untrusted by default.

A flaw was found in a way Lynx handled ".mailcap" and ".mime.types"
configuration files. Files in the browser's current working directory were
opened before those in the user's home directory. A local attacker, able to
convince a user to run Lynx in a directory under their control, could
possibly execute arbitrary commands as the user running Lynx. (CVE-2006-7234)

All users of Lynx are advised to upgrade to this updated package, which
contains backported patches correcting these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0965</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4690</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080965"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080967" severity="medium">
    <xccdf:title>RHSA-2008:0967: httpd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_proxy Apache module. An attacker in control of
a Web server to which requests were being proxied could have caused a
limited denial of service due to CPU consumption and stack exhaustion.
(CVE-2008-2364)

A flaw was found in the mod_proxy_ftp Apache module. If Apache was
configured to support FTP-over-HTTP proxying, a remote attacker could have
performed a cross-site scripting attack. (CVE-2008-2939)

In addition, these updated packages fix a bug found in the handling of the
"ProxyRemoteMatch" directive in the Red Hat Enterprise Linux 4 httpd
packages. This bug is not present in the Red Hat Enterprise Linux 3 or Red
Hat Enterprise Linux 5 packages.

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0967</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2939</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080967"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080971" severity="high">
    <xccdf:title>RHSA-2008:0971: net-snmp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

A denial-of-service flaw was found in the way Net-SNMP processes SNMP
GETBULK requests. A remote attacker who issued a specially-crafted request
could cause the snmpd server to crash. (CVE-2008-4309)

Note: An attacker must have read access to the SNMP server in order to
exploit this flaw. In the default configuration, the community name
"public" grants read-only access. In production deployments, it is
recommended to change this default community name.

All users of net-snmp should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0971</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4309</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080971"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080972" severity="high">
    <xccdf:title>RHSA-2008:0972: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* a flaw was found in the Linux kernel's Direct-IO implementation. This
could have allowed a local unprivileged user to cause a denial of service.
(CVE-2007-6716, Important)

* when running ptrace in 31-bit mode on an IBM S/390 or IBM System z
kernel, a local unprivileged user could cause a denial of service by
reading from or writing into a padding area in the user_regs_struct32
structure. (CVE-2008-1514, Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could have allowed a local unprivileged
user to obtain access to privileged information. (CVE-2008-4210, Important)

* Tobias Klein reported a missing check in the Linux kernel's Open Sound
System (OSS) implementation. This deficiency could have led to an
information leak. (CVE-2008-3272, Moderate)

* a potential denial of service attack was discovered in the Linux kernel's
PWC USB video driver. A local unprivileged user could have used this flaw
to bring the kernel USB subsystem into the busy-waiting state.
(CVE-2007-5093, Low)

* the ext2 and ext3 file systems code failed to properly handle corrupted
data structures, leading to a possible local denial of service issue when
read or write operations were performed. (CVE-2008-3528, Low)

In addition, these updated packages fix the following bugs:

* when using the CIFS "forcedirectio" option, appending to an open file on
a CIFS share resulted in that file being overwritten with the data to be
appended.

* a kernel panic occurred when a device with PCI ID 8086:10c8 was present
on a system with a loaded ixgbe driver.

* due to an aacraid driver regression, the kernel failed to boot when trying
to load the aacraid driver and printed the following error message:
"aac_srb: aac_fib_send failed with status: 8195".

* due to an mpt driver regression, when RAID 1 was configured on Primergy
systems with an LSI SCSI IME 53C1020/1030 controller, the kernel panicked
during boot.

* the mpt driver produced a large number of extraneous debugging messages
when performing a "Host reset" operation.

* due to a regression in the sym driver, the kernel panicked when a SCSI
hot swap was performed using MCP18 hardware.

* all cores on a multi-core system now scale their frequencies in
accordance with the policy set by the system's CPU frequency governor.

* the netdump subsystem suffered from several stability issues. These are
addressed in this updated kernel.

* under certain conditions, the ext3 file system reported a negative count
of used blocks.

* reading /proc/self/mem incorrectly returned "Invalid argument" instead of
"input/output error" due to a regression.

* under certain conditions, the kernel panicked when a USB device was
removed while the system was busy accessing the device.

* a race condition in the kernel could have led to a kernel crash during
the creation of a new process.

All Red Hat Enterprise Linux 4 Users should upgrade to these updated
packages, which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0972</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1514</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4210</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080972"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080976" severity="medium">
    <xccdf:title>RHSA-2008:0976: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5014, CVE-2008-5016, CVE-2008-5017, CVE-2008-5018,
CVE-2008-5021)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing specially-crafted content could
potentially trick a Thunderbird user into surrendering sensitive
information. (CVE-2008-5012, CVE-2008-5022, CVE-2008-5024)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5052</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080976"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080977" severity="high">
    <xccdf:title>RHSA-2008:0977: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-0017, CVE-2008-5013, CVE-2008-5014, CVE-2008-5016,
CVE-2008-5017, CVE-2008-5018, CVE-2008-5019, CVE-2008-5021)

Several flaws were found in the way malformed content was processed. A web
site containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-5012,
CVE-2008-5022, CVE-2008-5023, CVE-2008-5024)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0977</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5052</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080977"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080978" severity="high">
    <xccdf:title>RHSA-2008:0978: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-0017, CVE-2008-5014, CVE-2008-5016, CVE-2008-5017,
CVE-2008-5018, CVE-2008-5019, CVE-2008-5021)

Several flaws were found in the way malformed content was processed. A web
site containing specially-crafted content could potentially trick a Firefox
user into surrendering sensitive information. (CVE-2008-5022,
CVE-2008-5023, CVE-2008-5024)

A flaw was found in the way Firefox opened "file:" URIs. If a file: URI was
loaded in the same tab as a chrome or privileged "about:" page, the file:
URI could execute arbitrary code with the permissions of the user running
Firefox. (CVE-2008-5015)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.4. You can find a link to the Mozilla
advisories in the References section.

All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0978</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5052</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080978"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080981" severity="medium">
    <xccdf:title>RHSA-2008:0981: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

Vincent Danen reported, that Red Hat Security Advisory RHSA-2008:0897
did not properly address a denial of service flaw in the WEBrick (Ruby
HTTP server toolkit), known as CVE-2008-3656. This flaw allowed a
remote attacker to send a specially-crafted HTTP request to a WEBrick
server that would cause the server to use excessive CPU time. This
update properly addresses this flaw. (CVE-2008-4310)

All Ruby users should upgrade to these updated packages, which contain a
correct patch that resolves this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4310</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080982" severity="medium">
    <xccdf:title>RHSA-2008:0982: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). 

Martin von Gagern discovered a flaw in the way GnuTLS verified certificate
chains provided by a server. A malicious server could use this flaw to
spoof its identity by tricking client applications using the GnuTLS library
to trust invalid certificates. (CVE-2008-4989)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4989</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080982"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20080988" severity="high">
    <xccdf:title>RHSA-2008:0988: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libxml2 is a library for parsing and manipulating XML files. It includes
support for reading, modifying, and writing XML and HTML files.

An integer overflow flaw causing a heap-based buffer overflow was found in
the libxml2 XML parser. If an application linked against libxml2 processed
untrusted, malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-4226)

A denial of service flaw was discovered in the libxml2 XML parser. If an
application linked against libxml2 processed untrusted, malformed XML
content, it could cause the application to enter an infinite loop.
(CVE-2008-4225)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.

Users of libxml2 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:0988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4225</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4226</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20080988"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081001" severity="high">
    <xccdf:title>RHSA-2008:1001: tog-pegasus security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The tog-pegasus packages provide OpenPegasus Web-Based Enterprise
Management (WBEM) services. WBEM is a platform and resource independent
Distributed Management Task Force (DMTF) standard that defines a common
information model and communication protocol for monitoring and controlling
resources.

Red Hat defines additional security enhancements for OpenGroup Pegasus WBEM
services in addition to those defined by the upstream OpenGroup Pegasus
release. For details regarding these enhancements, refer to the file
"README.RedHat.Security", included in the Red Hat tog-pegasus package.

After re-basing to version 2.7.0 of the OpenGroup Pegasus code, these
additional security enhancements were no longer being applied. As a
consequence, access to OpenPegasus WBEM services was not restricted to the
dedicated users as described in README.RedHat.Security. An attacker able to
authenticate using a valid user account could use this flaw to send
requests to WBEM services. (CVE-2008-4313)

Note: default SELinux policy prevents tog-pegasus from modifying system
files. This flaw's impact depends on whether or not tog-pegasus is confined
by SELinux, and on any additional CMPI providers installed and enabled on a
particular system.

Failed authentication attempts against the OpenPegasus CIM server were not
logged to the system log as documented in README.RedHat.Security. An
attacker could use this flaw to perform password guessing attacks against a
user account without leaving traces in the system log. (CVE-2008-4315)

All tog-pegasus users are advised to upgrade to these updated packages,
which contain patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4315</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081001"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081016" severity="medium">
    <xccdf:title>RHSA-2008:1016: enscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU enscript converts ASCII files to PostScript(R) language files and
spools the generated output to a specified printer or saves it to a file.
Enscript can be extended to handle different output media and includes
options for customizing printouts.

Two buffer overflow flaws were found in GNU enscript. An attacker could
craft an ASCII file in such a way that it could execute arbitrary commands
if the file was opened with enscript with the "special escapes" option (-e
or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306)

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4306</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081017" severity="high">
    <xccdf:title>RHSA-2008:1017: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* Olaf Kirch reported a flaw in the i915 kernel driver. This flaw could,
potentially, lead to local privilege escalation. Note: the flaw only
affects systems based on the Intel G33 Express Chipset and newer.
(CVE-2008-3831, Important)

* Miklos Szeredi reported a missing check for files opened with O_APPEND in
the sys_splice(). This could allow a local, unprivileged user to bypass the
append-only file restrictions. (CVE-2008-4554, Important)

* a deficiency was found in the Linux kernel Stream Control Transmission
Protocol (SCTP) implementation. This could lead to a possible denial of
service if one end of a SCTP connection did not support the AUTH extension.
(CVE-2008-4576, Important)

In addition, these updated packages fix the following bugs:

* on Itanium® systems, when a multithreaded program was traced using the
command "strace -f", messages such as
 
   PANIC: attached pid 10740 exited 
   PANIC: handle_group_exit: 10740 leader 10721
   ...

will be displayed, and after which the trace would stop.  With these
updated packages, "strace -f" command no longer results in these error
messages, and strace terminates normally after tracing all threads.

* on big-endian systems such as PowerPC, the getsockopt() function
incorrectly returned 0 depending on the parameters passed to it when the
time to live (TTL) value equaled 255.

* when using an NFSv4 file system, accessing the same file with two
separate processes simultaneously resulted in the NFS client process
becoming unresponsive.

* on AMD64 and Intel® 64 hypervisor-enabled systems, when a syscall
correctly returned '-1' in code compiled on Red Hat Enterprise Linux 5, the
same code, when run with the strace utility, would incorrectly return an
invalid return value. This has been fixed: on AMD64 and Intel® 64
hypervisor-enabled systems, syscalls in compiled code return the same,
correct values as syscalls run with strace.

* on the Itanium® architecture, fully-virtualized guest domains created
using more than 64 GB of memory caused other guest domains not to receive
interrupts. This caused soft lockups on other guests. All guest domains are
now able to receive interrupts regardless of their allotted memory.

* when user-space used SIGIO notification, which was not disabled before
closing a file descriptor and was then re-enabled in a different process,
an attempt by the kernel to dereference a stale pointer led to a kernel
crash. With this fix, such a situation no longer causes a kernel crash.

* modifications to certain pages made through a memory-mapped region could
have been lost in cases when the NFS client needed to invalidate the page
cache for that particular memory-mapped file.

* fully-virtualized Windows® guests became unresponsive due to the vIOSAPIC
component being multiprocessor-unsafe. With this fix, vIOSAPIC is
multiprocessor-safe and Windows guests do not become unresponsive.

* on certain systems, keyboard controllers could not withstand continuous
requests to switch keyboard LEDs on or off. This resulted in some or all
key presses not being registered by the system.

* on the Itanium® architecture, setting the "vm.nr_hugepages" sysctl
parameter caused a kernel stack overflow resulting in a kernel panic, and
possibly stack corruption. With this fix, setting vm.nr_hugepages works
correctly.

* hugepages allow the Linux kernel to utilize the multiple page size
capabilities of modern hardware architectures. In certain configurations,
systems with large amounts of memory could fail to allocate most of this
memory for hugepages even if it was free. This could result, for example,
in database restart failures.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4576</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081017"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081021" severity="medium">
    <xccdf:title>RHSA-2008:1021: enscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU enscript converts ASCII files to PostScript(R) language files and
spools the generated output to a specified printer or saves it to a file.
Enscript can be extended to handle different output media and includes
options for customizing printouts.

Several buffer overflow flaws were found in GNU enscript. An attacker could
craft an ASCII file in such a way that it could execute arbitrary commands
if the file was opened with enscript with the "special escapes" option (-e
or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306, CVE-2008-5078)

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5078</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081021"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081023" severity="medium">
    <xccdf:title>RHSA-2008:1023: pidgin security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is a multi-protocol Internet Messaging client.

A denial-of-service flaw was found in Pidgin's MSN protocol handler. If a
remote user was able to send, and the Pidgin user accepted, a
carefully-crafted file request, it could result in Pidgin crashing.
(CVE-2008-2955)

A denial-of-service flaw was found in Pidgin's Universal Plug and Play
(UPnP) request handling. A malicious UPnP server could send a request to
Pidgin, causing it to download an excessive amount of data, consuming all
available memory or disk space. (CVE-2008-2957)

A flaw was found in the way Pidgin handled SSL certificates. The NSS SSL
implementation in Pidgin did not properly verify the authenticity of SSL
certificates. This could have resulted in users unknowingly connecting to a
malicious SSL service. (CVE-2008-3532)

In addition, this update upgrades pidgin from version 2.3.1 to version
2.5.2, with many additional stability and functionality fixes from the
Pidgin Project.

Note: the Secure Internet Live Conferencing (SILC) chat network protocol
has recently changed, affecting all versions of pidgin shipped with Red Hat
Enterprise Linux.

Pidgin cannot currently connect to the latest version of the SILC server
(1.1.14): it fails to properly exchange keys during initial login. This
update does not correct this. Red Hat Bugzilla #474212 (linked to in the
References section) has more information.

Note: after the errata packages are installed, Pidgin must be restarted for
the update to take effect.

All Pidgin users should upgrade to these updated packages, which contains
Pidgin version 2.5.2 and resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3532</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081023"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081029" severity="medium">
    <xccdf:title>RHSA-2008:1029: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A null pointer dereference flaw was found in the way CUPS handled
subscriptions for printing job completion notifications. A local user could
use this flaw to crash the CUPS daemon by submitting a large number of
printing jobs requiring mail notification on completion, leading to a
denial of service. (CVE-2008-5183)

Users of cups should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081029"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081036" severity="high">
    <xccdf:title>RHSA-2008:1036: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511, CVE-2008-5512,
CVE-2008-5513)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-5506,
CVE-2008-5507)

A flaw was found in the way Firefox stored attributes in XML User Interface
Language (XUL) elements. A web site could use this flaw to track users
across browser sessions, even if users did not allow the site to store
cookies in the victim's browser. (CVE-2008-5505)

A flaw was found in the way malformed URLs were processed by Firefox.
This flaw could prevent various URL sanitization mechanisms from properly
parsing a malicious URL. (CVE-2008-5508)

A flaw was found in Firefox's CSS parser. A malicious web page could inject
NULL characters into a CSS input string, possibly bypassing an
application's script sanitization routines. (CVE-2008-5510)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.5. You can find a link to the Mozilla
advisories in the References section.

Note: after the errata packages are installed, Firefox must be restarted
for the update to take effect.

All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1036</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081036"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20081037" severity="high">
    <xccdf:title>RHSA-2008:1037: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5504, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-5503,
CVE-2008-5506, CVE-2008-5507)

A flaw was found in the way malformed URLs were processed by SeaMonkey.
This flaw could prevent various URL sanitization mechanisms from properly
parsing a malicious URL. (CVE-2008-5508)

Note: after the errata packages are installed, SeaMonkey must be restarted
for the update to take effect.

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2008:1037</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20081037"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090002" severity="medium">
    <xccdf:title>RHSA-2009:0002: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)

Several flaws were found in the way malformed content was processed. An
HTML mail message containing specially-crafted content could potentially
trick a Thunderbird user into surrendering sensitive information.
(CVE-2008-5503, CVE-2008-5506, CVE-2008-5507)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the way malformed URLs were processed by
Thunderbird. This flaw could prevent various URL sanitization mechanisms
from properly parsing a malicious URL. (CVE-2008-5508)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090002"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090003" severity="medium">
    <xccdf:title>RHSA-2009:0003: xen security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain the Xen tools and management daemons needed to
manage virtual machines running on Red Hat Enterprise Linux.

Xen was found to allow unprivileged DomU domains to overwrite xenstore
values which should only be changeable by the privileged Dom0 domain. An
attacker controlling a DomU domain could, potentially, use this flaw to
kill arbitrary processes in Dom0 or trick a Dom0 user into accessing the
text console of a different domain running on the same host. This update
makes certain parts of the xenstore tree read-only to the unprivileged DomU
domains. (CVE-2008-4405)

It was discovered that the qemu-dm.debug script created a temporary file in
/tmp in an insecure way. A local attacker in Dom0 could, potentially, use
this flaw to overwrite arbitrary files via a symlink attack. Note: This
script is not needed in production deployments and therefore was removed
and is not shipped with updated xen packages. (CVE-2008-4993)

This update also fixes the following bug:

* xen calculates its running time by adding the hypervisor's up-time to the
hypervisor's boot-time record. In live migrations of para-virtualized
guests, however, the guest would over-write the new hypervisor's boot-time
record with the boot-time of the previous hypervisor. This caused
time-dependent processes on the guests to fail (for example, crond would
fail to start cron jobs). With this update, the new hypervisor's boot-time
record is no longer over-written during live migrations.

All xen users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The Xen host must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4405</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4993</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090004" severity="high">
    <xccdf:title>RHSA-2009:0004: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength,
general purpose, cryptography library.

The Google security team discovered a flaw in the way OpenSSL checked the
verification of certificates. An attacker in control of a malicious server,
or able to effect a "man in the middle" attack, could present a malformed
SSL/TLS signature from a certificate chain to a vulnerable client and
bypass validation. (CVE-2008-5077)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all running OpenSSL client applications must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5077</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090004"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090005" severity="medium">
    <xccdf:title>RHSA-2009:0005: gnome-vfs, gnome-vfs2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNOME VFS is the GNOME virtual file system. It provides a modular
architecture and ships with several modules that implement support for
various local and remote file systems as well as numerous protocols,
including HTTP, FTP, and others.

A buffer overflow flaw was discovered in the GNOME virtual file system when
handling data returned by CDDB servers. If a user connected to a malicious
CDDB server, an attacker could use this flaw to execute arbitrary code on
the victim's machine. (CVE-2005-0706)

Users of gnome-vfs and gnome-vfs2 are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. All
running GNOME sessions must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-0706</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090005"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090008" severity="medium">
    <xccdf:title>RHSA-2009:0008: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial-of-service flaw was discovered in the system for sending messages
between applications. A local user could send a message with a malformed
signature to the bus causing the bus (and, consequently, any process using
libdbus to receive messages) to abort. (CVE-2008-3834)

All users are advised to upgrade to these updated dbus packages, which
contain backported patch which resolve this issue. For the update to take
effect, all running instances of dbus-daemon and all running applications
using libdbus library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3834</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090010" severity="medium">
    <xccdf:title>RHSA-2009:0010: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

Ivan Markovic discovered a cross-site scripting (XSS) flaw in SquirrelMail
caused by insufficient HTML mail sanitization. A remote attacker could send
a specially-crafted HTML mail or attachment that could cause a user's Web
browser to execute a malicious script in the context of the SquirrelMail
session when that email or attachment was opened by the user.
(CVE-2008-2379)

It was discovered that SquirrelMail allowed cookies over insecure
connections (ie did not restrict cookies to HTTPS connections). An attacker
who controlled the communication channel between a user and the
SquirrelMail server, or who was able to sniff the user's network
communication, could use this flaw to obtain the user's session cookie, if
a user made an HTTP request to the server. (CVE-2008-3663)

Note: After applying this update, all session cookies set for SquirrelMail
sessions started over HTTPS connections will have the "secure" flag set.
That is, browsers will only send such cookies over an HTTPS connection. If
needed, you can revert to the previous behavior by setting the
configuration option "$only_secure_cookies" to "false" in SquirrelMail's
/etc/squirrelmail/config.php configuration file.

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3663</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090010"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090011" severity="medium">
    <xccdf:title>RHSA-2009:0011: lcms security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple insufficient input validation flaws were discovered in LittleCMS.
An attacker could use these flaws to create a specially-crafted image file
which could cause an application using LittleCMS to crash, or, possibly,
execute arbitrary code when opened. (CVE-2008-5316, CVE-2008-5317)

Users of lcms should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
lcms library must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5316</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5317</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090011"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090012" severity="medium">
    <xccdf:title>RHSA-2009:0012: netpbm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps), and others.

An input validation flaw and multiple integer overflows were discovered in
the JasPer library providing support for JPEG-2000 image format and used in
the jpeg2ktopam and pamtojpeg2k converters. An attacker could create a
carefully-crafted JPEG file which could cause jpeg2ktopam to crash or,
possibly, execute arbitrary code as the user running jpeg2ktopam.
(CVE-2007-2721, CVE-2008-3520)

All users are advised to upgrade to these updated packages which contain
backported patches which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3520</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090012"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090013" severity="medium">
    <xccdf:title>RHSA-2009:0013: avahi security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zeroconf Networking. It facilitates service discovery on
a local network. Avahi and Avahi-aware applications allow you to plug your
computer into a network and, with no configuration, view other people to
chat with, see printers to print to, and find shared files on other computers.

Hugo Dias discovered a denial of service flaw in avahi-daemon. A remote
attacker on the same local area network (LAN) could send a
specially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemon
to exit unexpectedly due to a failed assertion check. (CVE-2008-5081)

All users are advised to upgrade to these updated packages, which contain a
backported patch which resolves this issue. After installing the update,
avahi-daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5081</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090013"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090014" severity="high">
    <xccdf:title>RHSA-2009:0014: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* the sendmsg() function in the Linux kernel did not block during UNIX
socket garbage collection. This could, potentially, lead to a local denial
of service. (CVE-2008-5300, Important)

* when fput() was called to close a socket, the __scm_destroy() function in
the Linux kernel could make indirect recursive calls to itself. This could,
potentially, lead to a local denial of service. (CVE-2008-5029, Important)

* a deficiency was found in the Linux kernel virtual file system (VFS)
implementation. This could allow a local, unprivileged user to make a
series of file creations within deleted directories, possibly causing a
denial of service. (CVE-2008-3275, Moderate)

* a buffer underflow flaw was found in the Linux kernel IB700 SBC watchdog
timer driver. This deficiency could lead to a possible information leak. By
default, the "/dev/watchdog" device is accessible only to the root user.
(CVE-2008-5702, Low)

* the hfs and hfsplus file systems code failed to properly handle corrupted
data structures. This could, potentially, lead to a local denial of
service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the hfsplus file system implementation. This could,
potentially, lead to a local denial of service when write operations were
performed. (CVE-2008-4934, Low)

This update also fixes the following bugs:

* when running Red Hat Enterprise Linux 4.6 and 4.7 on some systems running
Intel® CPUs, the cpuspeed daemon did not run, preventing the CPU speed from
being changed, such as not being reduced to an idle state when not in use.

* mmap() could be used to gain access to beyond the first megabyte of RAM,
due to insufficient checks in the Linux kernel code. Checks have been added
to prevent this.

* attempting to turn keyboard LEDs on and off rapidly on keyboards with
slow keyboard controllers, may have caused key presses to fail.

* after migrating a hypervisor guest, the MAC address table was not
updated, causing packet loss and preventing network connections to the
guest. Now, a gratuitous ARP request is sent after migration. This
refreshes the ARP caches, minimizing network downtime.

* writing crash dumps with diskdump may have caused a kernel panic on
Non-Uniform Memory Access (NUMA) systems with certain memory
configurations.

* on big-endian systems, such as PowerPC, the getsockopt() function
incorrectly returned 0 depending on the parameters passed to it when the
time to live (TTL) value equaled 255, possibly causing memory corruption
and application crashes.

* a problem in the kernel packages provided by the RHSA-2008:0508 advisory
caused the Linux kernel's built-in memory copy procedure to return the
wrong error code after recovering from a page fault on AMD64 and Intel 64
systems. This may have caused other Linux kernel functions to return wrong
error codes.

* a divide-by-zero bug in the Linux kernel process scheduler, which may
have caused kernel panics on certain systems, has been resolved.

* the netconsole kernel module caused the Linux kernel to hang when slave
interfaces of bonded network interfaces were started, resulting in a system
hang or kernel panic when restarting the network.

* the "/proc/xen/" directory existed even if systems were not running Red
Hat Virtualization. This may have caused problems for third-party software
that checks virtualization-ability based on the existence of "/proc/xen/".
Note: this update will remove the "/proc/xen/" directory on systems not
running Red Hat Virtualization.

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4934</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5300</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5702</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090014"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090018" severity="high">
    <xccdf:title>RHSA-2009:0018: xterm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xterm program is a terminal emulator for the X Window System.

A flaw was found in the xterm handling of Device Control Request Status
String (DECRQSS) escape sequences. An attacker could create a malicious
text file (or log entry, if unfiltered) that could run arbitrary commands
if read by a victim inside an xterm window. (CVE-2008-2383)

All xterm users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. All running instances of
xterm must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2383</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090018"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090020" severity="medium">
    <xccdf:title>RHSA-2009:0020: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.

A flaw was discovered in the way BIND checked the return value of the
OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone
could present a malformed DSA certificate and bypass proper certificate
validation, allowing spoofing attacks. (CVE-2009-0025)

For users of Red Hat Enterprise Linux 3 this update also addresses a bug
which can cause BIND to occasionally exit with an assertion failure.

All BIND users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. After installing the
update, BIND daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0025</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090020"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090046" severity="medium">
    <xccdf:title>RHSA-2009:0046: ntp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A flaw was discovered in the way the ntpd daemon checked the return value
of the OpenSSL EVP_VerifyFinal function. On systems using NTPv4
authentication, this could lead to an incorrect verification of
cryptographic signatures, allowing time-spoofing attacks. (CVE-2009-0021)

Note: This issue only affects systems that have enabled NTP authentication.
By default, NTP authentication is not enabled.

All ntp users are advised to upgrade to the updated packages, which contain
a backported patch to resolve this issue. After installing the update, the
ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0046</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0021</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090046"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090057" severity="high">
    <xccdf:title>RHSA-2009:0057: squirrelmail security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

The Red Hat SquirrelMail packages provided by the RHSA-2009:0010 advisory
introduced a session handling flaw. Users who logged back into SquirrelMail
without restarting their web browsers were assigned fixed session
identifiers. A remote attacker could make use of that flaw to hijack user
sessions. (CVE-2009-0030)

SquirrelMail users should upgrade to this updated package, which contains a
patch to correct this issue. As well, all users who used affected versions
of SquirrelMail should review their preferences.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1580</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090057"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090205" severity="low">
    <xccdf:title>RHSA-2009:0205: dovecot security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.

A flaw was found in Dovecot's ACL plug-in. The ACL plug-in treated negative
access rights as positive rights, which could allow an attacker to bypass
intended access restrictions. (CVE-2008-4577)

A password disclosure flaw was found with Dovecot's configuration file. If
a system had the "ssl_key_password" option defined, any local user could
view the SSL key password. (CVE-2008-4870)

Note: This flaw did not allow the attacker to acquire the contents of the
SSL key. The password has no value without the key file which arbitrary
users should not have read access to.

To better protect even this value, however, the dovecot.conf file now
supports the "!include_try" directive. The ssl_key_password option should
be moved from dovecot.conf to a new file owned by, and only readable and
writable by, root (ie 0600). This file should be referenced from
dovecot.conf by setting the "!include_try [/path/to/password/file]" option.

Additionally, this update addresses the following bugs:

* the dovecot init script -- /etc/rc.d/init.d/dovecot -- did not check if
the dovecot binary or configuration files existed. It also used the wrong
pid file for checking the dovecot service's status. This update includes a
new init script that corrects these errors.

* the %files section of the dovecot spec file did not include "%dir
%{ssldir}/private". As a consequence, the /etc/pki/private/ directory was
not owned by dovecot. (Note: files inside /etc/pki/private/ were and are
owned by dovecot.) With this update, the missing line has been added to the
spec file, and the noted directory is now owned by dovecot.

* in some previously released versions of dovecot, the authentication
process accepted (and passed along un-escaped) passwords containing
characters that had special meaning to dovecot's internal protocols. This
updated release prevents such passwords from being passed back, instead
returning the error, "Attempted login with password having illegal chars".

Note: dovecot versions previously shipped with Red Hat Enterprise Linux 5
did not allow this behavior. This update addresses the issue above but said
issue was only present in versions of dovecot not previously included with
Red Hat Enterprise Linux 5.

Users of dovecot are advised to upgrade to this updated package, which
addresses these vulnerabilities and resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4870</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090205"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090225" severity="high">
    <xccdf:title>RHSA-2009:0225: Red Hat Enterprise Linux 5.3 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Linux kernel (the core of the Linux operating system)

These updated packages contain 730 bug fixes and enhancements for the Linux
kernel. Space precludes a detailed description of each of these changes in
this advisory and users are therefore directed to the release notes for Red
Hat Enterprise Linux 5.3 for information on 97 of the most significant of
these changes. 

Details of three security-related bug fixes are set out below, along with
notes on other broad categories of change not covered in the release notes.
For more detailed information on specific bug fixes or enhancements, please
consult the Bugzilla numbers listed in this advisory.

* when fput() was called to close a socket, the __scm_destroy() function  
in the Linux kernel could make indirect recursive calls to itself. This  
could, potentially, lead to a denial of service issue. (CVE-2008-5029,  
Important)

* a flaw was found in the Asynchronous Transfer Mode (ATM) subsystem. A
local, unprivileged user could use the flaw to listen on the same socket
more than once, possibly causing a denial of service. (CVE-2008-5079,
Important)

* a race condition was found in the Linux kernel "inotify" watch removal
and umount implementation. This could allow a local, unprivileged user  
to cause a privilege escalation or a denial of service. (CVE-2008-5182,  
Important)

* Bug fixes and enhancements are provided for:

* support for specific NICs, including products from the following
manufacturers:
Broadcom
Chelsio
Cisco
Intel
Marvell
NetXen
Realtek
Sun

* Fiber Channel support, including support for Qlogic qla2xxx,
qla4xxx, and qla84xx HBAs and the FCoE, FCP, and zFCP protocols.

* support for various CPUs, including:
AMD Opteron processors with 45 nm SOI ("Shanghai")
AMD Turion Ultra processors
Cell processors
Intel Core i7 processors

* Xen support, including issues specific to the IA64 platform, systems
using AMD processors, and Dell Optiplex GX280 systems

* ext3, ext4, GFS2, NFS, and SPUFS

* Infiniband (including eHCA, eHEA, and IPoIB) support

* common I/O (CIO), direct I/O (DIO), and queued direct I/O (qdio) support

* the kernel distributed lock manager (DLM)

* hardware issues with: SCSI, IEEE 1394 (FireWire), RAID (including issues
specific to Adaptec controllers), SATA (including NCQ), PCI, audio, serial
connections, tape-drives, and USB

* ACPI, some of a general nature and some related to specific hardware
including: certain Lenovo Thinkpad notebooks, HP DC7700 systems, and
certain machines based on Intel Centrino processor technology.

* CIFS, including Kerberos support and a tech-preview of DFS support

* networking support, including IPv6, PPPoE, and IPSec

* support for Intel chipsets, including:
Intel Cantiga chipsets
Intel Eagle Lake chipsets
Intel i915 chipsets
Intel i965 chipsets
Intel Ibex Peak chipsets
Intel chipsets offering QuickPath Interconnects (QPI)

* device mapping issues, including some in device mapper itself

* various issues specific to IA64 and PPC

* CCISS, including support for Compaq SMART Array controllers P711m and
P712m and other new hardware

* various issues affecting specific HP systems, including:
DL785G5
XW4800
XW8600
XW8600
XW9400

* IOMMU support, including specific
issues with AMD and IBM Calgary hardware

* the audit subsystem

* DASD support

* iSCSI support, including issues specific to Chelsio T3 adapters

* LVM issues

* SCTP management information base (MIB) support

* issues with: autofs, kdump, kobject_add, libata, lpar, ptrace, and utrace

* IBM Power platforms using Enhanced I/O Error Handling (EEH)

* EDAC issues for AMD K8 and Intel i5000

* ALSA, including support for new hardware

* futex support

* hugepage support

* Intelligent Platform Management Interface (IPMI) support

* issues affecting NEC/Stratus servers

* OFED support

* SELinux 

* various Virtio issues

All users are advised to upgrade to these updated packages, which resolve
these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0225</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5300</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090225"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090256" severity="high">
    <xccdf:title>RHSA-2009:0256: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0352, CVE-2009-0353, CVE-2009-0356)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0354,
CVE-2009-0355)

A flaw was found in the way Firefox treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

A flaw was found in the way Firefox treated certain HTTP page caching
directives. A local attacker could steal the contents of sensitive pages
which the page author did not intend to be cached. (CVE-2009-0358)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.6. You can find a link to the Mozilla
advisories in the References section.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.6, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0256</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0354</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0356</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0357</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0358</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090256"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090257" severity="high">
    <xccdf:title>RHSA-2009:0257: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0352, CVE-2009-0353)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into uploading a local file. (CVE-2009-0355)

A flaw was found in the way SeaMonkey treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0357</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090257"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090258" severity="medium">
    <xccdf:title>RHSA-2009:0258: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. An
HTML mail message containing specially-crafted content could potentially
trick a Thunderbird user into surrendering sensitive information.
(CVE-2009-0355, CVE-2009-0776)

Note: JavaScript support is disabled by default in Thunderbird. None of
the above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090258"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090259" severity="medium">
    <xccdf:title>RHSA-2009:0259: mod_auth_mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_auth_mysql package includes an extension module for the Apache HTTP
Server which can be used to implement web user authentication against a
MySQL database.

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a
multibyte character set that allowed a backslash '\' as part of the
character encodings, a remote attacker could inject arbitrary SQL commands
into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where 
AuthMySQLCharacterSet is configured to use one of the affected multibyte
character sets. Installations that did not use the AuthMySQLCharacterSet
configuration option were not vulnerable to this flaw.

All mod_auth_mysql users are advised to upgrade to the updated package,
which contains a backported patch to resolve this issue. After installing
the update, the httpd daemon must be restarted for the fix to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0259</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2384</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090259"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090261" severity="medium">
    <xccdf:title>RHSA-2009:0261: vnc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Virtual Network Computing (VNC) is a remote display system which allows you
to view a computer's "desktop" environment not only on the machine where it
is running, but from anywhere on the Internet and from a wide variety of
machine architectures.

An insufficient input validation flaw was discovered in the VNC client
application, vncviewer. If an attacker could convince a victim to connect
to a malicious VNC server, or when an attacker was able to connect to
vncviewer running in the "listen" mode, the attacker could cause the
victim's vncviewer to crash or, possibly, execute arbitrary code.
(CVE-2008-4770)

Users of vncviewer should upgrade to these updated packages, which contain
a backported patch to resolve this issue. For the update to take effect,
all running instances of vncviewer must be restarted after the update is
installed.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0261</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4770</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090261"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090264" severity="high">
    <xccdf:title>RHSA-2009:0264: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a memory leak in keyctl handling. A local user could use this flaw to
deplete kernel memory, eventually leading to a denial of service. 
(CVE-2009-0031, Important)

* a buffer overflow in the Linux kernel Partial Reliable Stream Control
Transmission Protocol (PR-SCTP) implementation. This could, potentially,
lead to a denial of service if a Forward-TSN chunk is received with a large
stream ID. (CVE-2009-0065, Important)

* a flaw when handling heavy network traffic on an SMP system with many
cores. An attacker who could send a large amount of network traffic could
create a denial of service. (CVE-2008-5713, Important)

* the code for the HFS and HFS Plus (HFS+) file systems failed to properly
handle corrupted data structures. This could, potentially, lead to a local
denial of service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the HFS Plus (HFS+) file system implementation. This
could, potentially, lead to a local denial of service when write operations
are performed. (CVE-2008-4934, Low)

In addition, these updated packages fix the following bugs:

* when using the nfsd daemon in a clustered setup, kernel panics appeared
seemingly at random. These panics were caused by a race condition in
the device-mapper mirror target. 

* the clock_gettime(CLOCK_THREAD_CPUTIME_ID, ) syscall returned a smaller
timespec value than the result of previous clock_gettime() function
execution, which resulted in a negative, and nonsensical, elapsed time value.

* nfs_create_rpc_client was called with a "flavor" parameter which was
usually ignored and ended up unconditionally creating the RPC client with
an AUTH_UNIX flavor. This caused problems on AUTH_GSS mounts when the
credentials needed to be refreshed. The credops did not match the
authorization type, which resulted in the credops dereferencing an
incorrect part of the AUTH_UNIX rpc_auth struct.

* when copy_user_c terminated prematurely due to reading beyond the end of
the user buffer and the kernel jumped to the exception table entry, the rsi
register was not cleared. This resulted in exiting back to user code with
garbage in the rsi register.

* the hexdump data in s390dbf traces was incomplete. The length of the data
traced was incorrect and the SAN payload was read from a different place
then it was written to.

* when using connected mode (CM) in IPoIB on ehca2 hardware, it was not
possible to transmit any data.

* when an application called fork() and pthread_create() many times and, at
some point, a thread forked a child and then attempted to call the
setpgid() function, then this function failed and returned and ESRCH error
value.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Note: for this update to take effect, the
system must be rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0264</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4934</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0065</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090264"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090267" severity="medium">
    <xccdf:title>RHSA-2009:0267: sudo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A flaw was discovered in a way sudo handled group specifications in "run
as" lists in the sudoers configuration file. If sudo configuration allowed
a user to run commands as any user of some group and the user was also a
member of that group, sudo incorrectly allowed them to run defined commands
with the privileges of any system user. This gave the user unintended
privileges. (CVE-2009-0034)

Users of sudo should update to this updated package, which contains a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0267</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0034</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090267"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090270" severity="high">
    <xccdf:title>RHSA-2009:0270: gstreamer-plugins security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gstreamer-plugins package contains plugins used by the GStreamer
streaming-media framework to support a wide variety of media types.

A heap buffer overflow was found in the GStreamer's QuickTime media file
format decoding plug-in. An attacker could create a carefully-crafted
QuickTime media .mov file that would cause an application using GStreamer
to crash or, potentially, execute arbitrary code if played by a victim.
(CVE-2009-0397)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, all applications using GStreamer (such as rhythmbox)
must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0397</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090270"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090271" severity="high">
    <xccdf:title>RHSA-2009:0271: gstreamer-plugins-good security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, GStreamer plug-ins of good quality released under the LGPL
license.

Multiple heap buffer overflows and an array indexing error were found in
the GStreamer's QuickTime media file format decoding plugin. An attacker
could create a carefully-crafted QuickTime media .mov file that would cause
an application using GStreamer to crash or, potentially, execute arbitrary
code if played by a victim. (CVE-2009-0386, CVE-2009-0387, CVE-2009-0397)

All users of gstreamer-plugins-good are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as totem or
rhythmbox) must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0387</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0397</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090271"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090296" severity="medium">
    <xccdf:title>RHSA-2009:0296: icu security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A flaw was found in the way ICU processed certain, invalid, encoded data.
If an application used ICU to decode malformed, multibyte, character data,
it may have been possible to bypass certain content protection mechanisms,
or display information in a manner misleading to the user. (CVE-2008-1036)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1036</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090296"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090313" severity="medium">
    <xccdf:title>RHSA-2009:0313: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network or opened a malformed dump file, it could
crash or, possibly, execute arbitrary code as the user running Wireshark.
(CVE-2008-4683, CVE-2009-0599)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malformed dump file. (CVE-2008-4680, CVE-2008-4681, CVE-2008-4682,
CVE-2008-4684, CVE-2008-4685, CVE-2008-5285, CVE-2009-0600)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.6, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4684</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4685</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0600</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090313"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090315" severity="high">
    <xccdf:title>RHSA-2009:0315: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0040, CVE-2009-0771, CVE-2009-0772, CVE-2009-0773, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0776,
CVE-2009-0777)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.7. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.7, and which correct these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0315</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0773</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0777</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090315"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090325" severity="high">
    <xccdf:title>RHSA-2009:0325: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0040, CVE-2009-0772, CVE-2009-0774, CVE-2009-0775)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into surrendering sensitive information. (CVE-2009-0776)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090325"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090326" severity="high">
    <xccdf:title>RHSA-2009:0326: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* memory leaks were found on some error paths in the icmp_send()
function in the Linux kernel. This could, potentially, cause the network
connectivity to cease. (CVE-2009-0778, Important)

* Chris Evans reported a deficiency in the clone() system call when called
with the CLONE_PARENT flag. This flaw permits the caller (the parent
process) to indicate an arbitrary signal it wants to receive when its child
process exits. This could lead to a denial of service of the parent
process. (CVE-2009-0028, Moderate)

* an off-by-one underflow flaw was found in the eCryptfs subsystem. This
could potentially cause a local denial of service when the readlink()
function returned an error. (CVE-2009-0269, Moderate)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size files in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Moderate)

* an inverted logic flaw was found in the SysKonnect FDDI PCI adapter
driver, allowing driver statistics to be reset only when the CAP_NET_ADMIN
capability was absent (local, unprivileged users could reset driver
statistics). (CVE-2009-0675, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

* the ext2 and ext3 file system code failed to properly handle corrupted
data structures, leading to a possible local denial of service when read
or write operations were performed on a specially-crafted file system.
(CVE-2008-3528, Low)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a local denial of service. Note: by default, the
"/dev/sg*" devices are accessible only to the root user.
(CVE-2008-5700, Low)

Bug fixes:

* a bug in aic94xx may have caused kernel panics during boot on some
systems with certain SATA disks. (BZ#485909)

* a word endianness problem in the qla2xx driver on PowerPC-based machines
may have corrupted flash-based devices. (BZ#485908)

* a memory leak in pipe() may have caused a system deadlock. The workaround
in Section 1.5, Known Issues, of the Red Hat Enterprise Linux 5.3 Release
Notes Updates, which involved manually allocating extra file descriptors to
processes calling do_pipe, is no longer necessary. (BZ#481576)

* CPU soft-lockups in the network rate estimator. (BZ#481746)

* bugs in the ixgbe driver caused it to function unreliably on some
systems with 16 or more CPU cores. (BZ#483210)

* the iwl4965 driver may have caused a kernel panic. (BZ#483206)

* a bug caused NFS attributes to not update for some long-lived NFS
mounted file systems. (BZ#483201)

* unmounting a GFS2 file system may have caused a panic. (BZ#485910)

* a bug in ptrace() may have caused a panic when single stepping a target.
(BZ#487394)

* on some 64-bit systems, notsc was incorrectly set at boot, causing slow
gettimeofday() calls. (BZ#488239)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#490433)

* scaling problems caused performance problems for LAPI applications.
(BZ#489457)

* a panic may have occurred on systems using certain Intel WiFi Link 5000
products when booting with the RF Kill switch on. (BZ#489846)

* the TSC is invariant with C/P/T states, and always runs at constant
frequency from now on. (BZ#489310)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues. The system must be rebooted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0269</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0778</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090326"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090329" severity="high">
    <xccdf:title>RHSA-2009:0329: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2
font engines.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Chris Evans discovered multiple integer overflow flaws in the FreeType font
engine. If a user loaded a carefully-crafted font file with an application
linked against FreeType, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2006-1861)

An integer overflow flaw was found in the way the FreeType font engine
processed TrueType® Font (TTF) files. If a user loaded a carefully-crafted
font file with an application linked against FreeType, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2007-2754)

A flaw was discovered in the FreeType TTF font-file format parser when the
TrueType virtual machine Byte Code Interpreter (BCI) is enabled. If a user
loaded a carefully-crafted font file with an application linked against
FreeType, it could cause the application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2008-1808)

The CVE-2008-1808 flaw did not affect the freetype packages as distributed
in Red Hat Enterprise Linux 3 and 4, as they are not compiled with TrueType
BCI support. A fix for this flaw has been included in this update as users
may choose to recompile the freetype packages in order to enable TrueType
BCI support. Red Hat does not, however, provide support for modified and
recompiled packages.

Note: For the FreeType 2 font engine, the CVE-2006-1861, CVE-2007-2754,
and CVE-2008-1808 flaws were addressed via RHSA-2006:0500, RHSA-2007:0403,
and RHSA-2008:0556 respectively. This update provides corresponding
updates for the FreeType 1 font engine, included in the freetype packages
distributed in Red Hat Enterprise Linux 3 and 4.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2754</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0946</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090329"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090331" severity="high">
    <xccdf:title>RHSA-2009:0331: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a buffer overflow was found in the Linux kernel Partial Reliable Stream
Control Transmission Protocol (PR-SCTP) implementation. This could,
potentially, lead to a denial of service if a Forward-TSN chunk is received
with a large stream ID. (CVE-2009-0065, Important)

* a memory leak was found in keyctl handling. A local, unprivileged user
could use this flaw to deplete kernel memory, eventually leading to a
denial of service. (CVE-2009-0031, Important)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size file in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Important)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a denial of service. Note: by default, "/dev/sg*"
devices are accessible only to the root user. (CVE-2008-5700, Low)

This update also fixes the following bugs:

* when the hypervisor changed a page table entry (pte) mapping from
read-only to writable via a make_writable hypercall, accessing the changed
page immediately following the change caused a spurious page fault. When
trying to install a para-virtualized Red Hat Enterprise Linux 4 guest on a
Red Hat Enterprise Linux 5.3 dom0 host, this fault crashed the installer
with a kernel backtrace. With this update, the "spurious" page fault is
handled properly. (BZ#483748)

* net_rx_action could detect its cpu poll_list as non-empty, but have that
same list reduced to empty by the poll_napi path. This resulted in garbage
data being returned when net_rx_action calls list_entry, which subsequently
resulted in several possible crash conditions. The race condition in the
network code which caused this has been fixed. (BZ#475970, BZ#479681,
BZ#480741)

* a misplaced memory barrier at unlock_buffer() could lead to a concurrent
h_refcounter update which produced a reference counter leak and, later, a
double free in ext3_xattr_release_block(). Consequent to the double free,
ext3 reported an error

    ext3_free_blocks_sb: bit already cleared for block [block number]

and mounted itself as read-only. With this update, the memory barrier is
now placed before the buffer head lock bit, forcing the write order and
preventing the double free. (BZ#476533)

* when the iptables module was unloaded, it was assumed the correct entry
for removal had been found if "wrapper-&gt;ops-&gt;pf" matched the value passed
in by "reg-&gt;pf". If several ops ranges were registered against the same
protocol family, however, (which was likely if you had both ip_conntrack
and ip_contrack_* loaded) this assumption could lead to NULL list pointers
and cause a kernel panic. With this update, "wrapper-&gt;ops" is matched to
pointer values "reg", which ensures the correct entry is removed and
results in no NULL list pointers. (BZ#477147)

* when the pidmap page (used for tracking process ids, pids) incremented to
an even page (ie the second, fourth, sixth, etc. pidmap page), the
alloc_pidmap() routine skipped the page. This resulted in "holes" in the
allocated pids. For example, after pid 32767, you would expect 32768 to be
allocated. If the page skipping behavior presented, however, the pid
allocated after 32767 was 65536. With this update, alloc_pidmap() no longer
skips alternate pidmap pages and allocated pid holes no longer occur. This
fix also corrects an error which allowed pid_max to be set higher than the
pid_max limit has been corrected. (BZ#479182)

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. The
system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0331</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090331"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090333" severity="medium">
    <xccdf:title>RHSA-2009:0333: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was discovered in libpng that could result in libpng trying to
free() random memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)

A flaw was discovered in the way libpng handled PNG images containing
"unknown" chunks. If an application linked against libpng attempted to
process a malformed, unknown chunk in a malicious PNG image, it could cause
the application to crash. (CVE-2008-1382)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0333</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0040</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090333"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090336" severity="medium">
    <xccdf:title>RHSA-2009:0336: glib2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GLib is the low-level core library that forms the basis for projects such
as GTK+ and GNOME. It provides data structure handling for C, portability
wrappers, and interfaces for such runtime functionality as an event loop,
threads, dynamic loading, and an object system.

Diego Pettenò discovered multiple integer overflows causing heap-based
buffer overflows in GLib's Base64 encoding and decoding functions. An
attacker could use these flaws to crash an application using GLib's Base64
functions to encode or decode large, untrusted inputs, or, possibly,
execute arbitrary code as the user running the application. (CVE-2008-4316)

Note: No application shipped with Red Hat Enterprise Linux 5 uses the
affected functions. Third-party applications may, however, be affected.

All users of glib2 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4316</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090336"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090337" severity="medium">
    <xccdf:title>RHSA-2009:0337: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3660</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090337"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090338" severity="medium">
    <xccdf:title>RHSA-2009:0338: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

A cross-site scripting flaw was found in a way PHP reported errors for
invalid cookies. If the PHP interpreter had "display_errors" enabled, a
remote attacker able to set a specially-crafted cookie on a victim's system
could possibly inject arbitrary HTML into an error message generated by
PHP. (CVE-2008-5814)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3660</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090338"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090339" severity="medium">
    <xccdf:title>RHSA-2009:0339: lcms security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in LittleCMS. An attacker could use these flaws to create a
specially-crafted image file which could cause an application using
LittleCMS to crash, or, possibly, execute arbitrary code when opened by a
victim. (CVE-2009-0723, CVE-2009-0733)

A memory leak flaw was found in LittleCMS. An application using LittleCMS
could use excessive amount of memory, and possibly crash after using all
available memory, if used to open specially-crafted images. (CVE-2009-0581)

Red Hat would like to thank Chris Evans from the Google Security Team for
reporting these issues.

All users of LittleCMS should install these updated packages, which upgrade
LittleCMS to version 1.18. All running applications using the lcms library
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0733</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090339"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090341" severity="medium">
    <xccdf:title>RHSA-2009:0341: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

David Kierznowski discovered a flaw in libcurl where it would not
differentiate between different target URLs when handling automatic
redirects. This caused libcurl to follow any new URL that it understood,
including the "file://" URL type. This could allow a remote server to force
a local libcurl-using application to read a local file instead of the
remote one, possibly exposing local files that were not meant to be
exposed. (CVE-2009-0037)

Note: Applications using libcurl that are expected to follow redirects to
"file://" protocol must now explicitly call curl_easy_setopt(3) and set the
newly introduced CURLOPT_REDIR_PROTOCOLS option as required.

cURL users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0037</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090341"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090344" severity="medium">
    <xccdf:title>RHSA-2009:0344: libsoup security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libsoup is an HTTP client/library implementation for GNOME written in C. It
was originally part of a SOAP (Simple Object Access Protocol)
implementation called Soup, but the SOAP and non-SOAP parts have now been
split into separate packages.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in libsoup's Base64 encoding routine. An attacker could use this
flaw to crash, or, possibly, execute arbitrary code. This arbitrary code
would execute with the privileges of the application using libsoup's Base64
routine to encode large, untrusted inputs. (CVE-2009-0585)

All users of libsoup and evolution28-libsoup should upgrade to these
updated packages, which contain a backported patch to resolve this issue.
All running applications using the affected library function (such as
Evolution configured to connect to the GroupWise back-end) must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0585</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090344"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090345" severity="medium">
    <xccdf:title>RHSA-2009:0345: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript(TM)
interpreter, a set of C procedures (the Ghostscript library, which
implements the graphics capabilities in the PostScript language) and
an interpreter for Portable Document Format (PDF) files. 

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in Ghostscript's International Color Consortium Format library
(icclib). Using specially-crafted ICC profiles, an attacker could create a
malicious PostScript or PDF file with embedded images which could cause
Ghostscript to crash, or, potentially, execute arbitrary code when opened
by the victim. (CVE-2009-0583, CVE-2009-0584)

All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0584</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090345"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090352" severity="medium">
    <xccdf:title>RHSA-2009:0352: gstreamer-plugins-base security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GStreamer is a streaming media framework based on graphs of filters which
operate on media data. GStreamer Base Plug-ins is a collection of
well-maintained base plug-ins.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in the Vorbis comment tags reader. An attacker could create a
carefully-crafted Vorbis file that would cause an application using
GStreamer to crash or, potentially, execute arbitrary code if opened by a
victim. (CVE-2009-0586)

All users of gstreamer-plugins-base are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all applications using GStreamer (such as Totem or
Rhythmbox) must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0586</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090352"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090354" severity="medium">
    <xccdf:title>RHSA-2009:0354: evolution-data-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution Data Server provides a unified back-end for applications which
interact with contacts, task, and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution Data Server did not properly check the Secure/Multipurpose
Internet Mail Extensions (S/MIME) signatures used for public key encryption
and signing of e-mail messages. An attacker could use this flaw to spoof a
signature by modifying the text of the e-mail message displayed to the
user. (CVE-2009-0547)

It was discovered that Evolution Data Server did not properly validate NTLM
(NT LAN Manager) authentication challenge packets. A malicious server using
NTLM authentication could cause an application using Evolution Data Server
to disclose portions of its memory or crash during user authentication.
(CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by Evolution Data
Server. This could cause an application using Evolution Data Server to
crash, or, possibly, execute an arbitrary code when large untrusted data
blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution-data-server and evolution28-evolution-data-server
are advised to upgrade to these updated packages, which contain backported
patches to correct these issues. All running instances of Evolution Data
Server and applications using it (such as Evolution) must be restarted for
the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0354</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0587</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090354"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090355" severity="medium">
    <xccdf:title>RHSA-2009:0355: evolution and evolution-data-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

Evolution Data Server provides a unified back-end for applications which
interact with contacts, task and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution did not properly check the Secure/Multipurpose Internet Mail
Extensions (S/MIME) signatures used for public key encryption and signing
of e-mail messages. An attacker could use this flaw to spoof a signature by
modifying the text of the e-mail message displayed to the user. (CVE-2009-0547)

It was discovered that evolution did not properly validate NTLM (NT LAN
Manager) authentication challenge packets. A malicious server using NTLM
authentication could cause evolution to disclose portions of its memory or
crash during user authentication. (CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by evolution and
evolution-data-server. This could cause evolution, or an application using
evolution-data-server, to crash, or, possibly, execute an arbitrary code
when large untrusted data blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution and evolution-data-server are advised to upgrade to
these updated packages, which contain backported patches to correct these
issues. All running instances of evolution and evolution-data-server must
be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0587</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090355"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090361" severity="medium">
    <xccdf:title>RHSA-2009:0361: NetworkManager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

A potential denial of service flaw was found in NetworkManager's D-Bus
interface. A local user could leverage this flaw to modify local connection
settings, preventing the system's network connection from functioning
properly. (CVE-2009-0578)

Red Hat would like to thank Ludwig Nussel for reporting these flaws
responsibly.

Users of NetworkManager should upgrade to these updated packages which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0361</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0578</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090361"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090362" severity="medium">
    <xccdf:title>RHSA-2009:0362: NetworkManager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

Red Hat would like to thank Ludwig Nussel for responsibly reporting this
flaw.

NetworkManager users should upgrade to these updated packages, which
contain a backported patch that corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0365</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090362"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090373" severity="medium">
    <xccdf:title>RHSA-2009:0373: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation infrastructure for systems running version
2.6 of the Linux kernel. SystemTap scripts can collect system operations
data, greatly simplifying information gathering. Collected data can then
assist in performance measuring, functional testing, and performance and
function problem diagnosis.

A race condition was discovered in SystemTap that could allow users in the
stapusr group to elevate privileges to that of members of the stapdev group
(and hence root), bypassing directory confinement restrictions and allowing
them to insert arbitrary SystemTap kernel modules. (CVE-2009-0784)

Note: This issue was only exploitable if another SystemTap kernel module
was placed in the "systemtap/" module directory for the currently running
kernel.

Red Hat would like to thank Erik Sjölund for reporting this issue.

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0784</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090373"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090377" severity="high">
    <xccdf:title>RHSA-2009:0377: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way that the Java Virtual Machine (JVM) handled
temporary font files. A malicious applet could use this flaw to use large
amounts of disk space, causing a denial of service. (CVE-2006-2426)

A memory leak flaw was found in LittleCMS (embedded in OpenJDK). An
application using color profiles could use excessive amounts of memory, and
possibly crash after using all available memory, if used to open
specially-crafted images. (CVE-2009-0581)

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in the way LittleCMS handled color profiles. An attacker could use
these flaws to create a specially-crafted image file which could cause a
Java application to crash or, possibly, execute arbitrary code when opened.
(CVE-2009-0723, CVE-2009-0733)

A null pointer dereference flaw was found in LittleCMS. An application
using color profiles could crash while converting a specially-crafted image
file. (CVE-2009-0793)

A flaw in the Java API for XML Web Services (JAX-WS) service endpoint
handling could allow a remote attacker to cause a denial of service on the
server application hosting the JAX-WS service endpoint. (CVE-2009-1101)

A flaw in the way the Java Runtime Environment initialized LDAP connections
could allow a remote, authenticated user to cause a denial of service on
the LDAP service. (CVE-2009-1093)

A flaw in the Java Runtime Environment LDAP client could allow malicious
data from an LDAP server to cause arbitrary code to be loaded and then run
on an LDAP client. (CVE-2009-1094)

Several buffer overflow flaws were found in the Java Runtime Environment
unpack200 functionality. An untrusted applet could extend its privileges,
allowing it to read and write local files, as well as to execute local
applications with the privileges of the user running the applet.
(CVE-2009-1095, CVE-2009-1096)

A flaw in the Java Runtime Environment Virtual Machine code generation
functionality could allow untrusted applets to extend their privileges. An
untrusted applet could extend its privileges, allowing it to read and write
local files, as well as execute local applications with the privileges
of the user running the applet. (CVE-2009-1102)

A buffer overflow flaw was found in the splash screen processing. A remote
attacker could extend privileges to read and write local files, as well as
to execute local applications with the privileges of the user running the
java process. (CVE-2009-1097)

A buffer overflow flaw was found in how GIF images were processed. A remote
attacker could extend privileges to read and write local files, as well as
execute local applications with the privileges of the user running the
java process. (CVE-2009-1098)

Note: The flaws concerning applets in this advisory, CVE-2009-1095,
CVE-2009-1096, and CVE-2009-1102, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-2426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090377"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090382" severity="medium">
    <xccdf:title>RHSA-2009:0382: libvirt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libvirt is a C API for managing and interacting with the virtualization
capabilities of Linux and other operating systems. libvirt also provides
tools for remotely managing virtualized systems.

The libvirtd daemon was discovered to not properly check user connection
permissions before performing certain privileged actions, such as
requesting migration of an unprivileged guest domain to another system. A
local user able to establish a read-only connection to libvirtd could use
this flaw to perform actions that should be restricted to read-write
connections. (CVE-2008-5086)

libvirt_proxy, a setuid helper application allowing non-privileged users to
communicate with the hypervisor, was discovered to not properly validate
user requests. Local users could use this flaw to cause a stack-based
buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary
code with root privileges. (CVE-2009-0036)

All users are advised to upgrade to these updated packages, which contain
backported patches which resolve these issues. After installing the update,
libvirtd must be restarted manually (for example, by issuing a "service
libvirtd restart" command), and guest systems rebooted, for this change to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0036</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090382"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090397" severity="high">
    <xccdf:title>RHSA-2009:0397: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A memory corruption flaw was discovered in the way Firefox handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2009-1169)

A flaw was discovered in the way Firefox handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash Firefox
or, potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1044)

For technical details regarding these flaws, refer to the Mozilla security
advisories. You can find a link to the Mozilla advisories in the References
section of this errata.

Firefox users should upgrade to these updated packages, which resolve these
issues. For Red Hat Enterprise Linux 4, they contain backported patches to
the firefox package. For Red Hat Enterprise Linux 5, they contain
backported patches to the xulrunner packages. After installing the update,
Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090397"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090398" severity="high">
    <xccdf:title>RHSA-2009:0398: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A memory corruption flaw was discovered in the way SeaMonkey handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash SeaMonkey or, potentially, execute arbitrary code as the user
running SeaMonkey. (CVE-2009-1169)

A flaw was discovered in the way SeaMonkey handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash SeaMonkey
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1044)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090398"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090402" severity="high">
    <xccdf:title>RHSA-2009:0402: openswan security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Gerd v. Egidy discovered a flaw in the Dead Peer Detection (DPD) in
Openswan's pluto IKE daemon. A remote attacker could use a malicious DPD
packet to crash the pluto daemon. (CVE-2009-0790)

It was discovered that Openswan's livetest script created temporary files
in an insecure manner. A local attacker could use this flaw to overwrite
arbitrary files owned by the user running the script. (CVE-2008-4190)

Note: The livetest script is an incomplete feature and was not
automatically executed by any other script distributed with Openswan, or
intended to be used at all, as was documented in its man page. In these
updated packages, the script only prints an informative message and exits
immediately when run.

All users of openswan are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4190</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0790</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090402"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090408" severity="high">
    <xccdf:title>RHSA-2009:0408: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC). The Generic
Security Service Application Program Interface (GSS-API) definition
provides security services to callers (protocols) in a generic fashion. The
Simple and Protected GSS-API Negotiation (SPNEGO) mechanism is used by
GSS-API peers to choose from a common set of security mechanisms.

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

Multiple input validation flaws were found in the MIT Kerberos GSS-API
library's implementation of the SPNEGO mechanism. A remote attacker could
use these flaws to crash any network service utilizing the MIT Kerberos
GSS-API library to authenticate users or, possibly, leak portions of the
service's memory. (CVE-2009-0844, CVE-2009-0845)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running services using the
MIT Kerberos libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0846</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090408"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090409" severity="high">
    <xccdf:title>RHSA-2009:0409: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0846</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090409"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090411" severity="medium">
    <xccdf:title>RHSA-2009:0411: device-mapper-multipath security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The device-mapper multipath packages provide tools to manage multipath
devices by issuing instructions to the device-mapper multipath kernel
module, and by managing the creation and removal of partitions for
device-mapper devices.

It was discovered that the multipathd daemon set incorrect permissions on
the socket used to communicate with command line clients. An unprivileged,
local user could use this flaw to send commands to multipathd, resulting in
access disruptions to storage devices accessible via multiple paths and,
possibly, file system corruption on these devices. (CVE-2009-0115)

Users of device-mapper-multipath are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. The
multipathd service must be restarted for the changes to take effect.

Important: the version of the multipathd daemon in Red Hat Enterprise Linux
5 has a known issue which may cause a machine to become unresponsive when
the multipathd service is stopped. This issue is tracked in the Bugzilla
bug #494582; a link is provided in the References section of this erratum.
Until this issue is resolved, we recommend restarting the multipathd
service by issuing the following commands in sequence:

	# killall -KILL multipathd

	# service multipathd restart</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0115</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090411"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090420" severity="medium">
    <xccdf:title>RHSA-2009:0420: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not
address all possible integer overflow flaws in Ghostscript's International
Color Consortium Format library (icclib). Using specially-crafted ICC
profiles, an attacker could create a malicious PostScript or PDF file with
embedded images that could cause Ghostscript to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0792)

A missing boundary check was found in Ghostscript's CCITTFax decoding
filter. An attacker could create a specially-crafted PostScript or PDF file
that could cause Ghostscript to crash or, potentially, execute arbitrary
code when opened. (CVE-2007-6725)

Users of ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0792</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090420"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090421" severity="medium">
    <xccdf:title>RHSA-2009:0421: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not
address all possible integer overflow flaws in Ghostscript's International
Color Consortium Format library (icclib). Using specially-crafted ICC
profiles, an attacker could create a malicious PostScript or PDF file with
embedded images that could cause Ghostscript to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0792)

A buffer overflow flaw and multiple missing boundary checks were found in
Ghostscript. An attacker could create a specially-crafted PostScript or PDF
file that could cause Ghostscript to crash or, potentially, execute
arbitrary code when opened. (CVE-2008-6679, CVE-2007-6725, CVE-2009-0196)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly reporting the CVE-2009-0196 flaw.

Users of ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0792</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090421"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090427" severity="high">
    <xccdf:title>RHSA-2009:0427: udev security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>udev provides a user-space API and implements a dynamic device directory,
providing only the devices present on the system. udev replaces devfs in
order to provide greater hot plug functionality. Netlink is a datagram
oriented service, used to transfer information between kernel modules and
user-space processes.

It was discovered that udev did not properly check the origin of Netlink
messages. A local attacker could use this flaw to gain root privileges via
a crafted Netlink message sent to udev, causing it to create a
world-writable block device file for an existing system block device (for
example, the root file system). (CVE-2009-1185)

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
responsibly reporting this flaw.

Users of udev are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the udevd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1185</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090427"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090429" severity="high">
    <xccdf:title>RHSA-2009:0429: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

Multiple integer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0147, CVE-2009-1179)

Multiple buffer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in the CUPS JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause CUPS to crash or, potentially, execute arbitrary code
as the "lp" user if the file was printed. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0800)

An integer overflow flaw, leading to a heap-based buffer overflow, was
discovered in the Tagged Image File Format (TIFF) decoding routines used by
the CUPS image-converting filters, "imagetops" and "imagetoraster". An
attacker could create a malicious TIFF file that could, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0163)

Multiple denial of service flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
when printed. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Aaron Sigel, Braden Thomas and Drew Yao of
the Apple Product Security team, and Will Dormann of the CERT/CC for
responsibly reporting these flaws.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090429"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090430" severity="high">
    <xccdf:title>RHSA-2009:0430: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause Xpdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause Xpdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090430"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090431" severity="high">
    <xccdf:title>RHSA-2009:0431: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in KPDF's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF that would cause KPDF to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090431"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090436" severity="high">
    <xccdf:title>RHSA-2009:0436: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1308, CVE-2009-1309, CVE-2009-1310,
CVE-2009-1312)

A flaw was found in the way Firefox saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.9. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.9, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1311</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1312</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090436"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090437" severity="high">
    <xccdf:title>RHSA-2009:0437: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1303, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1312)

A flaw was found in the way SeaMonkey saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0437</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1311</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1312</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090437"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090444" severity="high">
    <xccdf:title>RHSA-2009:0444: giflib security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The giflib packages contain a shared library of functions for loading and
saving GIF image files. This library is API and ABI compatible with
libungif, the library that supported uncompressed GIF image files while the
Unisys LZW patent was in effect.

Several flaws were discovered in the way giflib decodes GIF images. An
attacker could create a carefully crafted GIF image that could cause an
application using giflib to crash or, possibly, execute arbitrary code when
opened by a victim. (CVE-2005-2974, CVE-2005-3350)

All users of giflib are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications using giflib must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-2974</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-3350</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090444"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090449" severity="high">
    <xccdf:title>RHSA-2009:0449: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1313)

For technical details regarding this flaw, refer to the Mozilla security
advisory for Firefox 3.0.10. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.10, which corrects this issue. After installing the
update, Firefox must be restarted for the change to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1313</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090449"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090457" severity="medium">
    <xccdf:title>RHSA-2009:0457: libwmf security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.

A pointer use-after-free flaw was found in the GD graphics library embedded
in libwmf. An attacker could create a specially-crafted WMF file that would
cause an application using libwmf to crash or, potentially, execute
arbitrary code as the user running the application when opened by a victim.
(CVE-2009-1364)

Note: This flaw is specific to the GD graphics library embedded in libwmf.
It does not affect the GD graphics library from the "gd" packages, or
applications using it.

Red Hat would like to thank Tavis Ormandy of the Google Security Team for
responsibly reporting this flaw.

All users of libwmf are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libwmf must be restarted for the update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1364</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090457"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090458" severity="high">
    <xccdf:title>RHSA-2009:0458: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GPdf is a viewer for Portable Document Format (PDF) files.

Multiple integer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in GPdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause GPdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause GPdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3606</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090458"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090459" severity="high">
    <xccdf:title>RHSA-2009:0459: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* Chris Evans reported a deficiency in the Linux kernel signals
implementation. The clone() system call permits the caller to indicate the
signal it wants to receive when its child exits. When clone() is called
with the CLONE_PARENT flag, it permits the caller to clone a new child that
shares the same parent as itself, enabling the indicated signal to be sent
to the caller's parent (instead of the caller), even if the caller's parent
has different real and effective user IDs. This could lead to a denial of
service of the parent. (CVE-2009-0028, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

Bug fixes:

* a kernel crash may have occurred for Red Hat Enterprise Linux 4.7 guests
if their guest configuration file specified "vif = [ "type=ioemu" ]". This
crash only occurred when starting guests via the "xm create" command.
(BZ#477146)

* a bug in IO-APIC NMI watchdog may have prevented Red Hat Enterprise Linux
4.7 from being installed on HP ProLiant DL580 G5 systems. Hangs during
installation and "NMI received for unknown reason [xx]" errors may have
occurred. (BZ#479184)

* a kernel deadlock on some systems when using netdump through a network
interface that uses the igb driver. (BZ#480579)

* a possible kernel hang in sys_ptrace() on the Itanium® architecture,
possibly triggered by tracing a threaded process with strace. (BZ#484904)

* the RHSA-2008:0665 errata only fixed the known problem with the LSI Logic
LSI53C1030 Ultra320 SCSI controller, for tape devices. Read commands sent
to tape devices may have received incorrect data. This issue may have led
to data corruption. This update includes a fix for all types of devices.
(BZ#487399)

* a missing memory barrier caused a race condition in the AIO subsystem
between the read_events() and aio_complete() functions. This may have
caused a thread in read_events() to sleep indefinitely, possibly causing an
application hang. (BZ#489935)

* due to a lack of synchronization in the NFS client code, modifications
to some pages (for files on an NFS mounted file system) made through a
region of memory mapped by mmap() may be lost if the NFS client invalidates
its page cache for particular files. (BZ#490119)

* a NULL pointer dereference in the megaraid_mbox driver caused a system
crash on some systems. (BZ#493420)

* the ext3_symlink() function in the ext3 file system code used an
illegal __GFP_FS allocation inside some transactions. This may have
resulted in a kernel panic and "Assertion failure" errors. (BZ#493422)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#494915)

* a bug prevented NMI watchdog from initializing on HP ProLiant DL580 G5
systems. (BZ#497330)

This update contains backported patches to fix these issues. The system
must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0834</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090473" severity="high">
    <xccdf:title>RHSA-2009:0473: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* a flaw was found in the ecryptfs_write_metadata_to_contents() function of
the Linux kernel eCryptfs implementation. On systems with a 4096 byte
page-size, this flaw may have caused 4096 bytes of uninitialized kernel
memory to be written into the eCryptfs file headers, leading to an
information leak. Note: Encrypted files created on systems running the
vulnerable version of eCryptfs may contain leaked data in the eCryptfs file
headers. This update does not remove any leaked data. Refer to the
Knowledgebase article in the References section for further information.
(CVE-2009-0787, Moderate)

* the Linux kernel implementation of the Network File System (NFS) did not
properly initialize the file name limit in the nfs_server data structure.
This flaw could possibly lead to a denial of service on a client mounting
an NFS share. (CVE-2009-1336, Moderate)

This update also fixes the following bugs:

* the enic driver (Cisco 10G Ethernet) did not operate under
virtualization. (BZ#472474)

* network interfaces using the IBM eHEA Ethernet device driver could not be
successfully configured under low-memory conditions. (BZ#487035)

* bonding with the "arp_validate=3" option may have prevented fail overs.
(BZ#488064)

* when running under virtualization, the acpi-cpufreq module wrote "Domain
attempted WRMSR" errors to the dmesg log. (BZ#488928)

* NFS clients may have experienced deadlocks during unmount. (BZ#488929)

* the ixgbe driver double counted the number of received bytes and packets.
(BZ#489459)

* the Wacom Intuos3 Lens Cursor device did not work correctly with the
Wacom Intuos3 12x12 tablet. (BZ#489460)

* on the Itanium® architecture, nanosleep() caused commands which used it,
such as sleep and usleep, to sleep for one second more than expected.
(BZ#490434)

* a panic and corruption of slab cache data structures occurred on 64-bit
PowerPC systems when clvmd was running. (BZ#491677)

* the NONSTOP_TSC feature did not perform correctly on the Intel®
microarchitecture (Nehalem) when running in 32-bit mode. (BZ#493356)

* keyboards may not have functioned on IBM eServer System p machines after
a certain point during installation or afterward. (BZ#494293)

* using Device Mapper Multipathing with the qla2xxx driver resulted in
frequent path failures. (BZ#495635)

* if the hypervisor was booted with the dom0_max_vcpus parameter set to
less than the actual number of CPUs in the system, and the cpuspeed service
was started, the hypervisor could crash. (BZ#495931)

* using Openswan to provide an IPsec virtual private network eventually
resulted in a CPU soft lockup and a system crash. (BZ#496044)

* it was possible for posix_locks_deadlock() to enter an infinite loop
(under the BKL), causing a system hang. (BZ#496842)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1337</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090473"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090474" severity="medium">
    <xccdf:title>RHSA-2009:0474: acpid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

Anthony de Almeida Lopes of Outpost24 AB reported a denial of service flaw
in the acpid daemon's error handling. If an attacker could exhaust the
sockets open to acpid, the daemon would enter an infinite loop, consuming
most CPU resources and preventing acpid from communicating with legitimate
processes. (CVE-2009-0798)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090476" severity="high">
    <xccdf:title>RHSA-2009:0476: pango security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

Will Drewry discovered an integer overflow flaw in Pango's
pango_glyph_string_set_size() function. If an attacker is able to pass an
arbitrarily long string to Pango, it may be possible to execute arbitrary
code with the permissions of the application calling Pango. (CVE-2009-1194)

pango and evolution28-pango users are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect. Note: Restarting the X server closes
all open applications and logs you out of your session.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1194</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090476"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090479" severity="medium">
    <xccdf:title>RHSA-2009:0479: perl-DBD-Pg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl DBI is a database access Application Programming Interface (API) for
the Perl language. perl-DBD-Pg allows Perl applications to access
PostgreSQL database servers.

A heap-based buffer overflow flaw was discovered in the pg_getline function
implementation. If the pg_getline or getline functions read large,
untrusted records from a database, it could cause an application using
these functions to crash or, possibly, execute arbitrary code.
(CVE-2009-0663)

Note: After installing this update, pg_getline may return more data than
specified by its second argument, as this argument will be ignored. This is
consistent with current upstream behavior. Previously, the length limit
(the second argument) was not enforced, allowing a buffer overflow.

A memory leak flaw was found in the function performing the de-quoting of
BYTEA type values acquired from a database. An attacker able to cause an
application using perl-DBD-Pg to perform a large number of SQL queries
returning BYTEA records, could cause the application to use excessive
amounts of memory or, possibly, crash. (CVE-2009-1341)

All users of perl-DBD-Pg are advised to upgrade to this updated package,
which contains backported patches to fix these issues. Applications using
perl-DBD-Pg must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0663</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1341</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090479"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090480" severity="high">
    <xccdf:title>RHSA-2009:0480: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0147, CVE-2009-1179, CVE-2009-1187, CVE-2009-1188)

Multiple buffer overflow flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in poppler's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause applications that use poppler (such as Evince) to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0166,
CVE-2009-1180)

Multiple input validation flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash when opened. (CVE-2009-0799,
CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1187</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3606</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090480"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090955" severity="medium">
    <xccdf:title>RHSA-2009:0955: nfs-utils security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils package provides a daemon for the kernel NFS server and
related tools, which provides a much higher level of performance than the
traditional Linux NFS server used by most users.

A flaw was found in the nfs-utils package provided by RHBA-2008:0742. The
nfs-utils package was missing TCP wrappers support, which could result in
an administrator believing they had access restrictions enabled when they
did not. (CVE-2008-1376)

This update also includes the following bug fixes:

* the "nfsstat" command now displays correct statistics. In previous
versions, performing more than 2^31 RPC calls could cause the "nfsstat"
command to incorrectly display the number of calls as "negative". This was
because "nfsstat" printed statistics from /proc/net/rpc/* files as signed
integers; with this version of nfs-utils, "nfsstat" now reads and prints
these statistics as unsigned integers. (BZ#404831)

* imapd upcalls now support zero-length reads and perform extra bounds
checking in gssd and svcgssd. This fixes a bug in previous versions that
could cause the rpc.imapd daemon to hang when communicating with the
kernel, which would halt any ID translation services. (BZ#448710)

* tcp_wrappers supported in nfs-utils now allows proper application of
hosts access rules defined in /etc/hosts.allow and /etc/hosts.deny. (BZ#494585)

* the nfs init script did not check whether SECURE_NFS was set to "yes"
before starting, stopping, or querying rpc.svcgssd. On systems where
SECURE_NFS was not set to "yes", the nfs init script could not start the
rpc.svcgssd daemon at the "service nfs start" command because the rpcsvcssd
init script would check the status of SECURE_NFS before starting the
daemon. However, at the "service nfs stop" or "service nfs restart"
commands, nfs init script would attempt to stop rpc.svcgssd and then report
a failure because the daemon was not running in the first place. These
error messages may have misled end-users into believing that there was a
genuine problem with their NFS configuration. This version of nfs-utils
contains a fix backported from Red Hat Enterprise Linux 5. nfs-utils now
checks the status of SECURE_NFS before the nfs init script attempts to
start, query or stop rpc.svcgssd and therefore, the irrelevant error
messages seen previously will not appear. (BZ#470423)

* the nfs init script is now fully compliant with Linux Standard Base Core
specifications. This update fixes a bug that prevented "/etc/init.d/nfs
start" from exiting properly if NFS was already running. (BZ#474570)

* /var/lib/nfs/statd/sm is now created with the proper user and group
whenever rpc.statd is called. In previous versions, some thread stack
conditions could incorrectly prevent rpc.statd from creating the
/var/lib/nfs/statd/sm file, which could cause "service nfslock start" to
fail. (BZ#479376)

All users of nfs-utils should upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1376</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090955"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20090981" severity="low">
    <xccdf:title>RHSA-2009:0981: util-linux security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux package contains a collection of basic system utilities,
such as fdisk and mount.

A log injection attack was found in util-linux when logging log in attempts
via the audit subsystem of the Linux kernel. A remote attacker could use
this flaw to modify certain parts of logged events, possibly hiding their
activities on a system. (CVE-2008-1926)

This updated package also fixes the following bugs:

* partitions created by VMware ESX™ were not included in the list of
recognized file systems used by fdisk. Consequently, if VMware ESX was
installed, "fdisk -l" returned "Unknown" for these partitions. With this
update, information regarding the VMKcore and VMFS partitions has been
added to the file systems list. On systems running VMware ESX, "fdisk -l"
now lists information about these partitions as expected. (BZ#447264)

* if a username was not set, the login command would fail with a
Segmentation fault. With this update, login lets the audit system handle
NULL usernames (it sends an AUDIT_USER_LOGIN message to the audit system in
the event there is no username set). (BZ#456213)

* the nfs(5) man page listed version 2 as the default. This is incorrect:
unless otherwise specified, the NFS client uses NFS version 3. The man page
has been corrected. (BZ#458539)

* in certain situations, backgrounded NFS mounts died shortly after being
backgrounded when the mount command was executed by the initlog command,
which, for example, would occur when running an init script, such as
running the "service netfs start" command. In these situations, running the
"ps -ef" command showed backgrounded NFS mounts disappearing shortly after
being backgrounded. In this updated package, backgrounded mount processes
detach from the controlling terminal, which resolves this issue.
(BZ#461488)

* if a new partition's starting cylinder was beyond one terabyte, fdisk
could not create the partition. This has been fixed. (BZ#471372)

* in rare cases "mount -a" ignored fstab order and tried to re-mount file
systems on mpath devices. With this update, mount honors fstab order even
in the rare cases reported. (BZ#472186)

* the "mount --move" command moved a file system's mount point as expected
(for example, /proc/mounts showed the changed mount point as expected) but
did not update /etc/mtab properly. With this update, the "mount --move"
command gathers all necessary information about the old mount point, copies
it to the new mount point and then deletes the old point, ensuring
/etc/mtab is updated properly. (BZ#485004)

Util-linux users are advised to upgrade to this updated package, which
addresses this vulnerability and resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1926</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20090981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091024" severity="high">
    <xccdf:title>RHSA-2009:1024: Red Hat Enterprise Linux 4.8 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security Fixes:

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* the Linux kernel implementation of the Network File System (NFS) did not
properly initialize the file name limit in the nfs_server data structure.
This flaw could possibly lead to a denial of service on a client mounting
an NFS share. (CVE-2009-1336, Moderate)

Bug Fixes and Enhancements:

Kernel Feature Support:

* added a new allowable value to "/proc/sys/kernel/wake_balance" to allow
the scheduler to run the thread on any available CPU rather than scheduling
it on the optimal CPU.
* added "max_writeback_pages" tunable parameter to /proc/sys/vm/ to allow
the maximum number of modified pages kupdate writes to disk, per iteration
per run.
* added "swap_token_timeout" tunable parameter to /proc/sys/vm/ to provide
a valid hold time for the swap out protection token.
* added diskdump support to sata_svw driver.
* limited physical memory to 64GB for 32-bit kernels running on systems
with more than 64GB of physical memory to prevent boot failures.
* improved reliability of autofs.
* added support for 'rdattr_error' in NFSv4 readdir requests.
* fixed various short packet handling issues for NFSv4 readdir and sunrpc.
* fixed several CIFS bugs.

Networking and IPv6 Enablement:

* added router solicitation support.
* enforced sg requires tx csum in ethtool.

Platform Support:

x86, AMD64, Intel 64, IBM System z

* added support for a new Intel chipset.
* added initialization vendor info in boot_cpu_data.
* added support for N_Port ID Virtualization (NPIV) for IBM System z guests
using zFCP.
* added HDMI support for some AMD and ATI chipsets.
* updated HDA driver in ALSA to latest upstream as of 2008-07-22.
* added support for affected_cpus for cpufreq.
* removed polling timer from i8042.
* fixed PM-Timer when using the ASUS A8V Deluxe motherboard.
* backported usbfs_mutex in usbfs.

64-bit PowerPC:

* updated eHEA driver from version 0078-04 to 0078-08.
* updated logging of checksum errors in the eHEA driver.

Network Driver Updates:

* updated forcedeth driver to latest upstream version 0.61.
* fixed various e1000 issues when using Intel ESB2 hardware.
* updated e1000e driver to upstream version 0.3.3.3-k6.
* updated igb to upstream version 1.2.45-k2.
* updated tg3 to upstream version 3.96.
* updated ixgbe to upstream version 1.3.18-k4.
* updated bnx2 to upstream version 1.7.9.
* updated bnx2x to upstream version 1.45.23.
* fixed bugs and added enhancements for the NetXen NX2031 and NX3031
products.
* updated Realtek r8169 driver to support newer network chipsets. All
variants of RTL810x/RTL8168(9) are now supported.

Storage Driver Updates:

* fixed various SCSI issues. Also, the SCSI sd driver now calls the
revalidate_disk wrapper.
* fixed a dmraid reduced I/O delay bug in certain configurations.
* removed quirk aac_quirk_scsi_32 for some aacraid controllers.
* updated FCP driver on IBM System z systems with support for
point-to-point connections.
* updated lpfc to version 8.0.16.46.
* updated megaraid_sas to version 4.01-RH1.
* updated MPT Fusion driver to version 3.12.29.00rh.
* updated qla2xxx firmware to 4.06.01 for 4GB/s and 8GB/s adapters.
* updated qla2xxx driver to version 8.02.09.00.04.08-d.
* fixed sata_nv in libsata to disable ADMA mode by default.

Miscellaneous Updates:

* upgraded OpenFabrics Alliance Enterprise Distribution (OFED) to version
1.4.
* added driver support and fixes for various Wacom tablets.

Users should install this update, which resolves these issues and adds
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1337</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091024"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091036" severity="high">
    <xccdf:title>RHSA-2009:1036: ipsec-tools security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon. An
unauthenticated, remote attacker could trigger a NULL pointer dereference
that could cause the racoon daemon to crash. (CVE-2009-1574)

Multiple memory leak flaws were found in the ipsec-tools racoon daemon. If
a remote attacker is able to make multiple connection attempts to the
racoon daemon, it was possible to cause the racoon daemon to consume all
available memory. (CVE-2009-1632)

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches to correct these issues. Users must restart the racoon
daemon for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1036</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1632</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091036"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091039" severity="high">
    <xccdf:title>RHSA-2009:1039: ntp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1252</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091039"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091040" severity="high">
    <xccdf:title>RHSA-2009:1040: ntp security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd or,
potentially, execute arbitrary code with the privileges of the "ntp" user.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq or, potentially, execute arbitrary code with
the privileges of the user running the ntpq command. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1252</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091040"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091060" severity="high">
    <xccdf:title>RHSA-2009:1060: pidgin security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)

A denial of service flaw was found in Pidgin's QQ protocol decryption
handler. When the QQ protocol decrypts packet information, heap data can be
overwritten, possibly causing Pidgin to crash. (CVE-2009-1374)

A flaw was found in the way Pidgin's PurpleCircBuffer object is expanded.
If the buffer is full when more data arrives, the data stored in this
buffer becomes corrupted. This corrupted data could result in confusing or
misleading data being presented to the user, or possibly crash Pidgin.
(CVE-2009-1375)

It was discovered that on 32-bit platforms, the Red Hat Security Advisory
RHSA-2008:0584 provided an incomplete fix for the integer overflow flaw
affecting Pidgin's MSN protocol handler. If a Pidgin client receives a
specially-crafted MSN message, it may be possible to execute arbitrary code
with the permissions of the user running Pidgin. (CVE-2009-1376)

Note: By default, when using an MSN account, only users on your buddy list
can send you messages. This prevents arbitrary MSN users from exploiting
this flaw.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1376</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091060"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091061" severity="high">
    <xccdf:title>RHSA-2009:1061: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0946</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091061"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091066" severity="high">
    <xccdf:title>RHSA-2009:1066: squirrelmail security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

A server-side code injection flaw was found in the SquirrelMail
"map_yp_alias" function. If SquirrelMail was configured to retrieve a
user's IMAP server address from a Network Information Service (NIS) server
via the "map_yp_alias" function, an unauthenticated, remote attacker using
a specially-crafted username could use this flaw to execute arbitrary code
with the privileges of the web server. (CVE-2009-1579)

Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. An
attacker could construct a carefully crafted URL, which once visited by an 
unsuspecting user, could cause the user's web browser to execute malicious
script in the context of the visited SquirrelMail web page. (CVE-2009-1578)

It was discovered that SquirrelMail did not properly sanitize Cascading
Style Sheets (CSS) directives used in HTML mail. A remote attacker could
send a specially-crafted email that could place mail content above
SquirrelMail's controls, possibly allowing phishing and cross-site
scripting attacks. (CVE-2009-1581)

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1579</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1581</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091066"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091075" severity="medium">
    <xccdf:title>RHSA-2009:1075: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the handling of compression structures between mod_ssl
and OpenSSL. If too many connections were opened in a short period of time,
all system memory and swap space would be consumed by httpd, negatively
impacting other processes, or causing a system crash. (CVE-2008-1678)

Note: The CVE-2008-1678 issue did not affect Red Hat Enterprise Linux 5
prior to 5.3. The problem was introduced via the RHBA-2009:0181 errata in
Red Hat Enterprise Linux 5.3, which upgraded OpenSSL to the newer 0.9.8e
version.

A flaw was found in the handling of the "Options" and "AllowOverride"
directives. In configurations using the "AllowOverride" directive with
certain "Options=" arguments, local users were not restricted from
executing commands from a Server-Side-Include script as intended.
(CVE-2009-1195)

All httpd users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Users must restart httpd for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1195</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091075"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091082" severity="high">
    <xccdf:title>RHSA-2009:1082: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. 

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting this issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0949</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091082"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091083" severity="high">
    <xccdf:title>RHSA-2009:1083: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. The CUPS
"pdftops" filter converts Portable Document Format (PDF) files to
PostScript. "pdftops" is based on Xpdf and the CUPS imaging library.

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

A use-after-free flaw was found in the CUPS scheduler directory services
routine, used to process data about available printers and printer classes.
An attacker could use this flaw to cause a denial of service (cupsd daemon
stop or crash). (CVE-2009-1196)

Multiple integer overflows flaws, leading to heap-based buffer overflows,
were found in the CUPS "pdftops" filter. An attacker could create a
malicious PDF file that would cause "pdftops" to crash or, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0791)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting the CVE-2009-0949 flaw, and Swen van Brussel for reporting
the CVE-2009-1196 flaw.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0949</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1196</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091083"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091095" severity="high">
    <xccdf:title>RHSA-2009:1095: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838,
CVE-2009-1841)

Multiple flaws were found in the processing of malformed, local file
content. If a user loaded malicious, local content via the file:// URL, it
was possible for that content to access other local data. (CVE-2009-1835,
CVE-2009-1839)

A script, privilege elevation flaw was found in the way Firefox loaded XML
User Interface Language (XUL) scripts. Firefox and certain add-ons could
load malicious content when certain policy checks did not happen.
(CVE-2009-1840)

A flaw was found in the way Firefox displayed certain Unicode characters in
International Domain Names (IDN). If an IDN contained invalid characters,
they may have been displayed as spaces, making it appear to the user that
they were visiting a trusted site. (CVE-2009-1834)

A flaw was found in the way Firefox handled error responses returned from
proxy servers. If an attacker is able to conduct a man-in-the-middle attack
against a Firefox instance that is using a proxy server, they may be able
to steal sensitive information from the site the user is visiting.
(CVE-2009-1836)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.11. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.11, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1832</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091095"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091096" severity="high">
    <xccdf:title>RHSA-2009:1096: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1392, CVE-2009-1833, CVE-2009-1838, CVE-2009-1841)

A flaw was found in the processing of malformed, local file content. If a
user loaded malicious, local content via the file:// URL, it was possible
for that content to access other local data. (CVE-2009-1835)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091096"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091100" severity="medium">
    <xccdf:title>RHSA-2009:1100: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A format string flaw was found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark. (CVE-2009-1210)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2009-1268, CVE-2009-1269, CVE-2009-1829)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.8, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1268</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1269</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1829</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091100"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091101" severity="medium">
    <xccdf:title>RHSA-2009:1101: cscope security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2006-4262, CVE-2009-0148, CVE-2009-1577)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-2541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1577</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091101"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091102" severity="medium">
    <xccdf:title>RHSA-2009:1102: cscope security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2009-0148)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-2541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0148</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091102"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091106" severity="high">
    <xccdf:title>RHSA-2009:1106: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* several flaws were found in the way the Linux kernel CIFS implementation
handles Unicode strings. CIFS clients convert Unicode strings sent by a
server to their local character sets, and then write those strings into
memory. If a malicious server sent a long enough string, it could write
past the end of the target memory region and corrupt other memory areas,
possibly leading to a denial of service or privilege escalation on the
client mounting the CIFS share. (CVE-2009-1439, CVE-2009-1633, Important)

* the Linux kernel Network File System daemon (nfsd) implementation did not
drop the CAP_MKNOD capability when handling requests from local,
unprivileged users. This flaw could possibly lead to an information leak or
privilege escalation. (CVE-2009-1072, Moderate)

* Frank Filz reported the NFSv4 client was missing a file permission check
for the execute bit in some situations. This could allow local,
unprivileged users to run non-executable files on NFSv4 mounted file
systems. (CVE-2009-1630, Moderate)

* a missing check was found in the hypervisor_callback() function in the
Linux kernel provided by the kernel-xen package. This could cause a denial
of service of a 32-bit guest if an application running in that guest
accesses a certain memory location in the kernel. (CVE-2009-1758, Moderate)

* a flaw was found in the AGPGART driver. The agp_generic_alloc_page() and
agp_generic_alloc_pages() functions did not zero out the memory pages they
allocate, which may later be available to user-space processes. This flaw
could possibly lead to an information leak. (CVE-2009-1192, Low)

Bug fixes:

* a race in the NFS client between destroying cached access rights and
unmounting an NFS file system could have caused a system crash. "Busy
inodes" messages may have been logged. (BZ#498653)

* nanosleep() could sleep several milliseconds less than the specified time
on Intel Itanium®-based systems. (BZ#500349)

* LEDs for disk drives in AHCI mode may have displayed a fault state when
there were no faults. (BZ#500120)

* ptrace_do_wait() reported tasks were stopped each time the process doing
the trace called wait(), instead of reporting it once. (BZ#486945)

* epoll_wait() may have caused a system lockup and problems for
applications. (BZ#497322)

* missing capabilities could possibly allow users with an fsuid other than
0 to perform actions on some file system types that would otherwise be
prevented. (BZ#497271)

* on NFS mounted file systems, heavy write loads may have blocked
nfs_getattr() for long periods, causing commands that use stat(2), such as
ls, to hang. (BZ#486926)

* in rare circumstances, if an application performed multiple O_DIRECT
reads per virtual memory page and also performed fork(2), the buffer
storing the result of the I/O may have ended up with invalid data.
(BZ#486921)

* when using GFS2, gfs2_quotad may have entered an uninterpretable sleep
state. (BZ#501742)

* with this update, get_random_int() is more random and no longer uses a
common seed value, reducing the possibility of predicting the values
returned. (BZ#499783)

* the "-fwrapv" flag was added to the gcc build options to prevent gcc from
optimizing away wrapping. (BZ#501751)

* a kernel panic when enabling and disabling iSCSI paths. (BZ#502916)

* using the Broadcom NetXtreme BCM5704 network device with the tg3 driver
caused high system load and very bad performance. (BZ#502837)

* "/proc/[pid]/maps" and "/proc/[pid]/smaps" can only be read by processes
able to use the ptrace() call on a given process; however, certain
information from "/proc/[pid]/stat" and "/proc/[pid]/wchan" could be used
to reconstruct memory maps. (BZ#499546)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1106</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1630</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1758</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3238</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091106"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091107" severity="medium">
    <xccdf:title>RHSA-2009:1107: apr-util security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>apr-util is a utility library used with the Apache Portable Runtime (APR).
It aims to provide a free library of C data structures and routines. This
library contains additional utility interfaces for APR; including support
for XML, LDAP, database interfaces, URI parsing, and more.

An off-by-one overflow flaw was found in the way apr-util processed a
variable list of arguments. An attacker could provide a specially-crafted
string as input for the formatted output conversion routine, which could,
on big-endian platforms, potentially lead to the disclosure of sensitive
information or a denial of service (application crash). (CVE-2009-1956)

Note: The CVE-2009-1956 flaw only affects big-endian platforms, such as the
IBM S/390 and PowerPC. It does not affect users using the apr-util package
on little-endian platforms, due to their different organization of byte
ordering used to represent particular data.

A denial of service flaw was found in the apr-util Extensible Markup
Language (XML) parser. A remote attacker could create a specially-crafted
XML document that would cause excessive memory consumption when processed
by the XML decoding engine. (CVE-2009-1955)

A heap-based underwrite flaw was found in the way apr-util created compiled
forms of particular search patterns. An attacker could formulate a
specially-crafted search keyword, that would overwrite arbitrary heap
memory locations when processed by the pattern preparation engine.
(CVE-2009-0023)

All apr-util users should upgrade to these updated packages, which contain
backported patches to correct these issues. Applications using the Apache
Portable Runtime library, such as httpd, must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1107</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1956</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091107"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091116" severity="high">
    <xccdf:title>RHSA-2009:1116: cyrus-imapd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and SIEVE support.

It was discovered that the Cyrus SASL library (cyrus-sasl) does not always
reliably terminate output from the sasl_encode64() function used by
programs using this library. The Cyrus IMAP server (cyrus-imapd) relied on
this function's output being properly terminated. Under certain conditions,
improperly terminated output from sasl_encode64() could, potentially, cause
cyrus-imapd to crash, disclose portions of its memory, or lead to SASL
authentication failures. (CVE-2009-0688)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which resolve this issue. After installing the update, cyrus-imapd will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0688</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091116"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091122" severity="medium">
    <xccdf:title>RHSA-2009:1122: icu security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A flaw was found in the way ICU processed certain, invalid byte sequences
during Unicode conversion. If an application used ICU to decode malformed,
multibyte character data, it may have been possible to bypass certain
content protection mechanisms, or display information in a manner
misleading to the user. (CVE-2009-0153)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0153</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091122"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091123" severity="medium">
    <xccdf:title>RHSA-2009:1123: gstreamer-plugins-good security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, good quality GStreamer plug-ins.

Multiple integer overflow flaws, that could lead to a buffer overflow, were
found in the GStreamer Good Plug-ins PNG decoding handler. An attacker
could create a specially-crafted PNG file that would cause an application
using the GStreamer Good Plug-ins library to crash or, potentially, execute
arbitrary code as the user running the application when parsed.
(CVE-2009-1932)

All users of gstreamer-plugins-good are advised to upgrade to these updated
packages, which contain a backported patch to correct these issues. After
installing the update, all applications using GStreamer Good Plug-ins (such
as some media playing applications) must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1932</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091123"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091125" severity="medium">
    <xccdf:title>RHSA-2009:1125: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-1392, CVE-2009-1303, CVE-2009-1305, CVE-2009-1833,
CVE-2009-1838)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing malicious content could execute
arbitrary JavaScript in the context of the mail message, possibly
presenting misleading data to the user, or stealing sensitive information
such as login credentials. (CVE-2009-1306, CVE-2009-1307, CVE-2009-1309)

Note: JavaScript support is disabled by default in Thunderbird. None of the
above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2210</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091125"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091126" severity="medium">
    <xccdf:title>RHSA-2009:1126: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-1392, CVE-2009-1303, CVE-2009-1305, CVE-2009-1833,
CVE-2009-1838)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing malicious content could execute
arbitrary JavaScript in the context of the mail message, possibly
presenting misleading data to the user, or stealing sensitive information
such as login credentials. (CVE-2009-1306, CVE-2009-1307, CVE-2009-1308,
CVE-2009-1309)

A flaw was found in the way Thunderbird handled error responses returned
from proxy servers. If an attacker is able to conduct a man-in-the-middle
attack against a Thunderbird instance that is using a proxy server, they
may be able to steal sensitive information from the site Thunderbird is
displaying. (CVE-2009-1836)

Note: JavaScript support is disabled by default in Thunderbird. None of the
above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2210</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091127" severity="high">
    <xccdf:title>RHSA-2009:1127: kdelibs security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A flaw was found in the way the KDE CSS parser handled content for the
CSS "style" attribute. A remote attacker could create a specially-crafted
CSS equipped HTML page, which once visited by an unsuspecting user, could
cause a denial of service (Konqueror crash) or, potentially, execute
arbitrary code with the privileges of the user running Konqueror.
(CVE-2009-1698)

A flaw was found in the way the KDE HTML parser handled content for the
HTML "head" element. A remote attacker could create a specially-crafted
HTML page, which once visited by an unsuspecting user, could cause a denial
of service (Konqueror crash) or, potentially, execute arbitrary code with
the privileges of the user running Konqueror. (CVE-2009-1690)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the KDE JavaScript garbage collector handled memory
allocation requests. A remote attacker could create a specially-crafted
HTML page, which once visited by an unsuspecting user, could cause a denial
of service (Konqueror crash) or, potentially, execute arbitrary code with
the privileges of the user running Konqueror. (CVE-2009-1687)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091127"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091130" severity="high">
    <xccdf:title>RHSA-2009:1130: kdegraphics security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop Environment
(KDE). Scalable Vector Graphics (SVG) is an XML-based language to describe
vector images. KSVG is a framework aimed at implementing the latest W3C SVG
specifications.

A use-after-free flaw was found in the KDE KSVG animation element
implementation. A remote attacker could create a specially-crafted SVG
image, which once opened by an unsuspecting user, could cause a denial of
service (Konqueror crash) or, potentially, execute arbitrary code with the
privileges of the user running Konqueror. (CVE-2009-1709)

A NULL pointer dereference flaw was found in the KDE, KSVG SVGList
interface implementation. A remote attacker could create a
specially-crafted SVG image, which once opened by an unsuspecting user,
would cause memory corruption, leading to a denial of service (Konqueror
crash). (CVE-2009-0945)

All users of kdegraphics should upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0945</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1709</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091130"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091132" severity="high">
    <xccdf:title>RHSA-2009:1132: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the Intel PRO/1000 network driver in the Linux
kernel. Frames with sizes near the MTU of an interface may be split across
multiple hardware receive descriptors. Receipt of such a frame could leak
through a validation check, leading to a corruption of the length check. A
remote attacker could use this flaw to send a specially-crafted packet that
would cause a denial of service. (CVE-2009-1385, Important)

* the Linux kernel Network File System daemon (nfsd) implementation did not
drop the CAP_MKNOD capability when handling requests from local,
unprivileged users. This flaw could possibly lead to an information leak or
privilege escalation. (CVE-2009-1072, Moderate)

* Frank Filz reported the NFSv4 client was missing a file permission check
for the execute bit in some situations. This could allow local,
unprivileged users to run non-executable files on NFSv4 mounted file
systems. (CVE-2009-1630, Moderate)

* a missing check was found in the hypervisor_callback() function in the
Linux kernel provided by the kernel-xen package. This could cause a denial
of service of a 32-bit guest if an application running in that guest
accesses a certain memory location in the kernel. (CVE-2009-1758, Moderate)

* a flaw was found in the AGPGART driver. The agp_generic_alloc_page() and
agp_generic_alloc_pages() functions did not zero out the memory pages they
allocate, which may later be available to user-space processes. This flaw
could possibly lead to an information leak. (CVE-2009-1192, Low)

These updated packages also fix the following bugs:

* "/proc/[pid]/maps" and "/proc/[pid]/smaps" can only be read by processes
able to use the ptrace() call on a given process; however, certain
information from "/proc/[pid]/stat" and "/proc/[pid]/wchan" could be used
to reconstruct memory maps, making it possible to bypass the Address Space
Layout Randomization (ASLR) security feature. This update addresses this
issue. (BZ#499549)

* in some situations, the link count was not decreased when renaming unused
files on NFS mounted file systems. This may have resulted in poor
performance. With this update, the link count is decreased in these
situations, the same as is done for other file operations, such as unlink
and rmdir. (BZ#501802)

* tcp_ack() cleared the probes_out variable even if there were outstanding
packets. When low TCP keepalive intervals were used, this bug may have
caused problems, such as connections terminating, when using remote tools
such as rsh and rlogin. (BZ#501754)

* off-by-one errors in the time normalization code could have caused
clock_gettime() to return one billion nanoseconds, rather than adding an
extra second. This bug could have caused the name service cache daemon
(nscd) to consume excessive CPU resources. (BZ#501800)

* a system panic could occur when one thread read "/proc/bus/input/devices"
while another was removing a device. With this update, a mutex has been
added to protect the input_dev_list and input_handler_list variables, which
resolves this issue. (BZ#501804)

* using netdump may have caused a kernel deadlock on some systems.
(BZ#504565)

* the file system mask, which lists capabilities for users with a file
system user ID (fsuid) of 0, was missing the CAP_MKNOD and
CAP_LINUX_IMMUTABLE capabilities. This could, potentially, allow users with
an fsuid other than 0 to perform actions on some file system types that
would otherwise be prevented. This update adds these capabilities. (BZ#497269)

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. Note:
The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1630</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1758</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091134" severity="high">
    <xccdf:title>RHSA-2009:1134: seamonkey security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way that SeaMonkey parsed malformed HTML mail
messages. If a user opened a specially-crafted HTML mail message, it could
cause SeaMonkey to crash or, possibly, to execute arbitrary code as the
user running SeaMonkey. (CVE-2009-2210)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2210</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091134"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091136" severity="high">
    <xccdf:title>RHSA-2009:1136: dhcp security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

The Mandriva Linux Engineering Team discovered a stack-based buffer
overflow flaw in the ISC DHCP client. If the DHCP client were to receive a
malicious DHCP response, it could crash or execute arbitrary code with the
permissions of the client (root). (CVE-2009-0692)

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0692</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091136"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091138" severity="high">
    <xccdf:title>RHSA-2009:1138: openswan security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Multiple insufficient input validation flaws were found in the way
Openswan's pluto IKE daemon processed some fields of X.509 certificates. A
remote attacker could provide a specially-crafted X.509 certificate that
would crash the pluto daemon. (CVE-2009-2185)

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2185</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091138"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091139" severity="medium">
    <xccdf:title>RHSA-2009:1139: pidgin security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for CommunicAtion in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

A denial of service flaw was found in the Pidgin OSCAR protocol
implementation. If a remote ICQ user sent a web message to a local Pidgin
user using this protocol, it would cause excessive memory usage, leading to
a denial of service (Pidgin crash). (CVE-2009-1889)

These updated packages also fix the following bug:

* the Yahoo! Messenger Protocol changed, making it incompatible (and
unusable) with Pidgin versions prior to 2.5.7. This update provides Pidgin
2.5.8, which implements version 16 of the Yahoo! Messenger Protocol, which
resolves this issue.

Note: These packages upgrade Pidgin to version 2.5.8. Refer to the Pidgin
release notes for a full list of changes:
http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1889</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091139"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091140" severity="medium">
    <xccdf:title>RHSA-2009:1140: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way the Ruby POP module processed certain APOP
authentication requests. By sending certain responses when the Ruby APOP
module attempted to authenticate using APOP against a POP server, a remote
attacker could, potentially, acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

It was discovered that Ruby did not properly check the return value when
verifying X.509 certificates. This could, potentially, allow a remote
attacker to present an invalid X.509 certificate, and have Ruby treat it as
valid. (CVE-2009-0642)

A flaw was found in the way Ruby converted BigDecimal objects to Float
numbers. If an attacker were able to provide certain input for the
BigDecimal object converter, they could crash an application using this
class. (CVE-2009-1904)

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1904</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091148" severity="high">
    <xccdf:title>RHSA-2009:1148: httpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A denial of service flaw was found in the Apache mod_proxy module when it
was used as a reverse proxy. A remote attacker could use this flaw to force
a proxy process to consume large amounts of CPU time. (CVE-2009-1890)

A denial of service flaw was found in the Apache mod_deflate module. This
module continued to compress large files until compression was complete,
even if the network connection that requested the content was closed before
compression completed. This would cause mod_deflate to consume large
amounts of CPU if mod_deflate was enabled for a large file. (CVE-2009-1891)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1891</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091148"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091159" severity="medium">
    <xccdf:title>RHSA-2009:1159: libtiff security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Several integer overflow flaws, leading to heap-based buffer overflows,
were found in various libtiff color space conversion tools. An attacker
could create a specially-crafted TIFF file, which once opened by an
unsuspecting user, would cause the conversion tool to crash or,
potentially, execute arbitrary code with the privileges of the user running
the tool. (CVE-2009-2347)

A buffer underwrite flaw was found in libtiff's Lempel-Ziv-Welch (LZW)
compression algorithm decoder. An attacker could create a specially-crafted
LZW-encoded TIFF file, which once opened by an unsuspecting user, would
cause an application linked with libtiff to access an out-of-bounds memory
location, leading to a denial of service (application crash).
(CVE-2009-2285)

The CVE-2009-2347 flaws were discovered by Tielei Wang from ICST-ERCIS,
Peking University.

All libtiff users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
all applications linked with the libtiff library (such as Konqueror) must
be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2347</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091159"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091162" severity="high">
    <xccdf:title>RHSA-2009:1162: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466,
CVE-2009-2467, CVE-2009-2469, CVE-2009-2471)

Several flaws were found in the way Firefox handles malformed JavaScript
code. A website containing malicious content could launch a cross-site
scripting (XSS) attack or execute arbitrary JavaScript with the permissions
of another website. (CVE-2009-2472)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.12. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.12, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2664</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091162"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091163" severity="high">
    <xccdf:title>RHSA-2009:1163: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-2462, CVE-2009-2463, CVE-2009-2466)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2470</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091164" severity="high">
    <xccdf:title>RHSA-2009:1164: tomcat security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that the Red Hat Security Advisory RHSA-2007:0871 did not
address all possible flaws in the way Tomcat handles certain characters and
character sequences in cookie values. A remote attacker could use this flaw
to obtain sensitive information, such as session IDs, and then use this
information for session hijacking attacks. (CVE-2007-5333)

Note: The fix for the CVE-2007-5333 flaw changes the default cookie
processing behavior: with this update, version 0 cookies that contain
values that must be quoted to be valid are automatically changed to version
1 cookies. To reactivate the previous, but insecure behavior, add the
following entry to the "/etc/tomcat5/catalina.properties" file:

org.apache.tomcat.util.http.ServerCookie.VERSION_SWITCH=false

It was discovered that request dispatchers did not properly normalize user
requests that have trailing query strings, allowing remote attackers to
send specially-crafted requests that would cause an information leak.
(CVE-2008-5515)

A flaw was found in the way the Tomcat AJP (Apache JServ Protocol)
connector processes AJP connections. An attacker could use this flaw to
send specially-crafted requests that would cause a temporary denial of
service. (CVE-2009-0033)

It was discovered that the error checking methods of certain authentication
classes did not have sufficient error checking, allowing remote attackers
to enumerate (via brute force methods) usernames registered with
applications running on Tomcat when FORM-based authentication was used.
(CVE-2009-0580)

A cross-site scripting (XSS) flaw was found in the examples calendar
application. With some web browsers, remote attackers could use this flaw
to inject arbitrary web script or HTML via the "time" parameter.
(CVE-2009-0781)

It was discovered that web applications containing their own XML parsers
could replace the XML parser Tomcat uses to parse configuration files. A
malicious web application running on a Tomcat instance could read or,
potentially, modify the configuration and XML-based data of other web
applications deployed on the same Tomcat instance. (CVE-2009-0783)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to resolve these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5333</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0783</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091176" severity="medium">
    <xccdf:title>RHSA-2009:1176: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

When the assert() system call was disabled, an input sanitization flaw was
revealed in the Python string object implementation that led to a buffer
overflow. The missing check for negative size values meant the Python
memory allocator could allocate less memory than expected. This could
result in arbitrary code execution with the Python interpreter's
privileges. (CVE-2008-1887)

Multiple buffer and integer overflow flaws were found in the Python Unicode
string processing and in the Python Unicode and string object
implementations. An attacker could use these flaws to cause a denial of
service (Python application crash). (CVE-2008-3142, CVE-2008-5031)

Multiple integer overflow flaws were found in the Python imageop module. If
a Python application used the imageop module to process untrusted images,
it could cause the application to disclose sensitive information, crash or,
potentially, execute arbitrary code with the Python interpreter's
privileges. (CVE-2007-4965, CVE-2008-4864)

Multiple integer underflow and overflow flaws were found in the Python
snprintf() wrapper implementation. An attacker could use these flaws to
cause a denial of service (memory corruption). (CVE-2008-3144)

Multiple integer overflow flaws were found in various Python modules. An
attacker could use these flaws to cause a denial of service (Python
application crash). (CVE-2008-2315, CVE-2008-3143)

An integer signedness error, leading to a buffer overflow, was found
in the Python zlib extension module. If a Python application requested
the negative byte count be flushed for a decompression stream, it could
cause the application to crash or, potentially, execute arbitrary code
with the Python interpreter's privileges. (CVE-2008-1721)

A flaw was discovered in the strxfrm() function of the Python locale
module. Strings generated by this function were not properly
NULL-terminated, which could possibly cause disclosure of data stored in
the memory of a Python application using this function. (CVE-2007-2052)

Red Hat would like to thank David Remahl of the Apple Product Security team
for responsibly reporting the CVE-2008-2315 issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4965</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1887</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2315</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5031</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091176"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091177" severity="medium">
    <xccdf:title>RHSA-2009:1177: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

When the assert() system call was disabled, an input sanitization flaw was
revealed in the Python string object implementation that led to a buffer
overflow. The missing check for negative size values meant the Python
memory allocator could allocate less memory than expected. This could
result in arbitrary code execution with the Python interpreter's
privileges. (CVE-2008-1887)

Multiple buffer and integer overflow flaws were found in the Python Unicode
string processing and in the Python Unicode and string object
implementations. An attacker could use these flaws to cause a denial of
service (Python application crash). (CVE-2008-3142, CVE-2008-5031)

Multiple integer overflow flaws were found in the Python imageop module. If
a Python application used the imageop module to process untrusted images,
it could cause the application to crash or, potentially, execute arbitrary
code with the Python interpreter's privileges. (CVE-2008-1679,
CVE-2008-4864)

Multiple integer underflow and overflow flaws were found in the Python
snprintf() wrapper implementation. An attacker could use these flaws to
cause a denial of service (memory corruption). (CVE-2008-3144)

Multiple integer overflow flaws were found in various Python modules. An
attacker could use these flaws to cause a denial of service (Python
application crash). (CVE-2008-2315, CVE-2008-3143)

An integer signedness error, leading to a buffer overflow, was found
in the Python zlib extension module. If a Python application requested
the negative byte count be flushed for a decompression stream, it could
cause the application to crash or, potentially, execute arbitrary code
with the Python interpreter's privileges. (CVE-2008-1721)

Red Hat would like to thank David Remahl of the Apple Product Security team
for responsibly reporting the CVE-2008-1679 and CVE-2008-2315 issues.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1887</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2315</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5031</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091177"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091179" severity="high">
    <xccdf:title>RHSA-2009:1179: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handles dynamic update message packets
containing the "ANY" record type. A remote attacker could use this flaw to
send a specially-crafted dynamic update packet that could cause named to
exit with an assertion failure. (CVE-2009-0696)

Note: even if named is not configured for dynamic updates, receiving such
a specially-crafted dynamic update packet could still cause named to exit
unexpectedly.

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091179"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091180" severity="high">
    <xccdf:title>RHSA-2009:1180: bind security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handles dynamic update message packets
containing the "ANY" record type. A remote attacker could use this flaw to
send a specially-crafted dynamic update packet that could cause named to
exit with an assertion failure. (CVE-2009-0696)

Note: even if named is not configured for dynamic updates, receiving such
a specially-crafted dynamic update packet could still cause named to exit
unexpectedly.

This update also fixes the following bug:

* when running on a system receiving a large number of (greater than 4,000)
DNS requests per second, the named DNS nameserver became unresponsive, and
the named service had to be restarted in order for it to continue serving
requests. This was caused by a deadlock occurring between two threads that
led to the inability of named to continue to service requests. This
deadlock has been resolved with these updated packages so that named no
longer becomes unresponsive under heavy load. (BZ#512668)

All BIND users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091184" severity="high">
    <xccdf:title>RHSA-2009:1184: nspr and nss security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities. These facilities include threads, thread
synchronization, normal file and network I/O, interval timing, calendar
time, basic memory management (malloc and free), and shared library linking.

Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv2, SSLv3, TLS,
and other security standards.

These updated packages upgrade NSS from the previous version, 3.12.2, to a
prerelease of version 3.12.4. The version of NSPR has also been upgraded
from 4.7.3 to 4.7.4. 

Moxie Marlinspike reported a heap overflow flaw in a regular expression
parser in the NSS library used by browsers such as Mozilla Firefox to match
common names in certificates. A malicious website could present a
carefully-crafted certificate in such a way as to trigger the heap
overflow, leading to a crash or, possibly, arbitrary code execution with
the permissions of the user running the browser. (CVE-2009-2404)

Note: in order to exploit this issue without further user interaction in
Firefox, the carefully-crafted certificate would need to be signed by a
Certificate Authority trusted by Firefox, otherwise Firefox presents the
victim with a warning that the certificate is untrusted. Only if the user
then accepts the certificate will the overflow take place.

Dan Kaminsky discovered flaws in the way browsers such as Firefox handle
NULL characters in a certificate. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
Firefox, the attacker could use the certificate during a man-in-the-middle
attack and potentially confuse Firefox into accepting it by mistake.
(CVE-2009-2408)

Dan Kaminsky found that browsers still accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. NSS
now disables the use of MD2 and MD4 algorithms inside signatures by
default. (CVE-2009-2409)

These version upgrades also provide a fix for the following bug:

* SSL client authentication failed against an Apache server when it was 
using the mod_nss module and configured for NSSOCSP. On the client side,
the user agent received an error message that referenced "Error Code:
-12271" and stated that establishing an encrypted connection had failed
because the certificate had been rejected by the host.

On the server side, the nss_error_log under /var/log/httpd/ contained the
following message:

[error] Re-negotiation handshake failed: Not accepted by client!?

Also, /var/log/httpd/error_log contained this error:

SSL Library Error: -8071 The OCSP server experienced an internal error

With these updated packages, the dependency problem which caused this
failure has been resolved so that SSL client authentication with an
Apache web server using mod_nss which is configured for NSSOCSP succeeds
as expected. Note that if the presented client certificate is expired,
then access is denied, the user agent is presented with an error message
about the invalid certificate, and the OCSP queries are seen in the OCSP
responder. Also, similar OCSP status verification happens for SSL server
certificates used in Apache upon instance start or restart. (BZ#508027)

All users of nspr and nss are advised to upgrade to these updated packages,
which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2404</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091184"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091186" severity="high">
    <xccdf:title>RHSA-2009:1186: nspr and nss security, bug fix, and enhancement update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities. These facilities include threads, thread
synchronization, normal file and network I/O, interval timing, calendar
time, basic memory management (malloc and free), and shared library linking.

Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv2, SSLv3, TLS,
and other security standards.

These updated packages upgrade NSS from the previous version, 3.12.2, to a
prerelease of version 3.12.4. The version of NSPR has also been upgraded
from 4.7.3 to 4.7.4. 

Moxie Marlinspike reported a heap overflow flaw in a regular expression
parser in the NSS library used by browsers such as Mozilla Firefox to match
common names in certificates. A malicious website could present a
carefully-crafted certificate in such a way as to trigger the heap
overflow, leading to a crash or, possibly, arbitrary code execution with
the permissions of the user running the browser. (CVE-2009-2404)

Note: in order to exploit this issue without further user interaction in
Firefox, the carefully-crafted certificate would need to be signed by a
Certificate Authority trusted by Firefox, otherwise Firefox presents the
victim with a warning that the certificate is untrusted. Only if the user
then accepts the certificate will the overflow take place.

Dan Kaminsky discovered flaws in the way browsers such as Firefox handle
NULL characters in a certificate. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
Firefox, the attacker could use the certificate during a man-in-the-middle
attack and potentially confuse Firefox into accepting it by mistake.
(CVE-2009-2408)

Dan Kaminsky found that browsers still accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. NSS
now disables the use of MD2 and MD4 algorithms inside signatures by
default. (CVE-2009-2409)

All users of nspr and nss are advised to upgrade to these updated packages,
which resolve these issues and add an enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2404</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091186"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091193" severity="high">
    <xccdf:title>RHSA-2009:1193: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* the possibility of a timeout value overflow was found in the Linux kernel
high-resolution timers functionality, hrtimers. This could allow a local,
unprivileged user to execute arbitrary code, or cause a denial of service
(kernel panic). (CVE-2007-5966, Important)

* a flaw was found in the Intel PRO/1000 network driver in the Linux
kernel. Frames with sizes near the MTU of an interface may be split across
multiple hardware receive descriptors. Receipt of such a frame could leak
through a validation check, leading to a corruption of the length check. A
remote attacker could use this flaw to send a specially-crafted packet that
would cause a denial of service or code execution. (CVE-2009-1385,
Important)

* Michael Tokarev reported a flaw in the Realtek r8169 Ethernet driver in
the Linux kernel. This driver allowed interfaces using this driver to
receive frames larger than could be handled, which could lead to a remote
denial of service or code execution. (CVE-2009-1389, Important)

* the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags were not cleared when a
setuid or setgid program was executed. A local, unprivileged user could use
this flaw to bypass the mmap_min_addr protection mechanism and perform a
NULL pointer dereference attack, or bypass the Address Space Layout
Randomization (ASLR) security feature. (CVE-2009-1895, Important)

* Ramon de Carvalho Valle reported two flaws in the Linux kernel eCryptfs
implementation. A local attacker with permissions to perform an eCryptfs
mount could modify the metadata of the files in that eCrypfts mount to
cause a buffer overflow, leading to a denial of service or privilege
escalation. (CVE-2009-2406, CVE-2009-2407, Important)

* Konstantin Khlebnikov discovered a race condition in the ptrace
implementation in the Linux kernel. This race condition can occur when the
process tracing and the process being traced participate in a core dump. A
local, unprivileged user could use this flaw to trigger a deadlock,
resulting in a partial denial of service. (CVE-2009-1388, Moderate)

Bug fixes (see References below for a link to more detailed notes):

* possible dom0 crash when a Xen para-virtualized guest was installed while
another para-virtualized guest was rebooting. (BZ#497812)

* no directory removal audit record if the directory and its subtree were
recursively watched by an audit rule. (BZ#507561)

* running "echo 1 &gt; /proc/sys/vm/drop_caches" under high memory load could
cause a kernel panic. (BZ#503692)

* on 32-bit systems, core dumps for some multithreaded applications did not
include all thread information. (BZ#505322)

* a stack buffer used by get_event_name() was too small for nul terminator
sprintf() writes. This could lead to an invalid pointer or kernel panic.
(BZ#506906)

* when using the aic94xx driver, systems with SATA drives may not boot due
to a libsas bug. (BZ#506029)

* Wacom Cintiq 21UX and Intuos stylus buttons were handled incorrectly when
moved away from and back to these tablets. (BZ#508275)

* CPU "soft lockup" messages and possibe system hangs on systems with
certain Broadcom network devices and running the Linux kernel from the
kernel-xen package. (BZ#503689)

* on 64-bit PowerPC, getitimer() failed for programs using the ITIMER_REAL
timer that were also compiled for 64-bit systems. This caused such programs
to abort. (BZ#510018)

* write operations could be blocked even when using O_NONBLOCK. (BZ#510239)

* the "pci=nomsi" option was required for installing and booting Red Hat
Enterprise Linux 5.2 on systems with VIA VT3364 chipsets. (BZ#507529)

* shutting down, destroying, or migrating Xen guests with large amounts of
memory could cause other guests to be temporarily unresponsive. (BZ#512311)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Systems must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1388</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1895</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2407</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091193"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091201" severity="high">
    <xccdf:title>RHSA-2009:1201: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way the XML Digital Signature implementation in the
JRE handled HMAC-based XML signatures. An attacker could use this flaw to
create a crafted signature that could allow them to bypass authentication,
or trick a user, applet, or application into accepting untrusted content.
(CVE-2009-0217)

Several potential information leaks were found in various mutable static
variables. These could be exploited in application scenarios that execute
untrusted scripting code. (CVE-2009-2475)

It was discovered that OpenType checks can be bypassed. This could allow a
rogue application to bypass access restrictions by acquiring references to
privileged objects through finalizer resurrection. (CVE-2009-2476)

A denial of service flaw was found in the way the JRE processes XML. A
remote attacker could use this flaw to supply crafted XML that would lead
to a denial of service. (CVE-2009-2625)

A flaw was found in the JRE audio system. An untrusted applet or
application could use this flaw to gain read access to restricted System
properties. (CVE-2009-2670)

Two flaws were found in the JRE proxy implementation. An untrusted applet
or application could use these flaws to discover the usernames of users
running applets and applications, or obtain web browser cookies and use
them for session hijacking attacks. (CVE-2009-2671, CVE-2009-2672)

An additional flaw was found in the proxy mechanism implementation. This
flaw allowed an untrusted applet or application to bypass access
restrictions and communicate using non-authorized socket or URL connections
to hosts other than the origin host. (CVE-2009-2673) 

An integer overflow flaw was found in the way the JRE processes JPEG
images. An untrusted application could use this flaw to extend its
privileges, allowing it to read and write local files, as well as to
execute local applications with the privileges of the user running the
application. (CVE-2009-2674)

An integer overflow flaw was found in the JRE unpack200 functionality. An
untrusted applet or application could extend its privileges, allowing it to
read and write local files, as well as to execute local applications with
the privileges of the user running the applet or application. (CVE-2009-2675)

It was discovered that JDK13Services grants unnecessary privileges to
certain object types. This could be misused by an untrusted applet or
application to use otherwise restricted functionality. (CVE-2009-2689)

An information disclosure flaw was found in the way private Java variables
were handled. An untrusted applet or application could use this flaw to
obtain information from variables that would otherwise be private.
(CVE-2009-2690)

Note: The flaws concerning applets in this advisory, CVE-2009-2475,
CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2675,
CVE-2009-2689, and CVE-2009-2690, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

This update also fixes the following bug:

* the EVR in the java-1.6.0-openjdk package as shipped with Red Hat
Enterprise Linux allowed the java-1.6.0-openjdk package from the EPEL
repository to take precedence (appear newer). Users using
java-1.6.0-openjdk from EPEL would not have received security updates since
October 2008. This update prevents the packages from EPEL from taking
precedence. (BZ#499079)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0217</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2672</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2690</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091201"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091203" severity="high">
    <xccdf:title>RHSA-2009:1203: subversion security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.

Matt Lewis, of Google, reported multiple heap overflow flaws in Subversion
(server and client) when parsing binary deltas. A malicious user with
commit access to a server could use these flaws to cause a heap overflow on
that server. A malicious server could use these flaws to cause a heap
overflow on a client when it attempts to checkout or update. These heap
overflows can result in a crash or, possibly, arbitrary code execution.
(CVE-2009-2411)

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091203"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091204" severity="medium">
    <xccdf:title>RHSA-2009:1204: apr and apr-util security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It aims to provide a free library
of C data structures and routines. apr-util is a utility library used with
APR. This library provides additional utility interfaces for APR; including
support for XML parsing, LDAP, database interfaces, URI parsing, and more.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way the Apache Portable Runtime (APR) manages memory pool
and relocatable memory allocations. An attacker could use these flaws to
issue a specially-crafted request for memory allocation, which would lead
to a denial of service (application crash) or, potentially, execute
arbitrary code with the privileges of an application using the APR
libraries. (CVE-2009-2412)

All apr and apr-util users should upgrade to these updated packages, which
contain backported patches to correct these issues. Applications using the
APR libraries, such as httpd, must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091204"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091206" severity="medium">
    <xccdf:title>RHSA-2009:1206: libxml and libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libxml is a library for parsing and manipulating XML files. A Document Type
Definition (DTD) defines the legal syntax (and also which elements can be
used) for certain types of files, such as XML files.

A stack overflow flaw was found in the way libxml processes the root XML
document element definition in a DTD. A remote attacker could provide a
specially-crafted XML file, which once opened by a local, unsuspecting
user, would lead to denial of service (application crash). (CVE-2009-2414)

Multiple use-after-free flaws were found in the way libxml parses the
Notation and Enumeration attribute types. A remote attacker could provide
a specially-crafted XML file, which once opened by a local, unsuspecting
user, would lead to denial of service (application crash). (CVE-2009-2416)

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues. For Red Hat Enterprise Linux 3, they
contain backported patches for the libxml and libxml2 packages. For Red Hat
Enterprise Linux 4 and 5, they contain backported patches for the libxml2
packages. The desktop must be restarted (log out, then log back in) for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2416</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091209" severity="medium">
    <xccdf:title>RHSA-2009:1209: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

Scott Cantor reported that cURL is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse cURL into accepting it by mistake. (CVE-2009-2417)

cURL users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2417</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091209"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091211" severity="high">
    <xccdf:title>RHSA-2009:1211: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* Michael Tokarev reported a flaw in the Realtek r8169 Ethernet driver in
the Linux kernel. This driver allowed interfaces using this driver to
receive frames larger than what could be handled. This could lead to a
remote denial of service or code execution. (CVE-2009-1389, Important)

* a buffer overflow flaw was found in the CIFSTCon() function of the Linux
kernel Common Internet File System (CIFS) implementation. When mounting a
CIFS share, a malicious server could send an overly-long string to the
client, possibly leading to a denial of service or privilege escalation on
the client mounting the CIFS share. (CVE-2009-1439, Important)

* several flaws were found in the way the Linux kernel CIFS implementation
handles Unicode strings. CIFS clients convert Unicode strings sent by a
server to their local character sets, and then write those strings into
memory. If a malicious server sent a long enough string, it could write
past the end of the target memory region and corrupt other memory areas,
possibly leading to a denial of service or privilege escalation on the
client mounting the CIFS share. (CVE-2009-1633, Important)

These updated packages also fix the following bugs:

* when using network bonding in the "balance-tlb" or "balance-alb" mode,
the primary setting for the primary slave device was lost when said
device was brought down (ifdown). Bringing the slave interface back up
(ifup) did not restore the primary setting (the device was not made the
active slave). (BZ#507563)

* a bug in timer_interrupt() may have caused the system time to move up to
two days or more into the future, or to be delayed for several minutes.
This bug only affected Intel 64 and AMD64 systems that have the High
Precision Event Timer (HPET) enabled in the BIOS, and could have caused
problems for applications that require timing to be accurate. (BZ#508835)

* a race condition was resolved in the Linux kernel block layer between
show_partition() and rescan_partitions(). This could have caused a NULL
pointer dereference in show_partition(), leading to a system crash (kernel
panic). This issue was most likely to occur on systems running monitoring
software that regularly scanned hard disk partitions, or from repeatedly
running commands that probe for partition information. (BZ#512310)

* previously, the Stratus memory tracker missed certain modified pages.
With this update, information about the type of page (small page or
huge page) is passed to the Stratus memory tracker, which resolves this
issue. The fix for this issue does not affect systems that do not use
memory tracking. (BZ#513182)

* a bug may have caused a system crash when using the cciss driver, due to
an uninitialized kernel structure. A reported case of this issue occurred
after issuing consecutive SCSI TUR commands (sg_turs sends SCSI
test-unit-ready commands in a loop). (BZ#513189)

* a bug in the SCSI implementation caused "Aborted Command - internal
target failure" errors to be sent to Device-Mapper Multipath, without
retries, resulting in Device-Mapper Multipath marking the path as failed
and making a path group switch. With this update, all errors that return a
sense key in the SCSI mid layer (including "Aborted Command - internal
target failure") are retried. (BZ#514007)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1633</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091211"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091218" severity="high">
    <xccdf:title>RHSA-2009:1218: pidgin security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Federico Muttis of Core Security Technologies discovered a flaw in Pidgin's
MSN protocol handler. If a user received a malicious MSN message, it was
possible to execute arbitrary code with the permissions of the user running
Pidgin. (CVE-2009-2694)

Note: Users can change their privacy settings to only allow messages from
users on their buddy list to limit the impact of this flaw.

These packages upgrade Pidgin to version 2.5.9. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which resolve
this issue. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2694</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091218"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091219" severity="high">
    <xccdf:title>RHSA-2009:1219: libvorbis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

An insufficient input validation flaw was found in the way libvorbis
processes the codec file headers (static mode headers and encoding books)
of the Ogg Vorbis audio file format (Ogg). A remote attacker could provide
a specially-crafted Ogg file that would cause a denial of service (memory
corruption and application crash) or, potentially, execute arbitrary code
with the privileges of an application using the libvorbis library when
opened by a victim. (CVE-2009-2663)

Users of libvorbis should upgrade to these updated packages, which contain
a backported patch to correct this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2663</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091219"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091222" severity="high">
    <xccdf:title>RHSA-2009:1222: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This
macro did not initialize the sendpage operation in the proto_ops structure
correctly. A local, unprivileged user could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2692, Important)

* a flaw was found in the udp_sendmsg() implementation in the Linux kernel
when using the MSG_MORE flag on UDP sockets. A local, unprivileged user
could use this flaw to cause a local denial of service or escalate their
privileges. (CVE-2009-2698, Important)

Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google
Security Team for responsibly reporting these flaws.

These updated packages also fix the following bug:

* in the dlm code, a socket was allocated in tcp_connect_to_sock(), but was
not freed in the error exit path. This bug led to a memory leak and an
unresponsive system. A reported case of this bug occurred after running
"cman_tool kill -n [nodename]". (BZ#515432)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2692</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091222"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091223" severity="high">
    <xccdf:title>RHSA-2009:1223: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This
macro did not initialize the sendpage operation in the proto_ops structure
correctly. A local, unprivileged user could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2692, Important)

* a flaw was found in the udp_sendmsg() implementation in the Linux kernel
when using the MSG_MORE flag on UDP sockets. A local, unprivileged user
could use this flaw to cause a local denial of service or escalate their
privileges. (CVE-2009-2698, Important)

Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google
Security Team for responsibly reporting these flaws.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2692</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091223"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091232" severity="medium">
    <xccdf:title>RHSA-2009:1232: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was discovered in the way GnuTLS handles NULL characters in certain
fields of X.509 certificates. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
an application using GnuTLS, the attacker could use the certificate during
a man-in-the-middle attack and potentially confuse the application into
accepting it by mistake. (CVE-2009-2730)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2730</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091232"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091238" severity="high">
    <xccdf:title>RHSA-2009:1238: dnsmasq security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dnsmasq is a lightweight and easy to configure DNS forwarder and DHCP
server.

Core Security Technologies discovered a heap overflow flaw in dnsmasq when
the TFTP service is enabled (the "--enable-tftp" command line option, or by
enabling "enable-tftp" in "/etc/dnsmasq.conf"). If the configured tftp-root
is sufficiently long, and a remote user sends a request that sends a long
file name, dnsmasq could crash or, possibly, execute arbitrary code with
the privileges of the dnsmasq service (usually the unprivileged "nobody"
user). (CVE-2009-2957)

A NULL pointer dereference flaw was discovered in dnsmasq when the TFTP
service is enabled. This flaw could allow a malicious TFTP client to crash
the dnsmasq service. (CVE-2009-2958)

Note: The default tftp-root is "/var/ftpd", which is short enough to make
it difficult to exploit the CVE-2009-2957 issue; if a longer directory name
is used, arbitrary code execution may be possible. As well, the dnsmasq
package distributed by Red Hat does not have TFTP support enabled by
default.

All users of dnsmasq should upgrade to this updated package, which contains
a backported patch to correct these issues. After installing the updated
package, the dnsmasq service must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2958</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091238"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091243" severity="high">
    <xccdf:title>RHSA-2009:1243: Red Hat Enterprise Linux 5.4 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* it was discovered that, when executing a new process, the clear_child_tid
pointer in the Linux kernel is not cleared. If this pointer points to a
writable portion of the memory of the new program, the kernel could corrupt
four bytes of memory, possibly leading to a local denial of service or
privilege escalation. (CVE-2009-2848, Important)

* a flaw was found in the way the do_sigaltstack() function in the Linux
kernel copies the stack_t structure to user-space. On 64-bit machines, this
flaw could lead to a four-byte information leak. (CVE-2009-2847, Moderate)

* a flaw was found in the ext4 file system code. A local attacker could use
this flaw to cause a denial of service by performing a resize operation on
a specially-crafted ext4 file system. (CVE-2009-0745, Low)

* multiple flaws were found in the ext4 file system code. A local attacker
could use these flaws to cause a denial of service by mounting a
specially-crafted ext4 file system. (CVE-2009-0746, CVE-2009-0747,
CVE-2009-0748, Low)

These updated packages also include several hundred bug fixes for and
enhancements to the Linux kernel. Space precludes documenting each of these
changes in this advisory and users are directed to the Red Hat Enterprise
Linux 5.4 Release Notes for information on the most significant of these
changes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.4/html/Release_Notes/

Also, for details concerning every bug fixed in and every enhancement added
to the kernel for this release, see the kernel chapter in the Red Hat
Enterprise Linux 5.4 Technical Notes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.4/html/Technical_Notes/kernel.html

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which address these vulnerabilities as well as fixing the bugs
and adding the enhancements noted in the Red Hat Enterprise Linux 5.4
Release Notes and Technical Notes. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0745</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2848</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091243"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091278" severity="low">
    <xccdf:title>RHSA-2009:1278: lftp security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LFTP is a sophisticated file transfer program for the FTP and HTTP
protocols. Like bash, it has job control and uses the readline library for
input. It has bookmarks, built-in mirroring, and can transfer several files
in parallel. It is designed with reliability in mind.

It was discovered that lftp did not properly escape shell metacharacters
when generating shell scripts using the "mirror --script" command. A
mirroring script generated to download files from a malicious FTP server
could allow an attacker controlling the FTP server to run an arbitrary
command as the user running lftp. (CVE-2007-2348)

This update also fixes the following bugs:

* when using the "mirror" or "get" commands with the "-c" option, lftp did
not check for some specific conditions that could result in the program
becoming unresponsive, hanging and the command not completing. For example,
when waiting for a directory listing, if lftp received a "226" message,
denoting an empty directory, it previously ignored the message and kept
waiting. With this update, these conditions are properly checked for and
lftp no longer hangs when "-c" is used with "mirror" or "get". (BZ#422881)

* when using the "put", "mput" or "reput" commands over a Secure FTP (SFTP)
connection, specifying the "-c" option sometimes resulted in corrupted
files of incorrect size. With this update, using these commands over SFTP
with the "-c" option works as expected, and transferred files are no
longer corrupted in the transfer process. (BZ#434294)

* previously, LFTP linked to the OpenSSL library. OpenSSL's license is,
however, incompatible with LFTP's GNU GPL license and LFTP does not include
an exception allowing OpenSSL linking. With this update, LFTP links to the
GnuTLS (GNU Transport Layer Security) library, which is released under the
GNU LGPL license. Like OpenSSL, GnuTLS implements the SSL and TLS
protocols, so functionality has not changed. (BZ#458777)

* running "help mirror" from within lftp only presented a sub-set of the
available options compared to the full list presented in the man page. With
this update, running "help mirror" in lftp presents the same list of mirror
options as is available in the Commands section of the lftp man page.
(BZ#461922)

* LFTP imports gnu-lib from upstream. Subsequent to gnu-lib switching from
GNU GPLv2 to GNU GPLv3, the LFTP license was internally inconsistent, with
LFTP licensed as GNU GPLv2 but portions of the package apparently licensed
as GNU GPLv3 because of changes made by the gnu-lib import. With this
update, LFTP itself switches to GNU GPLv3, resolving the inconsistency.
(BZ#468858)

* when the "ls" command was used within lftp to present a directory listing
on a remote system connected to via HTTP, file names containing spaces were
presented incorrectly. This update corrects this behavior. (BZ#504591)

* the default alias "edit" did not define a default editor. If EDITOR was
not set in advance by the system, lftp attempted to execute
"~/.lftp/edit.tmp.$$" (which failed because the file is not set to
executable). The edit alias also did not support tab-completion of file
names and incorrectly interpreted file names containing spaces. The updated
package defines a default editor (vi) in the absence of a system-defined
EDITOR. The edit alias now also supports tab-completion and handles file
names containing spaces correctly for both downloading and uploading.
(BZ#504594)

Note: This update upgrades LFTP from version 3.7.3 to upstream version
3.7.11, which incorporates a number of further bug fixes to those noted
above. For details regarding these fixes, refer to the
"/usr/share/doc/lftp-3.7.11/NEWS" file after installing this update.
(BZ#308721)

All LFTP users are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1278</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2348</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091278"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091287" severity="low">
    <xccdf:title>RHSA-2009:1287: openssh security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the SSH protocol. An attacker able to perform a
man-in-the-middle attack may be able to obtain a portion of plain text from
an arbitrary ciphertext block when a CBC mode cipher was used to encrypt
SSH communication. This update helps mitigate this attack: OpenSSH clients
and servers now prefer CTR mode ciphers to CBC mode, and the OpenSSH server
now reads SSH packets up to their full possible length when corruption is
detected, rather than reporting errors early, reducing the possibility of
successful plain text recovery. (CVE-2008-5161)

This update also fixes the following bug:

* the ssh client hung when trying to close a session in which a background
process still held tty file descriptors open. With this update, this
so-called "hang on exit" error no longer occurs and the ssh client closes
the session immediately. (BZ#454812)

In addition, this update adds the following enhancements:

* the SFTP server can now chroot users to various directories, including
a user's home directory, after log in. A new configuration option --
ChrootDirectory -- has been added to "/etc/ssh/sshd_config" for setting
this up (the default is not to chroot users). Details regarding configuring
this new option are in the sshd_config(5) manual page. (BZ#440240)

* the executables which are part of the OpenSSH FIPS module which is being
validated will check their integrity and report their FIPS mode status to
the system log or to the terminal. (BZ#467268, BZ#492363)

All OpenSSH users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add these
enhancements. After installing this update, the OpenSSH server daemon
(sshd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5161</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091287"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091289" severity="medium">
    <xccdf:title>RHSA-2009:1289: mysql security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

MySQL did not correctly check directories used as arguments for the DATA
DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated
attacker could elevate their access privileges to tables created by other
database users. Note: This attack does not work on existing tables. An
attacker can only elevate their access to another user's tables as the
tables are created. As well, the names of these created tables need to be
predicted correctly for this attack to succeed. (CVE-2008-2079)

A flaw was found in the way MySQL handles an empty bit-string literal. A
remote, authenticated attacker could crash the MySQL server daemon (mysqld)
if they used an empty bit-string literal in an SQL statement. This issue
only caused a temporary denial of service, as the MySQL daemon was
automatically restarted after the crash. (CVE-2008-3963)

An insufficient HTML entities quoting flaw was found in the mysql command
line client's HTML output mode. If an attacker was able to inject arbitrary
HTML tags into data stored in a MySQL database, which was later retrieved
using the mysql command line client and its HTML output mode, they could
perform a cross-site scripting (XSS) attack against victims viewing the
HTML output in a web browser. (CVE-2008-4456)

Multiple format string flaws were found in the way the MySQL server logs
user commands when creating and deleting databases. A remote, authenticated
attacker with permissions to CREATE and DROP databases could use these
flaws to formulate a specifically-crafted SQL command that would cause a
temporary denial of service (open connections to mysqld are terminated).
(CVE-2009-2446)

Note: To exploit the CVE-2009-2446 flaws, the general query log (the mysqld
"--log" command line option or the "log" option in "/etc/my.cnf") must be
enabled. This logging is not enabled by default.

This update also fixes multiple bugs. Details regarding these bugs can be
found in the Red Hat Enterprise Linux 5.4 Technical Notes. You can find a
link to the Technical Notes in the References section of this errata.

Note: These updated packages upgrade MySQL to version 5.0.77 to incorporate
numerous upstream bug fixes. Details of these changes are found in the
following MySQL Release Notes:
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-77.html

All MySQL users are advised to upgrade to these updated packages, which
resolve these issues. After installing this update, the MySQL server
daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3963</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2446</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091289"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091307" severity="low">
    <xccdf:title>RHSA-2009:1307: ecryptfs-utils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>eCryptfs is a stacked, cryptographic file system. It is transparent to the
underlying file system and provides per-file granularity.

eCryptfs is released as a Technology Preview for Red Hat Enterprise Linux
5.4. These updated ecryptfs-utils packages have been upgraded to upstream
version 75, which provides a number of bug fixes and enhancements over the
previous version. In addition, these packages provide a graphical program
to help configure and use eCryptfs. To start this program, run the command:

	ecryptfs-mount-helper-gui

Important: the syntax of certain eCryptfs mount options has changed. Users
who were previously using the initial Technology Preview release of
ecryptfs-utils are advised to refer to the ecryptfs(7) man page, and to
update any affected mount scripts and /etc/fstab entries for eCryptfs file
systems.

A disclosure flaw was found in the way the "ecryptfs-setup-private" script
passed passphrases to the "ecryptfs-wrap-passphrase" and
"ecryptfs-add-passphrase" commands as command line arguments. A local user
could obtain the passphrases of other users who were running the script
from the process listing. (CVE-2008-5188)

These updated packages provide various enhancements, including a mount
helper and supporting libraries to perform key management and mounting
functions.

Notable enhancements include:

* a new package, ecryptfs-utils-gui, has been added to this update. This
package depends on the pygtk2 and pygtk2-libglade packages and provides the
eCryptfs Mount Helper GUI program. To install the GUI, first install
ecryptfs-utils and then issue the following command:

	yum install ecryptfs-utils-gui

(BZ#500997)

* the "ecryptfs-rewrite-file" utility is now more intelligent when dealing
with non-existent files and with filtering special files such as the "."
directory. In addition, the progress output from "ecryptfs-rewrite-file"
has been improved and is now more explicit about the success status of each
target. (BZ#500813)

* descriptions of the "verbose" flag and the "verbosity=[x]" option, where
[x] is either 0 or 1, were missing from a number of eCryptfs manual pages,
and have been added. Refer to the eCryptfs man pages for important
information regarding using the verbose and/or verbosity options.
(BZ#470444)

These updated packages also fix the following bugs:

* mounting a directory using the eCryptfs mount helper with an RSA key that
was too small did not allow the eCryptfs mount helper to encrypt the entire
key. When this situation occurred, the mount helper did not display an
error message alerting the user to the fact that the key size was too
small, possibly leading to corrupted files. The eCryptfs mount helper now
refuses RSA keys which are to small to encrypt the eCryptfs key.
(BZ#499175)

* when standard input was redirected from /dev/null or was unavailable,
attempting to mount a directory with the eCryptfs mount helper caused it to
become unresponsive and eventually crash, or an "invalid value" error
message, depending on if the "--verbosity=[value]" option was provided as
an argument, and, if so, its value. With these updated packages, attempting
to mount a directory using "mount.ecryptfs" under the same conditions
results in either the mount helper attempting to use default values (if
"verbosity=0" is supplied), or an "invalid value" error message (instead of
the mount helper hanging) if standard input is redirected and
"--verbosity=1" is supplied, or that option is omitted entirely.
(BZ#499367)

* attempting to use the eCryptfs mount helper with an OpenSSL key when the
keyring did not contain enough space for the key resulted in an unhelpful
error message. The user is now alerted when this situation occurs.
(BZ#501460)

* the eCryptfs mount helper no longer fails upon receiving an incorrect or
empty answer to "yes/no" questions. (BZ#466210)

Users are advised to upgrade to these updated ecryptfs-utils packages,
which resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091321" severity="low">
    <xccdf:title>RHSA-2009:1321: nfs-utils security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils package provides a daemon for the kernel NFS server and
related tools.

It was discovered that nfs-utils did not use tcp_wrappers correctly.
Certain hosts access rules defined in "/etc/hosts.allow" and
"/etc/hosts.deny" may not have been honored, possibly allowing remote
attackers to bypass intended access restrictions. (CVE-2008-4552)

This updated package also fixes the following bugs:

* the "LOCKD_TCPPORT" and "LOCKD_UDPPORT" options in "/etc/sysconfig/nfs"
were not honored: the lockd daemon continued to use random ports. With this
update, these options are honored. (BZ#434795)

* it was not possible to mount NFS file systems from a system that has
the "/etc/" directory mounted on a read-only file system (this could occur
on systems with an NFS-mounted root file system). With this update, it is
possible to mount NFS file systems from a system that has "/etc/" mounted
on a read-only file system. (BZ#450646)

* arguments specified by "STATDARG=" in "/etc/sysconfig/nfs" were removed
by the nfslock init script, meaning the arguments specified were never
passed to rpc.statd. With this update, the nfslock init script no longer
removes these arguments. (BZ#459591)

* when mounting an NFS file system from a host not specified in the NFS
server's "/etc/exports" file, a misleading "unknown host" error was logged
on the server (the hostname lookup did not fail). With this update, a
clearer error message is provided for these situations. (BZ#463578)

* the nhfsstone benchmark utility did not work with NFS version 3 and 4.
This update adds support to nhfsstone for NFS version 3 and 4. The new
nhfsstone "-2", "-3", and "-4" options are used to select an NFS version
(similar to nfsstat(8)). (BZ#465933)

* the exportfs(8) manual page contained a spelling mistake, "djando", in
the EXAMPLES section. (BZ#474848)

* in some situations the NFS server incorrectly refused mounts to hosts
that had a host alias in a NIS netgroup. (BZ#478952)

* in some situations the NFS client used its cache, rather than using
the latest version of a file or directory from a given export. This update
adds a new mount option, "lookupcache=", which allows the NFS client to
control how it caches files and directories. Note: The Red Hat Enterprise
Linux 5.4 kernel update (the fourth regular update) must be installed in
order to use the "lookupcache=" option. Also, "lookupcache=" is currently
only available for NFS version 3. Support for NFS version 4 may be
introduced in future Red Hat Enterprise Linux 5 updates. Refer to Red Hat
Bugzilla #511312 for further information. (BZ#489335)

Users of nfs-utils should upgrade to this updated package, which contains
backported patches to correct these issues. After installing this update,
the nfs service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091321"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091335" severity="medium">
    <xccdf:title>RHSA-2009:1335: openssl security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a full-strength
general purpose cryptography library. Datagram TLS (DTLS) is a protocol
based on TLS that is capable of securing datagram transport (for example,
UDP).

Multiple denial of service flaws were discovered in OpenSSL's DTLS
implementation. A remote attacker could use these flaws to cause a DTLS
server to use excessive amounts of memory, or crash on an invalid memory
access or NULL pointer dereference. (CVE-2009-1377, CVE-2009-1378,
CVE-2009-1379, CVE-2009-1386, CVE-2009-1387)

Note: These flaws only affect applications that use DTLS. Red Hat does not
ship any DTLS client or server applications in Red Hat Enterprise Linux.

An input validation flaw was found in the handling of the BMPString and
UniversalString ASN1 string types in OpenSSL's ASN1_STRING_print_ex()
function. An attacker could use this flaw to create a specially-crafted
X.509 certificate that could cause applications using the affected function
to crash when printing certificate contents. (CVE-2009-0590)

Note: The affected function is rarely used. No application shipped with Red
Hat Enterprise Linux calls this function, for example.

These updated packages also fix the following bugs:

* "openssl smime -verify -in" verifies the signature of the input file and
the "-verify" switch expects a signed or encrypted input file. Previously,
running openssl on an S/MIME file that was not encrypted or signed caused
openssl to segfault. With this update, the input file is now checked for a
signature or encryption. Consequently, openssl now returns an error and
quits when attempting to verify an unencrypted or unsigned S/MIME file.
(BZ#472440)

* when generating RSA keys, pairwise tests were called even in non-FIPS
mode. This prevented small keys from being generated. With this update,
generating keys in non-FIPS mode no longer calls the pairwise tests and
keys as small as 32-bits can be generated in this mode. Note: In FIPS mode,
pairwise tests are still called and keys generated in this mode must still
be 1024-bits or larger. (BZ#479817)

As well, these updated packages add the following enhancements:

* both the libcrypto and libssl shared libraries, which are part of the
OpenSSL FIPS module, are now checked for integrity on initialization of
FIPS mode. (BZ#475798)

* an issuing Certificate Authority (CA) allows multiple certificate
templates to inherit the CA's Common Name (CN). Because this CN is used as
a unique identifier, each template had to have its own Certificate
Revocation List (CRL). With this update, multiple CRLs with the same
subject name can now be stored in a X509_STORE structure, with their
signature field being used to distinguish between them. (BZ#457134)

* the fipscheck library is no longer needed for rebuilding the openssl
source RPM. (BZ#475798)

OpenSSL users should upgrade to these updated packages, which resolve these
issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1335</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7250</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1387</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091335"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091337" severity="low">
    <xccdf:title>RHSA-2009:1337: gfs2-utils security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gfs2-utils package provides the user-space tools necessary to mount,
create, maintain, and test GFS2 file systems.

Multiple insecure temporary file use flaws were discovered in GFS2 user
level utilities. A local attacker could use these flaws to overwrite an
arbitrary file writable by a victim running those utilities (typically
root) with the output of the utilities via a symbolic link attack.
(CVE-2008-6552)

This update also fixes the following bugs:

* gfs2_fsck now properly detects and repairs problems with sequence numbers
on GFS2 file systems.

* GFS2 user utilities now use the file system UUID.

* gfs2_grow now properly updates the file system size during operation.

* gfs2_fsck now returns the proper exit codes.

* gfs2_convert now properly frees blocks when removing free blocks up to
height 2.

* the gfs2_fsck manual page has been renamed to fsck.gfs2 to match current
standards.

* the 'gfs2_tool df' command now provides human-readable output.

* mounting GFS2 file systems with the noatime or noquota option now works
properly.

* new capabilities have been added to the gfs2_edit tool to help in testing
and debugging GFS and GFS2 issues.

* the 'gfs2_tool df' command no longer segfaults on file systems with a
block size other than 4k.

* the gfs2_grow manual page no longer references the '-r' option, which has
been removed.

* the 'gfs2_tool unfreeze' command no longer hangs during use.

* gfs2_convert no longer corrupts file systems when converting from GFS to
GFS2.

* gfs2_fsck no longer segfaults when encountering a block which is listed
as both a data and stuffed directory inode.

* gfs2_fsck can now fix file systems even if the journal is already locked
for use.

* a GFS2 file system's metadata is now properly copied with 'gfs2_edit
savemeta' and 'gfs2_edit restoremeta'.

* the gfs2_edit savemeta function now properly saves blocks of type 2.

* 'gfs2_convert -vy' now works properly on the PowerPC architecture.

* when mounting a GFS2 file system as '/', mount_gfs2 no longer fails after
being unable to find the file system in '/proc/mounts'.

* gfs2_fsck no longer segfaults when fixing 'EA leaf block type' problems.

All gfs2-utils users should upgrade to this updated package, which resolves
these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091337"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091339" severity="low">
    <xccdf:title>RHSA-2009:1339: rgmanager security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rgmanager package contains the Red Hat Resource Group Manager, which
provides high availability for critical server applications in the event of
system downtime.

Multiple insecure temporary file use flaws were discovered in rgmanager and
various resource scripts run by rgmanager. A local attacker could use these
flaws to overwrite an arbitrary file writable by the rgmanager process
(i.e. user root) with the output of rgmanager or a resource agent via a
symbolic link attack. (CVE-2008-6552)

This update also fixes the following bugs:

* clulog now accepts '-' as the first character in messages.

* if expire_time is 0, max_restarts is no longer ignored.

* the SAP resource agents included in the rgmanager package shipped with
Red Hat Enterprise Linux 5.3 were outdated. This update includes the most
recent SAP resource agents and, consequently, improves SAP failover
support.

* empty PID files no longer cause resource start failures.

* recovery policy of type 'restart' now works properly when using a
resource based on ra-skelet.sh.

* samba.sh has been updated to kill the PID listed in the proper PID file.

* handling of the '-F' option has been improved to fix issues causing
rgmanager to crash if no members of a restricted failover domain were
online.

* the number of simultaneous status checks can now be limited to prevent
load spikes.

* forking and cloning during status checks has been optimized to reduce
load spikes.

* rg_test no longer hangs when run with large cluster configuration files.

* when rgmanager is used with a restricted failover domain it will no
longer occasionally segfault when some nodes are offline during a failover
event.

* virtual machine guests no longer restart after a cluster.conf update.

* nfsclient.sh no longer leaves temporary files after running.

* extra checks from the Oracle agents have been removed.

* vm.sh now uses libvirt.

* users can now define an explicit service processing order when
central_processing is enabled.

* virtual machine guests can no longer start on 2 nodes at the same time.

* in some cases a successfully migrated virtual machine guest could restart
when the cluster.conf file was updated.

* incorrect reporting of a service being started when it was not started
has been addressed.

As well, this update adds the following enhancements:

* a startup_wait option has been added to the MySQL resource agent.

* services can now be prioritized.

* rgmanager now checks to see if it has been killed by the OOM killer and
if so, reboots the node.

Users of rgmanager are advised to upgrade to this updated package, which
resolves these issues and adds these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091339"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091341" severity="low">
    <xccdf:title>RHSA-2009:1341: cman security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Cluster Manager (cman) utility provides services for managing a Linux
cluster.

Multiple insecure temporary file use flaws were found in fence_apc_snmp and
ccs_tool. A local attacker could use these flaws to overwrite an arbitrary
file writable by a victim running those utilities (typically root) with
the output of the utilities via a symbolic link attack. (CVE-2008-4579,
CVE-2008-6552)

Bug fixes:

* a buffer could overflow if cluster.conf had more than 52 entries per
block inside the &lt;cman&gt; block. The limit is now 1024.

* the output of the group_tool dump subcommands were NULL padded.

* using device="" instead of label="" no longer causes qdiskd to
incorrectly exit.

* the IPMI fencing agent has been modified to time out after 10 seconds. It
is also now possible to specify a different timeout value with the '-t'
option.

* the IPMI fencing agent now allows punctuation in passwords.

* quickly starting and stopping the cman service no longer causes the
cluster membership to become inconsistent across the cluster.

* an issue with lock syncing caused 'receive_own from' errors to be logged
to '/var/log/messages'.

* an issue which caused gfs_controld to segfault when mounting hundreds of
file systems has been fixed.

* the LPAR fencing agent now properly reports status when an LPAR is in
Open Firmware mode.

* the LPAR fencing agent now works properly with systems using the
Integrated Virtualization Manager (IVM).

* the APC SNMP fencing agent now properly recognizes outletStatusOn and
outletStatusOff return codes from the SNMP agent.

* the WTI fencing agent can now connect to fencing devices with no
password.

* the rps-10 fencing agent now properly performs a reboot when run with no
options.

* the IPMI fencing agent now supports different cipher types with the '-C'
option.

* qdisk now properly scans devices and partitions.

* cman now checks to see if a new node has state to prevent killing the
first node during cluster setup.

* 'service qdiskd start' now works properly.

* the McData fence agent now works properly with the McData Sphereon 4500
Fabric Switch.

* the Egenera fence agent can now specify an SSH login name.

* the APC fence agent now works with non-admin accounts when using the
3.5.x firmware.

* fence_xvmd now tries two methods to reboot a virtual machine.

* connections to OpenAIS are now allowed from unprivileged CPG clients with
the user and group of 'ais'.

* groupd no longer allows the default fence domain to be '0', which
previously caused rgmanager to hang. Now, rgmanager no longer hangs.

* the RSA fence agent now supports SSH enabled RSA II devices.

* the DRAC fence agent now works with the Integrated Dell Remote Access
Controller (iDRAC) on Dell PowerEdge M600 blade servers.

* fixed a memory leak in cman.

* qdisk now displays a warning if more than one label is found with the
same name.

* the DRAC5 fencing agent now shows proper usage instructions for the '-D'
option.

* cman no longer uses the wrong node name when getnameinfo() fails.

* the SCSI fence agent now verifies that sg_persist is installed.

* the DRAC5 fencing agent now properly handles modulename.

* QDisk now logs warning messages if it appears its I/O to shared storage
is hung.

* fence_apc no longer fails with a pexpect exception.

* removing a node from the cluster using 'cman_tool leave remove' now
properly reduces the expected_votes and quorum.

* a semaphore leak in cman has been fixed.

* 'cman_tool nodes -F name' no longer segfaults when a node is out of
membership.

Enhancements:

* support for: ePowerSwitch 8+ and LPAR/HMC v3 devices, Cisco MDS 9124 and
MDS 9134 SAN switches, the virsh fencing agent, and broadcast communication
with cman.

* fence_scsi limitations added to fence_scsi man page.

Users of cman are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4579</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-6552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091341"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091364" severity="low">
    <xccdf:title>RHSA-2009:1364: gdm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNOME Display Manager (GDM) is a configurable re-implementation of XDM,
the X Display Manager. GDM allows you to log in to your system with the X
Window System running, and supports running several different X sessions on
your local machine at the same time.

A flaw was found in the way the gdm package was built. The gdm package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2009-2697)

This update also fixes the following bugs:

* the GDM Reference Manual is now included with the gdm packages. The
gdm-docs package installs this document in HTML format in
"/usr/share/doc/". (BZ#196054)

* GDM appeared in English on systems using Telugu (te_IN). With this
update, GDM has been localized in te_IN. (BZ#226931)

* the Ctrl+Alt+Backspace sequence resets the X server when in runlevel 5.
In previous releases, however, repeated use of this sequence prevented GDM
from starting the X server as part of the reset process. This was because
GDM sometimes did not notice the X server shutdown properly and would
subsequently fail to complete the reset process. This update contains an
added check to explicitly notify GDM whenever the X server is terminated,
ensuring that resets are executed reliably. (BZ#441971)

* the "gdm" user is now part of the "audio" group by default. This enables
audio support at the login screen. (BZ#458331)

* the gui/modules/dwellmouselistener.c source code contained incorrect
XInput code that prevented tablet devices from working properly. This
update removes the errant code, ensuring that tablet devices work as
expected. (BZ#473262)

* a bug in the XOpenDevice() function prevented the X server from starting
whenever a device defined in "/etc/X11/xorg.conf" was not actually plugged
in. This update wraps XOpenDevice() in the gdk_error_trap_pop() and
gdk_error_trap_push() functions, which resolves this bug. This ensures that
the X server can start properly even when devices defined in
"/etc/X11/xorg.conf" are not plugged in. (BZ#474588)

All users should upgrade to these updated packages, which resolve these
issues. GDM must be restarted for this update to take effect. Rebooting
achieves this, but changing the runlevel from 5 to 3 and back to 5 also
restarts GDM.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2697</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091364"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091426" severity="high">
    <xccdf:title>RHSA-2009:1426: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parses certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by an
unsuspecting user, could cause OpenOffice.org to crash or, potentially,
execute arbitrary code with the permissions of the user running
OpenOffice.org. (CVE-2009-0200, CVE-2009-0201)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0201</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091426"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091427" severity="medium">
    <xccdf:title>RHSA-2009:1427: fetchmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links, such as SLIP and PPP connections.

It was discovered that fetchmail is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse fetchmail into accepting it by mistake. (CVE-2009-2666)

A flaw was found in the way fetchmail handles rejections from a remote SMTP
server when sending warning mail to the postmaster. If fetchmail sent a
warning mail to the postmaster of an SMTP server and that SMTP server
rejected it, fetchmail could crash. (CVE-2007-4565)

A flaw was found in fetchmail. When fetchmail is run in double verbose
mode ("-v -v"), it could crash upon receiving certain, malformed mail
messages with long headers. A remote attacker could use this flaw to cause
a denial of service if fetchmail was also running in daemon mode ("-d").
(CVE-2008-2711)

Note: when using SSL-enabled services, it is recommended that the fetchmail
"--sslcertck" option be used to enforce strict SSL certificate checking.

All fetchmail users should upgrade to this updated package, which contains
backported patches to correct these issues. If fetchmail is running in
daemon mode, it must be restarted for this update to take effect (use the
"fetchmail --quit" command to stop the fetchmail process).</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2666</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091427"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091428" severity="medium">
    <xccdf:title>RHSA-2009:1428: xmlsec1 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The XML Security Library is a C library based on libxml2 and OpenSSL. It
implements the XML Signature Syntax and Processing and XML Encryption
Syntax and Processing standards. HMAC is used for message authentication
using cryptographic hash functions. The HMAC algorithm allows the hash
output to be truncated (as documented in RFC 2104).

A missing check for the recommended minimum length of the truncated form of
HMAC-based XML signatures was found in xmlsec1. An attacker could use this
flaw to create a specially-crafted XML file that forges an XML signature,
allowing the attacker to bypass authentication that is based on the XML
Signature specification. (CVE-2009-0217)

Users of xmlsec1 should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, applications that use the XML Security Library must be restarted
for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0217</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091428"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091430" severity="high">
    <xccdf:title>RHSA-2009:1430: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074,
CVE-2009-3075)

A use-after-free flaw was found in Firefox. An attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code with the
privileges of the user running Firefox. (CVE-2009-3077)

A flaw was found in the way Firefox handles malformed JavaScript. A website
with an object containing malicious JavaScript could execute that
JavaScript with the privileges of the user running Firefox. (CVE-2009-3079)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3076)

A flaw was found in the way Firefox displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

A flaw was found in the way Firefox displays certain Unicode characters. An
attacker could use this flaw to conceal a malicious URL, possibly tricking
a user into believing they are viewing a trusted site. (CVE-2009-3078)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.14. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.14, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3079</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091430"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091431" severity="high">
    <xccdf:title>RHSA-2009:1431: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3072, CVE-2009-3075)

A use-after-free flaw was found in SeaMonkey. An attacker could use this
flaw to crash SeaMonkey or, potentially, execute arbitrary code with the
privileges of the user running SeaMonkey. (CVE-2009-3077)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3076)

A flaw was found in the way SeaMonkey displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3077</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091431"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091438" severity="high">
    <xccdf:title>RHSA-2009:1438: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security issues:

* the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags were not cleared when a
setuid or setgid program was executed. A local, unprivileged user could use
this flaw to bypass the mmap_min_addr protection mechanism and perform a
NULL pointer dereference attack, or bypass the Address Space Layout
Randomization (ASLR) security feature. (CVE-2009-1895, Important)

* it was discovered that, when executing a new process, the clear_child_tid
pointer in the Linux kernel is not cleared. If this pointer points to a
writable portion of the memory of the new program, the kernel could corrupt
four bytes of memory, possibly leading to a local denial of service or
privilege escalation. (CVE-2009-2848, Important)

* Solar Designer reported a missing capability check in the z90crypt driver
in the Linux kernel. This missing check could allow a local user with an
effective user ID (euid) of 0 to bypass intended capability restrictions.
(CVE-2009-1883, Moderate)

* a flaw was found in the way the do_sigaltstack() function in the Linux
kernel copies the stack_t structure to user-space. On 64-bit machines, this
flaw could lead to a four-byte information leak. (CVE-2009-2847, Moderate)

Bug fixes:

* the gcc flag "-fno-delete-null-pointer-checks" was added to the kernel
build options. This prevents gcc from optimizing out NULL pointer checks
after the first use of a pointer. NULL pointer bugs are often exploited by
attackers. Keeping these checks is a safety measure. (BZ#517964)

* the Emulex LPFC driver has been updated to version 8.0.16.47, which fixes
a memory leak that caused memory allocation failures and system hangs.
(BZ#513192)

* an error in the MPT Fusion driver makefile caused CSMI ioctls to not work
with Serial Attached SCSI devices. (BZ#516184)

* this update adds the mmap_min_addr tunable and restriction checks to help
prevent unprivileged users from creating new memory mappings below the
minimum address. This can help prevent the exploitation of NULL pointer
deference bugs. Note that mmap_min_addr is set to zero (disabled) by
default for backwards compatibility. (BZ#517904)

* time-outs resulted in I/O errors being logged to "/var/log/messages" when
running "mt erase" on tape drives using certain LSI MegaRAID SAS adapters,
preventing the command from completing. The megaraid_sas driver's timeout
value is now set to the OS layer value. (BZ#517965)

* a locking issue caused the qla2xxx ioctl module to hang after
encountering errors. This locking issue has been corrected. This ioctl
module is used by the QLogic SAN management tools, such as SANsurfer and
scli. (BZ#519428)

* when a RAID 1 array that uses the mptscsi driver and the LSI 1030
controller became degraded, the whole array was detected as being offline,
which could cause kernel panics at boot or data loss. (BZ#517295)

* on 32-bit architectures, if a file was held open and frequently written
for more than 25 days, it was possible that the kernel would stop flushing
those writes to storage. (BZ#515255)

* a memory allocation bug in ib_mthca prevented the driver from loading if
it was loaded with large values for the "num_mpt=" and "num_mtt=" options.
See Kbase link below for details. (BZ#518707)

* with this update, get_random_int() is more random and no longer uses a
common seed value, reducing the possibility of predicting the values
returned. See Kbase link below for details. (BZ#519692)

* a bug in __ptrace_unlink() caused it to create deadlocked and unkillable
processes. See Kbase link below for details. (BZ#519446)

* previously, multiple threads using the fcntl() F_SETLK command to
synchronize file access caused a deadlock in posix_locks_deadlock(). This
could cause a system hang. (BZ#519429)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Reboot the system for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1895</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3238</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091438"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091451" severity="medium">
    <xccdf:title>RHSA-2009:1451: freeradius security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.

An input validation flaw was discovered in the way FreeRADIUS decoded
specific RADIUS attributes from RADIUS packets. A remote attacker could use
this flaw to crash the RADIUS daemon (radiusd) via a specially-crafted
RADIUS packet. (CVE-2009-3111)

Users of FreeRADIUS are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, radiusd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3111</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091451"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091452" severity="medium">
    <xccdf:title>RHSA-2009:1452: neon security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>neon is an HTTP and WebDAV client library, with a C interface. It provides
a high-level interface to HTTP and WebDAV methods along with a low-level
interface for HTTP request handling. neon supports persistent connections,
proxy servers, basic, digest and Kerberos authentication, and has complete
SSL support.

It was discovered that neon is affected by the previously published "null
prefix attack", caused by incorrect handling of NULL characters in X.509
certificates. If an attacker is able to get a carefully-crafted certificate
signed by a trusted Certificate Authority, the attacker could use the
certificate during a man-in-the-middle attack and potentially confuse an
application using the neon library into accepting it by mistake.
(CVE-2009-2474)

A denial of service flaw was found in the neon Extensible Markup Language
(XML) parser. A remote attacker (malicious DAV server) could provide a
specially-crafted XML document that would cause excessive memory and CPU
consumption if an application using the neon XML parser was tricked into
processing it. (CVE-2009-2473)

All neon users should upgrade to these updated packages, which contain
backported patches to correct these issues. Applications using the neon
HTTP and WebDAV client library, such as cadaver, must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2474</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091452"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091453" severity="medium">
    <xccdf:title>RHSA-2009:1453: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. Info/Query
(IQ) is an Extensible Messaging and Presence Protocol (XMPP) specific
request-response mechanism.

A NULL pointer dereference flaw was found in the way the Pidgin XMPP
protocol plug-in processes IQ error responses when trying to fetch a custom
smiley. A remote client could send a specially-crafted IQ error response
that would crash Pidgin. (CVE-2009-3085)

A NULL pointer dereference flaw was found in the way the Pidgin IRC
protocol plug-in handles IRC topics. A malicious IRC server could send a
specially-crafted IRC TOPIC message, which once received by Pidgin, would
lead to a denial of service (Pidgin crash). (CVE-2009-2703)

It was discovered that, when connecting to certain, very old Jabber servers
via XMPP, Pidgin may ignore the "Require SSL/TLS" setting. In these
situations, a non-encrypted connection is established rather than the
connection failing, causing the user to believe they are using an encrypted
connection when they are not, leading to sensitive information disclosure
(session sniffing). (CVE-2009-3026)

A NULL pointer dereference flaw was found in the way the Pidgin MSN
protocol plug-in handles improper MSNSLP invitations. A remote attacker
could send a specially-crafted MSNSLP invitation request, which once
accepted by a valid Pidgin user, would lead to a denial of service (Pidgin
crash). (CVE-2009-3083)

These packages upgrade Pidgin to version 2.6.2. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3085</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091453"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091455" severity="medium">
    <xccdf:title>RHSA-2009:1455: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fix:

* a NULL pointer dereference flaw was found in the Multiple Devices (md)
driver in the Linux kernel. If the "suspend_lo" or "suspend_hi" file on the
sysfs file system ("/sys/") is modified when the disk array is inactive, it
could lead to a local denial of service or privilege escalation. Note: By
default, only the root user can write to the files noted above.
(CVE-2009-2849, Moderate)

Bug fixes:

* a bug in nlm_lookup_host() could lead to un-reclaimed file system locks,
resulting in umount failing &amp; NFS service relocation issues for clusters.
(BZ#517967)

* a bug in the sky2 driver prevented the phy from being reset properly on
some hardware when it hung, preventing a link from coming back up.
(BZ#517976)

* disabling MSI-X for qla2xxx also disabled MSI interrupts. (BZ#519782)

* performance issues with reads when using the qlge driver on PowerPC
systems. A system hang could also occur during reboot. (BZ#519783)

* unreliable time keeping for Red Hat Enterprise Linux virtual machines.
The KVM pvclock code is now used to detect/correct lost ticks. (BZ#520685)

* /proc/cpuinfo was missing flags for new features in supported processors,
possibly preventing the operating system &amp; applications from getting the
best performance. (BZ#520686)

* reading/writing with a serial loopback device on a certain IBM system did
not work unless booted with "pnpacpi=off". (BZ#520905)

* mlx4_core failed to load on systems with more than 32 CPUs. (BZ#520906)

* on big-endian platforms, interfaces using the mlx4_en driver &amp; Large
Receive Offload (LRO) did not handle VLAN traffic properly (a segmentation
fault in the VLAN stack in the kernel occurred). (BZ#520908)

* due to a lock being held for a long time, some systems may have
experienced "BUG: soft lockup" messages under heavy load. (BZ#520919)

* incorrect APIC timer calibration may have caused a system hang during
boot, as well as the system time becoming faster or slower. A warning is
now provided. (BZ#521238)

* a Fibre Channel device re-scan via 'echo "---" &gt; /sys/class/scsi_host/
host[x]/scan' may not complete after hot adding a drive, leading to soft
lockups ("BUG: soft lockup detected"). (BZ#521239)

* the Broadcom BCM5761 network device could not to be initialized
properly; therefore, the associated interface could not obtain an IP
address via DHCP or be assigned one manually. (BZ#521241)

* when a process attempted to read from a page that had first been accessed
by writing to part of it (via write(2)), the NFS client needed to flush the
modified portion of the page out to the server, &amp; then read the entire page
back in. This flush caused performance issues. (BZ#521244)

* a kernel panic when using bnx2x devices &amp; LRO in a bridge. A warning is
now provided to disable LRO in these situations. (BZ#522636)

* the scsi_dh_rdac driver was updated to recognize the Sun StorageTek
Flexline 380. (BZ#523237)

* in FIPS mode, random number generators are required to not return the
first block of random data they generate, but rather save it to seed the
repetition check. This update brings the random number generator into
conformance. (BZ#523289)

* an option to disable/enable the use of the first random block is now
provided to bring ansi_cprng into compliance with FIPS-140 continuous test
requirements. (BZ#523290)

* running the SAP Linux Certification Suite in a KVM guest caused severe
SAP kernel errors, causing it to exit. (BZ#524150)

* attempting to 'online' a CPU for a KVM guest via sysfs caused a system
crash. (BZ#524151)

* when using KVM, pvclock returned bogus wallclock values. (BZ#524152)

* the clock could go backwards when using the vsyscall infrastructure.
(BZ#524527)

See References for KBase links re BZ#519782 &amp; BZ#520906.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Reboot the system for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2849</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091459" severity="high">
    <xccdf:title>RHSA-2009:1459: cyrus-imapd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

Multiple buffer overflow flaws were found in the Cyrus IMAP Sieve
implementation. An authenticated user able to create Sieve mail filtering
rules could use these flaws to execute arbitrary code with the privileges
of the Cyrus IMAP server user. (CVE-2009-2632, CVE-2009-3235)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues. After installing
the update, cyrus-imapd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091463" severity="medium">
    <xccdf:title>RHSA-2009:1463: newt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Newt is a programming library for color text mode, widget-based user
interfaces. Newt can be used to add stacked windows, entry widgets,
checkboxes, radio buttons, labels, plain text fields, scrollbars, and so
on, to text mode user interfaces.

A heap-based buffer overflow flaw was found in the way newt processes
content that is to be displayed in a text dialog box. A local attacker
could issue a specially-crafted text dialog box display request (direct or
via a custom application), leading to a denial of service (application
crash) or, potentially, arbitrary code execution with the privileges of the
user running the application using the newt library. (CVE-2009-2905)

Users of newt should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, all applications using the newt library must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2905</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091463"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091465" severity="high">
    <xccdf:title>RHSA-2009:1465: kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

The kvm_emulate_hypercall() implementation was missing a check for the
Current Privilege Level (CPL). A local, unprivileged user in a virtual
machine could use this flaw to cause a local denial of service or escalate
their privileges within that virtual machine. (CVE-2009-3290)

This update also fixes the following bugs:

* non-maskable interrupts (NMI) were not supported on systems with AMD
processors. As a consequence, Windows Server 2008 R2 guests running with
more than one virtual CPU assigned on systems with AMD processors would
hang at the Windows shut down screen when a restart was attempted. This
update adds support for NMI filtering on systems with AMD processors,
allowing clean restarts of Windows Server 2008 R2 guests running with
multiple virtual CPUs. (BZ#520694)

* significant performance issues for guests running 64-bit editions of
Windows. This update improves performance for guests running 64-bit
editions of Windows. (BZ#521793)

* Windows guests may have experienced time drift. (BZ#521794)

* removing the Red Hat VirtIO Ethernet Adapter from a guest running Windows
Server 2008 R2 caused KVM to crash. With this update, device removal should
not cause this issue. (BZ#524557)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update takes effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3290</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091465"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091470" severity="medium">
    <xccdf:title>RHSA-2009:1470: openssh security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A Red Hat specific patch used in the openssh packages as shipped in Red
Hat Enterprise Linux 5.4 (RHSA-2009:1287) loosened certain ownership
requirements for directories used as arguments for the ChrootDirectory
configuration options. A malicious user that also has or previously had
non-chroot shell access to a system could possibly use this flaw to
escalate their privileges and run commands as any system user.
(CVE-2009-2904)

All OpenSSH users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the OpenSSH server daemon (sshd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2904</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091470"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091471" severity="high">
    <xccdf:title>RHSA-2009:1471: elinks security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ELinks is a text-based Web browser. ELinks does not display any images, but
it does support frames, tables, and most other HTML tags.

An off-by-one buffer overflow flaw was discovered in the way ELinks handled
its internal cache of string representations for HTML special entities. A
remote attacker could use this flaw to create a specially-crafted HTML file
that would cause ELinks to crash or, possibly, execute arbitrary code when
rendered. (CVE-2008-7224)

It was discovered that ELinks tried to load translation files using
relative paths. A local attacker able to trick a victim into running ELinks
in a folder containing specially-crafted translation files could use this
flaw to confuse the victim via incorrect translations, or cause ELinks to
crash and possibly execute arbitrary code via embedded formatting sequences
in translated messages. (CVE-2007-2027)

All ELinks users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-2027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-7224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091471"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091472" severity="medium">
    <xccdf:title>RHSA-2009:1472: xen security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xen is an open source virtualization framework. Virtualization allows users
to run guest operating systems in virtual machines on top of a host
operating system.

The pyGrub boot loader did not honor the "password" option in the grub.conf
file for para-virtualized guests. Users with access to a guest's console
could use this flaw to bypass intended access restrictions and boot the
guest with arbitrary kernel boot options, allowing them to get root
privileges in the guest's operating system. With this update, pyGrub
correctly honors the "password" option in grub.conf for para-virtualized
guests. (CVE-2009-3525)

This update also fixes the following bugs:

* rebooting para-virtualized guests sometimes caused those guests to crash
due to a race condition in the xend node control daemon. This update fixes
this race condition so that rebooting guests no longer potentially causes
them to crash and fail to reboot. (BZ#525141)

* due to a race condition in the xend daemon, a guest could disappear from
the list of running guests following a reboot, even though the guest
rebooted successfully and was running. This update fixes this race
condition so that guests always reappear in the guest list following a
reboot. (BZ#525143)

* attempting to use PCI pass-through to para-virtualized guests on certain
kernels failed with a "Function not implemented" error message. As a
result, users requiring PCI pass-through on para-virtualized guests were
not able to update the xen packages without also updating the kernel and
thus requiring a reboot. These updated packages enable PCI pass-through for
para-virtualized guests so that users do not need to upgrade the kernel in
order to take advantage of PCI pass-through functionality. (BZ#525149)

All Xen users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the xend service must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3525</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091472"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091484" severity="medium">
    <xccdf:title>RHSA-2009:1484: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

It was discovered that the upstream patch for CVE-2007-6600 included in the
Red Hat Security Advisory RHSA-2008:0038 did not include protection against
misuse of the RESET ROLE and RESET SESSION AUTHORIZATION commands. An
authenticated user could use this flaw to install malicious code that would
later execute with superuser privileges. (CVE-2009-3230)

A flaw was found in the way PostgreSQL handled encoding conversion. A
remote, authenticated user could trigger an encoding conversion failure,
possibly leading to a temporary denial of service. Note: To exploit this
issue, a locale and client encoding for which specific messages fail to
translate must be selected (the availability of these is determined by an
administrator-defined locale setting). (CVE-2009-0922)

Note: For Red Hat Enterprise Linux 4, this update upgrades PostgreSQL to
version 7.4.26. For Red Hat Enterprise Linux 5, this update upgrades
PostgreSQL to version 8.1.18. Refer to the PostgreSQL Release Notes for a
list of changes:

http://www.postgresql.org/docs/7.4/static/release.html
http://www.postgresql.org/docs/8.1/static/release.html

All PostgreSQL users should upgrade to these updated packages, which
resolve these issues. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0922</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3230</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091484"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091490" severity="medium">
    <xccdf:title>RHSA-2009:1490: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

Form submissions in SquirrelMail did not implement protection against
Cross-Site Request Forgery (CSRF) attacks. If a remote attacker tricked a
user into visiting a malicious web page, the attacker could hijack that
user's authentication, inject malicious content into that user's
preferences, or possibly send mail without that user's permission.
(CVE-2009-2964)

Users of SquirrelMail should upgrade to this updated package, which
contains a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091490"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091501" severity="high">
    <xccdf:title>RHSA-2009:1501: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf. An attacker could
create a malicious PDF file that would cause Xpdf to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3606, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091501"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091502" severity="high">
    <xccdf:title>RHSA-2009:1502: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF. An attacker could
create a malicious PDF file that would cause KPDF to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3606, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to these updated packages, which contain a
backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091502"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091503" severity="high">
    <xccdf:title>RHSA-2009:1503: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GPdf is a viewer for Portable Document Format (PDF) files.

Multiple integer overflow flaws were found in GPdf. An attacker could
create a malicious PDF file that would cause GPdf to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091503"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091504" severity="high">
    <xccdf:title>RHSA-2009:1504: poppler security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-3603, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608
issue.

This update also corrects a regression introduced in the previous poppler
security update, RHSA-2009:0480, that prevented poppler from rendering
certain PDF documents correctly. (BZ#528147)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091504"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091512" severity="high">
    <xccdf:title>RHSA-2009:1512: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF. An attacker could
create a malicious PDF file that would cause KPDF to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to these updated packages, which contain a
backported patch to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091512"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091513" severity="medium">
    <xccdf:title>RHSA-2009:1513: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The CUPS "pdftops" filter converts Portable
Document Format (PDF) files to PostScript.

Two integer overflow flaws were found in the CUPS "pdftops" filter. An
attacker could create a malicious PDF file that would cause "pdftops" to
crash or, potentially, execute arbitrary code as the "lp" user if the file
was printed. (CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608
issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091513"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091522" severity="medium">
    <xccdf:title>RHSA-2009:1522: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* multiple, missing initialization flaws were found in the Linux kernel.
Padding data in several core network structures was not initialized
properly before being sent to user-space. These flaws could lead to
information leaks. (CVE-2005-4881, CVE-2009-3228, Moderate)

This update also fixes the following bugs:

* a packet duplication issue was fixed via the RHSA-2008:0665 update;
however, the fix introduced a problem for systems using network bonding:
Backup slaves were unable to receive ARP packets. When using network
bonding in the "active-backup" mode and with the "arp_validate=3" option,
the bonding driver considered such backup slaves as being down (since they
were not receiving ARP packets), preventing successful failover to these
devices. (BZ#519384)

* due to insufficient memory barriers in the network code, a process
sleeping in select() may have missed notifications about new data. In rare
cases, this bug may have caused a process to sleep forever. (BZ#519386)

* the driver version number in the ata_piix driver was not changed between
Red Hat Enterprise Linux 4.7 and Red Hat Enterprise Linux 4.8, even though
changes had been made between these releases. This could have prevented the
driver from loading on systems that check driver versions, as this driver
appeared older than it was. (BZ#519389)

* a bug in nlm_lookup_host() could have led to un-reclaimed locks on file
systems, resulting in the umount command failing. This bug could have also
prevented NFS services from being relocated correctly in clustered
environments. (BZ#519656)

* the data buffer ethtool_get_strings() allocated, for the igb driver, was
smaller than the amount of data that was copied in igb_get_strings(),
because of a miscalculation in IGB_QUEUE_STATS_LEN, resulting in memory
corruption. This bug could have led to a kernel panic. (BZ#522738)

* in some circumstances, write operations to a particular TTY device opened
by more than one user (eg, one opened it as /dev/console and the other
opened it as /dev/ttyS0) were blocked. If one user opened the TTY terminal
without setting the O_NONBLOCK flag, this user's write operations were
suspended if the output buffer was full or if a STOP (Ctrl-S) signal was
sent. As well, because the O_NONBLOCK flag was not respected, Write
operations for user terminals opened with the O_NONBLOCK flag set were also
blocked. This update re-implements TTY locks, ensuring O_NONBLOCK works as
expected, even if it a STOP signal is sent from another terminal.
(BZ#523930)

* a deadlock was found in the cciss driver. In rare cases, this caused an
NMI lockup during boot. Messages such as "cciss: controller cciss[x]
failed, stopping." and "cciss[x]: controller not responding." may have
been displayed on the console. (BZ#525725)

* on 64-bit PowerPC systems, a rollover bug in the ibmveth driver could
have caused a kernel panic. In a reported case, this panic occurred on a
system with a large uptime and under heavy network load. (BZ#527225)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3612</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091522"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091529" severity="medium">
    <xccdf:title>RHSA-2009:1529: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A denial of service flaw was found in the Samba smbd daemon. An
authenticated, remote user could send a specially-crafted response that
would cause an smbd child process to enter an infinite loop. An
authenticated, remote user could use this flaw to exhaust system resources
by opening multiple CIFS sessions. (CVE-2009-2906)

An uninitialized data access flaw was discovered in the smbd daemon when
using the non-default "dos filemode" configuration option in "smb.conf". An
authenticated, remote user with write access to a file could possibly use
this flaw to change an access control list for that file, even when such
access should have been denied. (CVE-2009-1888)

A flaw was discovered in the way Samba handled users without a home
directory set in the back-end password database (e.g. "/etc/passwd"). If a
share for the home directory of such a user was created (e.g. using the
automated "[homes]" share), any user able to access that share could see
the whole file system, possibly bypassing intended access restrictions.
(CVE-2009-2813)

The mount.cifs program printed CIFS passwords as part of its debug output
when running in verbose mode. When mount.cifs had the setuid bit set, a
local, unprivileged user could use this flaw to disclose passwords from a
file that would otherwise be inaccessible to that user. Note: mount.cifs
from the samba packages distributed by Red Hat does not have the setuid bit
set. This flaw only affected systems where the setuid bit was manually set
by an administrator. (CVE-2009-2948)

Users of Samba should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1888</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2948</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091529"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091530" severity="high">
    <xccdf:title>RHSA-2009:1530: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).

A flaw was found in the way Firefox handles form history. A malicious web
page could steal saved form data by synthesizing input events, causing the
browser to auto-fill form fields (which could then be read by an attacker).
(CVE-2009-3370)

A flaw was found in the way Firefox creates temporary file names for
downloaded files. If a local attacker knows the name of a file Firefox is
going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A flaw was found in the Firefox Proxy Auto-Configuration (PAC) file
processor. If Firefox loads a malicious PAC file, it could crash Firefox
or, potentially, execute arbitrary code with the privileges of the user
running Firefox. (CVE-2009-3372)

A heap-based buffer overflow flaw was found in the Firefox GIF image
processor. A malicious GIF image could crash Firefox or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2009-3373)

A heap-based buffer overflow flaw was found in the Firefox string to
floating point conversion routines. A web page containing malicious
JavaScript could crash Firefox or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2009-1563)

A flaw was found in the way Firefox handles text selection. A malicious
website may be able to read highlighted text in a different domain (e.g.
another website the user is viewing), bypassing the same-origin policy.
(CVE-2009-3375)

A flaw was found in the way Firefox displays a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differs from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that differs from what the user expected.
(CVE-2009-3376)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3374, CVE-2009-3380, CVE-2009-3382)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.15. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.15, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3384</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091530"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091531" severity="high">
    <xccdf:title>RHSA-2009:1531: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey creates temporary file names for
downloaded files. If a local attacker knows the name of a file SeaMonkey is
going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A heap-based buffer overflow flaw was found in the SeaMonkey string to
floating point conversion routines. A web page containing malicious
JavaScript could crash SeaMonkey or, potentially, execute arbitrary code
with the privileges of the user running SeaMonkey. (CVE-2009-1563)

A flaw was found in the way SeaMonkey handles text selection. A malicious
website may be able to read highlighted text in a different domain (e.g.
another website the user is viewing), bypassing the same-origin policy.
(CVE-2009-3375)

A flaw was found in the way SeaMonkey displays a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differs from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that differs from what the user expected.
(CVE-2009-3376)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3380)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3385</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091531"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091536" severity="medium">
    <xccdf:title>RHSA-2009:1536: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for Communication in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

An invalid pointer dereference bug was found in the way the Pidgin OSCAR
protocol implementation processed lists of contacts. A remote attacker
could send a specially-crafted contact list to a user running Pidgin,
causing Pidgin to crash. (CVE-2009-3615)

These packages upgrade Pidgin to version 2.6.3. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
this issue. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3615</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091536"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091541" severity="high">
    <xccdf:title>RHSA-2009:1541: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could
be released by other processes before it is used to update the pipe's
reader and writer counters. This could lead to a local denial of service or
privilege escalation. (CVE-2009-3547, Important)

Users should upgrade to these updated packages, which contain a backported
patch to correct these issues. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091541"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091548" severity="high">
    <xccdf:title>RHSA-2009:1548: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a system with SELinux enforced was more permissive in allowing local
users in the unconfined_t domain to map low memory areas even if the
mmap_min_addr restriction was enabled. This could aid in the local
exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important)

* a NULL pointer dereference flaw was found in the eCryptfs implementation
in the Linux kernel. A local attacker could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2908, Important)

* a flaw was found in the NFSv4 implementation. The kernel would do an
unnecessary permission check after creating a file. This check would
usually fail and leave the file with the permission bits set to random
values. Note: This is a server-side only issue. (CVE-2009-3286, Important)

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could
be released by other processes before it is used to update the pipe's
reader and writer counters. This could lead to a local denial of service or
privilege escalation. (CVE-2009-3547, Important)

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. pci_unmap_single() presented a memory leak that could lead to IOMMU
space exhaustion and a system crash. An attacker on the local network could
abuse this flaw by using jumbo frames for large amounts of network traffic.
(CVE-2009-3613, Important)

* missing initialization flaws were found in the Linux kernel. Padding data
in several core network structures was not initialized properly before
being sent to user-space. These flaws could lead to information leaks.
(CVE-2009-3228, Moderate)

Bug fixes:

* with network bonding in the "balance-tlb" or "balance-alb" mode, the
primary setting for the primary slave device was lost when said device was
brought down. Bringing the slave back up did not restore the primary
setting. (BZ#517971)

* some faulty serial device hardware caused systems running the kernel-xen
kernel to take a very long time to boot. (BZ#524153)

* a caching bug in nfs_readdir() may have caused NFS clients to see
duplicate files or not see all files in a directory. (BZ#526960)

* the RHSA-2009:1243 update removed the mpt_msi_enable option, preventing
certain scripts from running. This update adds the option back. (BZ#526963)

* an iptables rule with the recent module and a hit count value greater
than the ip_pkt_list_tot parameter (the default is 20), did not have any
effect over packets, as the hit count could not be reached. (BZ#527434)

* a check has been added to the IPv4 code to make sure that rt is not NULL,
to help prevent future bugs in functions that call ip_append_data() from
being exploitable. (BZ#527436)

* a kernel panic occurred in certain conditions after reconfiguring a tape
drive's block size. (BZ#528133)

* when using the Linux Virtual Server (LVS) in a master and backup
configuration, and propagating active connections on the master to the
backup, the connection timeout value on the backup was hard-coded to 180
seconds, meaning connection information on the backup was soon lost. This
could prevent the successful failover of connections. The timeout value
can now be set via "ipvsadm --set". (BZ#528645)

* a bug in nfs4_do_open_expired() could have caused the reclaimer thread on
an NFSv4 client to enter an infinite loop. (BZ#529162)

* MSI interrupts may not have been delivered for r8169 based network cards
that have MSI interrupts enabled. This bug only affected certain systems.
(BZ#529366)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3613</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091548"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091549" severity="medium">
    <xccdf:title>RHSA-2009:1549: wget security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU Wget is a file retrieval utility that can use HTTP, HTTPS, and FTP.

Daniel Stenberg reported that Wget is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse Wget into accepting it by mistake. (CVE-2009-3490)

Wget users should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3490</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091549"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091561" severity="high">
    <xccdf:title>RHSA-2009:1561: libvorbis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Multiple flaws were found in the libvorbis library. A specially-crafted Ogg
Vorbis media format file (Ogg) could cause an application using libvorbis
to crash or, possibly, execute arbitrary code when opened. (CVE-2009-3379)

Users of libvorbis should upgrade to these updated packages, which contain
backported patches to correct these issues. The desktop must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3379</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091561"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091572" severity="medium">
    <xccdf:title>RHSA-2009:1572: 4Suite security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 4Suite package contains XML-related tools and libraries for Python,
including 4DOM, 4XSLT, 4XPath, 4RDF, and 4XPointer.

A buffer over-read flaw was found in the way 4Suite's XML parser handles
malformed UTF-8 sequences when processing XML files. A specially-crafted
XML file could cause applications using the 4Suite library to crash while
parsing the file. (CVE-2009-3720)

Note: In Red Hat Enterprise Linux 3, this flaw only affects a non-default
configuration of the 4Suite package: configurations where the beta version
of the cDomlette module is enabled.

All 4Suite users should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing the updated
package, applications using the 4Suite XML-related tools and libraries must
be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1572</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091572"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091579" severity="medium">
    <xccdf:title>RHSA-2009:1579: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update partially mitigates this flaw for SSL
sessions to HTTP servers using mod_ssl by rejecting client-requested
renegotiation. (CVE-2009-3555)

Note: This update does not fully resolve the issue for HTTPS servers. An
attack is still possible in configurations that require a server-initiated
renegotiation. Refer to the following Knowledgebase article for further
information: http://kbase.redhat.com/faq/docs/DOC-20491

A NULL pointer dereference flaw was found in the Apache mod_proxy_ftp
module. A malicious FTP server to which requests are being proxied could
use this flaw to crash an httpd child process via a malformed reply to the
EPSV or PASV commands, resulting in a limited denial of service.
(CVE-2009-3094)

A second flaw was found in the Apache mod_proxy_ftp module. In a reverse
proxy configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands to
the FTP server. (CVE-2009-3095)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1579</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091579"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091580" severity="medium">
    <xccdf:title>RHSA-2009:1580: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular Web server.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update partially mitigates this flaw for SSL
sessions to HTTP servers using mod_ssl by rejecting client-requested
renegotiation. (CVE-2009-3555)

Note: This update does not fully resolve the issue for HTTPS servers. An
attack is still possible in configurations that require a server-initiated
renegotiation. Refer to the following Knowledgebase article for further
information: http://kbase.redhat.com/faq/docs/DOC-20491

A denial of service flaw was found in the Apache mod_deflate module. This
module continued to compress large files until compression was complete,
even if the network connection that requested the content was closed before
compression completed. This would cause mod_deflate to consume large
amounts of CPU if mod_deflate was enabled for a large file. (CVE-2009-1891)

A NULL pointer dereference flaw was found in the Apache mod_proxy_ftp
module. A malicious FTP server to which requests are being proxied could
use this flaw to crash an httpd child process via a malformed reply to the
EPSV or PASV commands, resulting in a limited denial of service.
(CVE-2009-3094)

A second flaw was found in the Apache mod_proxy_ftp module. In a reverse
proxy configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands to
the FTP server. (CVE-2009-3095)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1891</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091584" severity="high">
    <xccdf:title>RHSA-2009:1584: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

An integer overflow flaw and buffer overflow flaws were found in the way
the JRE processed image files. An untrusted applet or application could use
these flaws to extend its privileges, allowing it to read and write local
files, as well as to execute local applications with the privileges of the
user running the applet or application. (CVE-2009-3869, CVE-2009-3871,
CVE-2009-3873, CVE-2009-3874)

An information leak was found in the JRE. An untrusted applet or
application could use this flaw to extend its privileges, allowing it to
read and write local files, as well as to execute local applications with
the privileges of the user running the applet or application. (CVE-2009-3881)

It was discovered that the JRE still accepts certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by the JRE. With
this update, the JRE disables the use of the MD2 algorithm inside
signatures by default. (CVE-2009-2409)

A timing attack flaw was found in the way the JRE processed HMAC digests.
This flaw could aid an attacker using forged digital signatures to bypass
authentication checks. (CVE-2009-3875)

Two denial of service flaws were found in the JRE. These could be exploited
in server-side application scenarios that process DER-encoded
(Distinguished Encoding Rules) data. (CVE-2009-3876, CVE-2009-3877)

An information leak was found in the way the JRE handled color profiles. An
attacker could use this flaw to discover the existence of files outside of
the color profiles directory. (CVE-2009-3728)

A flaw in the JRE with passing arrays to the X11GraphicsDevice API was
found. An untrusted applet or application could use this flaw to access and
modify the list of supported graphics configurations. This flaw could also
lead to sensitive information being leaked to unprivileged code.
(CVE-2009-3879)

It was discovered that the JRE passed entire objects to the logging API.
This could lead to sensitive information being leaked to either untrusted
or lower-privileged code from an attacker-controlled applet which has
access to the logging API and is therefore able to manipulate (read and/or
call) the passed objects. (CVE-2009-3880)

Potential information leaks were found in various mutable static variables.
These could be exploited in application scenarios that execute untrusted
scripting code. (CVE-2009-3882, CVE-2009-3883)

An information leak was found in the way the TimeZone.getTimeZone method
was handled. This method could load time zone files that are outside of the
[JRE_HOME]/lib/zi/ directory, allowing a remote attacker to probe the local
file system. (CVE-2009-3884)

Note: The flaws concerning applets in this advisory, CVE-2009-3869,
CVE-2009-3871, CVE-2009-3873, CVE-2009-3874, CVE-2009-3879, CVE-2009-3880,
CVE-2009-3881 and CVE-2009-3884, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3873</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3874</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3875</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3877</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3879</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3880</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3884</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091584"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091595" severity="medium">
    <xccdf:title>RHSA-2009:1595: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A use-after-free flaw was found in the way CUPS handled references in its
file descriptors-handling interface. A remote attacker could, in a
specially-crafted way, query for the list of current print jobs for a
specific printer, leading to a denial of service (cupsd crash).
(CVE-2009-3553)

Several cross-site scripting (XSS) flaws were found in the way the CUPS web
server interface processed HTML form content. If a remote attacker could
trick a local user who is logged into the CUPS web interface into visiting
a specially-crafted HTML page, the attacker could retrieve and potentially
modify confidential CUPS administration data. (CVE-2009-2820)

Red Hat would like to thank Aaron Sigel of Apple Product Security for
responsibly reporting the CVE-2009-2820 issue.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3553</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091595"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091601" severity="high">
    <xccdf:title>RHSA-2009:1601: kdelibs security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A buffer overflow flaw was found in the kdelibs string to floating point
conversion routines. A web page containing malicious JavaScript could crash
Konqueror or, potentially, execute arbitrary code with the privileges of
the user running Konqueror. (CVE-2009-0689)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The desktop must be restarted (log out, then
log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091601"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091615" severity="medium">
    <xccdf:title>RHSA-2009:1615: xerces-j2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.

A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. Applications using the Apache Xerces2 Java
Parser must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2625</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091615"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091619" severity="medium">
    <xccdf:title>RHSA-2009:1619: dstat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dstat is a versatile replacement for the vmstat, iostat, and netstat tools.
Dstat can be used for performance tuning tests, benchmarks, and
troubleshooting.

Robert Buchholz of the Gentoo Security Team reported a flaw in the Python
module search path used in dstat. If a local attacker could trick a
local user into running dstat from a directory containing a Python script
that is named like an importable module, they could execute arbitrary code
with the privileges of the user running dstat. (CVE-2009-3894)

All dstat users should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3894</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091619"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091620" severity="medium">
    <xccdf:title>RHSA-2009:1620: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

Michael Sinatra discovered that BIND was incorrectly caching responses
without performing proper DNSSEC validation, when those responses were
received during the resolution of a recursive client query that requested
DNSSEC records but indicated that checking should be disabled. A remote
attacker could use this flaw to bypass the DNSSEC validation check and
perform a cache poisoning attack if the target BIND server was receiving
such client queries. (CVE-2009-4022)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091620"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091625" severity="medium">
    <xccdf:title>RHSA-2009:1625: expat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Expat is a C library written by James Clark for parsing XML documents.

Two buffer over-read flaws were found in the way Expat handled malformed
UTF-8 sequences when processing XML files. A specially-crafted XML file
could cause applications using Expat to crash while parsing the file.
(CVE-2009-3560, CVE-2009-3720)

All expat users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, applications using the Expat library must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3560</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091625"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091642" severity="high">
    <xccdf:title>RHSA-2009:1642: acpid security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

It was discovered that acpid could create its log file ("/var/log/acpid")
with random permissions on some systems. A local attacker could use this
flaw to escalate their privileges if the log file was created as
world-writable and with the setuid or setgid bit set. (CVE-2009-4033)

Please note that this flaw was due to a Red Hat-specific patch
(acpid-1.0.4-fd.patch) included in the Red Hat Enterprise Linux 5 acpid
package.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4033</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091642"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091646" severity="medium">
    <xccdf:title>RHSA-2009:1646: libtool security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU Libtool is a set of shell scripts which automatically configure UNIX,
Linux, and similar operating systems to generically build shared libraries.

A flaw was found in the way GNU Libtool's libltdl library looked for
modules to load. It was possible for libltdl to load and run modules from
an arbitrary library in the current working directory. If a local attacker
could trick a local user into running an application (which uses libltdl)
from an attacker-controlled directory containing a malicious Libtool
control file (.la), the attacker could possibly execute arbitrary code with
the privileges of the user running the application. (CVE-2009-3736)

All libtool users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, applications using the libltdl library must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1646</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3736</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091646"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091648" severity="medium">
    <xccdf:title>RHSA-2009:1648: ntp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

Robin Park and Dmitri Vinokurov discovered a flaw in the way ntpd handled
certain malformed NTP packets. ntpd logged information about all such
packets and replied with an NTP packet that was treated as malformed when
received by another ntpd. A remote attacker could use this flaw to create
an NTP packet reply loop between two ntpd servers via a malformed packet
with a spoofed source IP address and port, causing ntpd on those servers to
use excessive amounts of CPU time and fill disk space with log messages.
(CVE-2009-3563)

All ntp users are advised to upgrade to this updated package, which
contains a backported patch to resolve this issue. After installing the
update, the ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3563</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091648"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091659" severity="medium">
    <xccdf:title>RHSA-2009:1659: kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

On x86 platforms, the do_insn_fetch() function did not limit the amount of
instruction bytes fetched per instruction. Users in guest operating systems
could leverage this flaw to cause large latencies on SMP hosts that could
lead to a local denial of service on the host operating system. This
update fixes this issue by imposing the architecturally-defined 15 byte
length limit for instructions. (CVE-2009-4031)

This update also fixes the following bugs:

* performance problems occurred when using the qcow2 image format with the
qemu-kvm -drive "cache=none" option (the default setting when not specified
otherwise). This could cause guest operating system installations to take
hours. With this update, performance patches have been backported so that
using the qcow2 image format with the "cache=none" option no longer causes
performance issues. (BZ#520693)

* when using the virtual vm8086 mode, bugs in the emulated hardware task
switching implementation may have, in some situations, caused older guest
operating systems to malfunction. (BZ#532031)

* Windows Server 2003 guests (32-bit) with more than 4GB of memory may have
crashed during reboot when using the default qemu-kvm CPU settings.
(BZ#532043)

* with Red Hat Enterprise Virtualization, guests continued to run after
encountering disk read errors. This could have led to their file systems
becoming corrupted (but not the host's), notably in environments that use
networked storage. With this update, the qemu-kvm -drive "werror=stop"
option now applies not only to write errors but also to read errors: When
using this option, guests will pause on disk read and write errors.

By default, guests managed by Red Hat Enterprise Virtualization use the
"werror=stop" option. This option is not used by default for guests managed
by libvirt. (BZ#537334, BZ#540406)

* the para-virtualized block driver (virtio-blk) silently ignored read
errors when accessing disk images. With this update, the driver correctly
signals the read error to the guest. (BZ#537334)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4031</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091659"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091670" severity="high">
    <xccdf:title>RHSA-2009:1670: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* NULL pointer dereference flaws in the r128 driver. Checks to test if the
Concurrent Command Engine state was initialized were missing in private
IOCTL functions. An attacker could use these flaws to cause a local denial
of service or escalate their privileges. (CVE-2009-3620, Important)

* a NULL pointer dereference flaw in the NFSv4 implementation. Several
NFSv4 file locking functions failed to check whether a file had been opened
on the server before performing locking operations on it. A local user on a
system with an NFSv4 share mounted could possibly use this flaw to cause a
denial of service or escalate their privileges. (CVE-2009-3726, Important)

* a flaw in tcf_fill_node(). A certain data structure in this function was
not initialized properly before being copied to user-space. This could lead
to an information leak. (CVE-2009-3612, Moderate)

* unix_stream_connect() did not check if a UNIX domain socket was in the
shutdown state. This could lead to a deadlock. A local, unprivileged user
could use this flaw to cause a denial of service. (CVE-2009-3621, Moderate)

Knowledgebase DOC-20536 has steps to mitigate NULL pointer dereference
flaws.

Bug fixes:

* frequently changing a CPU between online and offline caused a kernel
panic on some systems. (BZ#545583)

* for the LSI Logic LSI53C1030 Ultra320 SCSI controller, read commands sent
could receive incorrect data, preventing correct data transfer. (BZ#529308)

* pciehp could not detect PCI Express hot plug slots on some systems.
(BZ#530383)

* soft lockups: inotify race and contention on dcache_lock. (BZ#533822,
BZ#537019)

* priority ordered lists are now used for threads waiting for a given
mutex. (BZ#533858)

* a deadlock in DLM could cause GFS2 file systems to lock up. (BZ#533859)

* use-after-free bug in the audit subsystem crashed certain systems when
running usermod. (BZ#533861)

* on certain hardware configurations, a kernel panic when the Broadcom
iSCSI offload driver (bnx2i.ko and cnic.ko) was loaded. (BZ#537014)

* qla2xxx: Enabled MSI-X, and correctly handle the module parameter to
control it. This improves performance for certain systems. (BZ#537020)

* system crash when reading the cpuaffinity file on a system. (BZ#537346)

* suspend-resume problems on systems with lots of logical CPUs, e.g. BX-EX.
(BZ#539674)

* off-by-one error in the legacy PCI bus check. (BZ#539675)

* TSC was not made available on systems with multi-clustered APICs. This
could cause slow performance for time-sensitive applications. (BZ#539676)

* ACPI: ARB_DISABLE now disabled on platforms that do not need it.
(BZ#539677)

* fix node to core and power-aware scheduling issues, and a kernel panic
during boot on certain AMD Opteron processors. (BZ#539678, BZ#540469,
BZ#539680, BZ#539682)

* APIC timer interrupt issues on some AMD Opteron systems prevented
achieving full power savings. (BZ#539681)

* general OProfile support for some newer Intel processors. (BZ#539683)

* system crash during boot when NUMA is enabled on systems using MC and
kernel-xen. (BZ#539684)

* on some larger systems, performance issues due to a spinlock. (BZ#539685)

* APIC errors when IOMMU is enabled on some AMD Opteron systems.
(BZ#539687)

* on some AMD Opteron systems, repeatedly taking a CPU offline then online
caused a system hang. (BZ#539688)

* I/O page fault errors on some systems. (BZ#539689)

* certain memory configurations could cause the kernel-xen kernel to fail
to boot on some AMD Opteron systems. (BZ#539690)

* NMI watchdog is now disabled for offline CPUs. (BZ#539691)

* duplicate directories in /proc/acpi/processor/ on BX-EX systems.
(BZ#539692)

* links did not come up when using bnx2x with certain Broadcom devices.
(BZ#540381)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3726</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091670"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091671" severity="high">
    <xccdf:title>RHSA-2009:1671: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. pci_unmap_single() presented a memory leak that could lead to IOMMU
space exhaustion and a system crash. An attacker on the local network could
trigger this flaw by using jumbo frames for large amounts of network
traffic. (CVE-2009-3613, Important)

* NULL pointer dereference flaws were found in the r128 driver in the Linux
kernel. Checks to test if the Concurrent Command Engine state was
initialized were missing in private IOCTL functions. An attacker could use
these flaws to cause a local denial of service or escalate their
privileges. (CVE-2009-3620, Important)

* an information leak was found in the Linux kernel. On AMD64 systems,
32-bit processes could access and read certain 64-bit registers by
temporarily switching themselves to 64-bit mode. (CVE-2009-2910, Moderate)

* the unix_stream_connect() function in the Linux kernel did not check if a
UNIX domain socket was in the shutdown state. This could lead to a
deadlock. A local, unprivileged user could use this flaw to cause a denial
of service. (CVE-2009-3621, Moderate)

This update also fixes the following bugs:

* an iptables rule with the recent module and a hit count value greater
than the ip_pkt_list_tot parameter (the default is 20), did not have any
effect over packets, as the hit count could not be reached. (BZ#529306)

* in environments that use dual-controller storage devices with the cciss
driver, Device-Mapper Multipath maps could not be detected and configured,
due to the cciss driver not exporting the bus attribute via sysfs. This
attribute is now exported. (BZ#529309)

* the kernel crashed with a divide error when a certain joystick was
attached. (BZ#532027)

* a bug in the mptctl_do_mpt_command() function in the mpt driver may have
resulted in crashes during boot on i386 systems with certain adapters using
the mpt driver, and also running the hugemem kernel. (BZ#533798)

* on certain hardware, the igb driver was unable to detect link statuses
correctly. This may have caused problems for network bonding, such as
failover not occurring. (BZ#534105)

* the RHSA-2009:1024 update introduced a regression. After updating to Red
Hat Enterprise Linux 4.8 and rebooting, network links often failed to be
brought up for interfaces using the forcedeth driver. "no link during
initialization" messages may have been logged. (BZ#534112)

* the RHSA-2009:1024 update introduced a second regression. On certain
systems, PS/2 keyboards failed to work. (BZ#537344)

* a bug in checksum offload calculations could have crashed the bnx2x
firmware when the iptable_nat module was loaded, causing network traffic
to stop. (BZ#537013)

* a check has been added to the IPv4 code to make sure that the routing
table data structure, rt, is not NULL, to help prevent future bugs in
functions that call ip_append_data() from being exploitable. (BZ#537016)

* possible kernel pointer dereferences on systems with several NFS mounts
(a mixture of "-o lock" and "-o nolock"), which in rare cases may have
caused a system crash, have been resolved. (BZ#537017)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3621</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091671"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091673" severity="high">
    <xccdf:title>RHSA-2009:1673: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3979)

A flaw was found in the SeaMonkey NT Lan Manager (NTLM) authentication
protocol implementation. If an attacker could trick a local user that has
NTLM credentials into visiting a specially-crafted web page, they could
send arbitrary requests, authenticated with the user's NTLM credentials, to
other applications on the user's system. (CVE-2009-3983)

A flaw was found in the way SeaMonkey displayed the SSL location bar
indicator. An attacker could create an unencrypted web page that appears
to be encrypted, possibly tricking the user into believing they are
visiting a secure page. (CVE-2009-3984)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3984</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091673"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091674" severity="high">
    <xccdf:title>RHSA-2009:1674: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)

A flaw was found in the Firefox NT Lan Manager (NTLM) authentication
protocol implementation. If an attacker could trick a local user that has
NTLM credentials into visiting a specially-crafted web page, they could
send arbitrary requests, authenticated with the user's NTLM credentials, to
other applications on the user's system. (CVE-2009-3983)

A flaw was found in the way Firefox displayed the SSL location bar
indicator. An attacker could create an unencrypted web page that appears to
be encrypted, possibly tricking the user into believing they are visiting a
secure page. (CVE-2009-3984)

A flaw was found in the way Firefox displayed blank pages after a user
navigates to an invalid address. If a user visits an attacker-controlled
web page that results in a blank page, the attacker could inject content
into that blank page, possibly tricking the user into believing they are
viewing a legitimate page. (CVE-2009-3985)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.16. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.16, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3984</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3985</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3986</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091674"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091680" severity="high">
    <xccdf:title>RHSA-2009:1680: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in Xpdf's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause Xpdf to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4035</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091680"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091681" severity="high">
    <xccdf:title>RHSA-2009:1681: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GPdf is a viewer for Portable Document Format (PDF) files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in GPdf's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause GPdf to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4035</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091681"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20091682" severity="high">
    <xccdf:title>RHSA-2009:1682: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in KPDF's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause KPDF to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2009:1682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4035</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20091682"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100002" severity="medium">
    <xccdf:title>RHSA-2010:0002: PyXML security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PyXML provides XML libraries for Python. The distribution contains a
validating XML parser, an implementation of the SAX and DOM programming
interfaces, and an interface to the Expat parser.

A buffer over-read flaw was found in the way PyXML's Expat parser handled
malformed UTF-8 sequences when processing XML files. A specially-crafted
XML file could cause Python applications using PyXML's Expat parser to
crash while parsing the file. (CVE-2009-3720)

This update makes PyXML use the system Expat library rather than its own
internal copy; therefore, users must install the RHSA-2009:1625 expat
update together with this PyXML update to resolve the CVE-2009-3720 issue.

All PyXML users should upgrade to this updated package, which changes PyXML
to use the system Expat library. After installing this update along with
RHSA-2009:1625, applications using the PyXML library must be restarted for
the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100002"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100003" severity="medium">
    <xccdf:title>RHSA-2010:0003: gd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gd packages provide a graphics library used for the dynamic creation of
images, such as PNG and JPEG.

A missing input sanitization flaw, leading to a buffer overflow, was
discovered in the gd library. A specially-crafted GD image file could cause
an application using the gd library to crash or, possibly, execute
arbitrary code when opened. (CVE-2009-3546)

Users of gd should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3546</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100018" severity="medium">
    <xccdf:title>RHSA-2010:0018: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

It was discovered that the Red Hat Security Advisory RHSA-2009:0008 did
not correctly fix the denial of service flaw in the system for sending
messages between applications. A local user could use this flaw to send a
message with a malformed signature to the bus, causing the bus (and,
consequently, any process using libdbus to receive messages) to abort.
(CVE-2009-1189)

Note: Users running any application providing services over the system
message bus are advised to test this update carefully before deploying it
in production environments.

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1189</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100018"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100019" severity="high">
    <xccdf:title>RHSA-2010:0019: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in the IPv6 Extension Header (EH) handling
implementation in the Linux kernel. The skb-&gt;dst data structure was not
properly validated in the ipv6_hop_jumbo() function. This could possibly
lead to a remote denial of service. (CVE-2007-4567, Important)

* a flaw was found in each of the following Intel PRO/1000 Linux drivers in
the Linux kernel: e1000 and e1000e. A remote attacker using packets larger
than the MTU could bypass the existing fragment check, resulting in
partial, invalid frames being passed to the network stack. These flaws
could also possibly be used to trigger a remote denial of service.
(CVE-2009-4536, CVE-2009-4538, Important)

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. Receiving overly-long frames with network cards supported by this
driver could possibly result in a remote denial of service. (CVE-2009-4537,
Important)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4538</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100019"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100020" severity="high">
    <xccdf:title>RHSA-2010:0020: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in each of the following Intel PRO/1000 Linux drivers in
the Linux kernel: e1000 and e1000e. A remote attacker using packets larger
than the MTU could bypass the existing fragment check, resulting in
partial, invalid frames being passed to the network stack. These flaws
could also possibly be used to trigger a remote denial of service.
(CVE-2009-4536, CVE-2009-4538, Important)

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. Receiving overly-long frames with network cards supported by this
driver could possibly result in a remote denial of service. (CVE-2009-4537,
Important)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4538</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100020"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100029" severity="high">
    <xccdf:title>RHSA-2010:0029: krb5 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

Multiple integer underflow flaws, leading to heap-based corruption, were
found in the way the MIT Kerberos Key Distribution Center (KDC) decrypted
ciphertexts encrypted with the Advanced Encryption Standard (AES) and
ARCFOUR (RC4) encryption algorithms. If a remote KDC client were able to
provide a specially-crafted AES- or RC4-encrypted ciphertext or texts, it
could potentially lead to either a denial of service of the central KDC
(KDC crash or abort upon processing the crafted ciphertext), or arbitrary
code execution with the privileges of the KDC (i.e., root privileges).
(CVE-2009-4212)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running services using the
MIT Kerberos libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4212</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100029"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100039" severity="medium">
    <xccdf:title>RHSA-2010:0039: gcc and gcc4 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gcc and gcc4 packages include, among others, C, C++, and Java GNU
compilers and related support libraries. libgcj contains a copy of GNU
Libtool's libltdl library.

A flaw was found in the way GNU Libtool's libltdl library looked for
libraries to load. It was possible for libltdl to load a malicious library
from the current working directory. In certain configurations, if a local
attacker is able to trick a local user into running a Java application
(which uses a function to load native libraries, such as
System.loadLibrary) from within an attacker-controlled directory containing
a malicious library or module, the attacker could possibly execute
arbitrary code with the privileges of the user running the Java
application. (CVE-2009-3736)

All gcc and gcc4 users should upgrade to these updated packages, which
contain a backported patch to correct this issue. All running Java
applications using libgcj must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3736</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100039"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100040" severity="medium">
    <xccdf:title>RHSA-2010:0040: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Multiple missing input sanitization flaws were discovered in PHP's exif
extension. A specially-crafted image file could cause the PHP interpreter
to crash or, possibly, disclose portions of its memory when a PHP script
tried to extract Exchangeable image file format (Exif) metadata from the
image file. (CVE-2009-2687, CVE-2009-3292)

A missing input sanitization flaw, leading to a buffer overflow, was
discovered in PHP's gd library. A specially-crafted GD image file could
cause the PHP interpreter to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-3546)

It was discovered that PHP did not limit the maximum number of files that
can be uploaded in one request. A remote attacker could use this flaw to
instigate a denial of service by causing the PHP interpreter to use lots of
system resources dealing with requests containing large amounts of files to
be uploaded. This vulnerability depends on file uploads being enabled
(which it is, in the default PHP configuration). (CVE-2009-4017)

Note: This update introduces a new configuration option, max_file_uploads,
used for limiting the number of files that can be uploaded in one request.
By default, the limit is 20 files per request.

It was discovered that PHP was affected by the previously published "null
prefix attack", caused by incorrect handling of NUL characters in X.509
certificates. If an attacker is able to get a carefully-crafted certificate
signed by a trusted Certificate Authority, the attacker could use the
certificate during a man-in-the-middle attack and potentially confuse PHP
into accepting it by mistake. (CVE-2009-3291)

It was discovered that PHP's htmlspecialchars() function did not properly
recognize partial multi-byte sequences for some multi-byte encodings,
sending them to output without them being escaped. An attacker could use
this flaw to perform a cross-site scripting attack. (CVE-2009-4142)

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3291</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4142</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100040"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100044" severity="high">
    <xccdf:title>RHSA-2010:0044: pidgin security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A directory traversal flaw was discovered in Pidgin's MSN protocol
implementation. A remote attacker could send a specially-crafted emoticon
image download request that would cause Pidgin to disclose an arbitrary
file readable to the user running Pidgin. (CVE-2010-0013)

These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
this issue. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0013</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100044"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100046" severity="high">
    <xccdf:title>RHSA-2010:0046: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* an array index error was found in the gdth driver. A local user could
send a specially-crafted IOCTL request that would cause a denial of service
or, possibly, privilege escalation. (CVE-2009-3080, Important)

* a flaw was found in the FUSE implementation. When a system is low on
memory, fuse_put_request() could dereference an invalid pointer, possibly
leading to a local denial of service or privilege escalation.
(CVE-2009-4021, Important)

* Tavis Ormandy discovered a deficiency in the fasync_helper()
implementation. This could allow a local, unprivileged user to leverage a
use-after-free of locked, asynchronous file descriptors to cause a denial
of service or privilege escalation. (CVE-2009-4141, Important)

* the Parallels Virtuozzo Containers team reported the RHSA-2009:1243
update introduced two flaws in the routing implementation. If an attacker
was able to cause a large enough number of collisions in the routing hash
table (via specially-crafted packets) for the emergency route flush to
trigger, a deadlock could occur. Secondly, if the kernel routing cache was
disabled, an uninitialized pointer would be left behind after a route
lookup, leading to a kernel panic. (CVE-2009-4272, Important)

* the RHSA-2009:0225 update introduced a rewrite attack flaw in the
do_coredump() function. A local attacker able to guess the file name a
process is going to dump its core to, prior to the process crashing, could
use this flaw to append data to the dumped core file. This issue only
affects systems that have "/proc/sys/fs/suid_dumpable" set to 2 (the
default value is 0). (CVE-2006-6304, Moderate)

The fix for CVE-2006-6304 changes the expected behavior: With suid_dumpable
set to 2, the core file will not be recorded if the file already exists.
For example, core files will not be overwritten on subsequent crashes of
processes whose core files map to the same name.

* an information leak was found in the Linux kernel. On AMD64 systems,
32-bit processes could access and read certain 64-bit registers by
temporarily switching themselves to 64-bit mode. (CVE-2009-2910, Moderate)

* the RHBA-2008:0314 update introduced N_Port ID Virtualization (NPIV)
support in the qla2xxx driver, resulting in two new sysfs pseudo files,
"/sys/class/scsi_host/[a qla2xxx host]/vport_create" and "vport_delete".
These two files were world-writable by default, allowing a local user to
change SCSI host attributes. This flaw only affects systems using the
qla2xxx driver and NPIV capable hardware. (CVE-2009-3556, Moderate)

* permission issues were found in the megaraid_sas driver. The "dbg_lvl"
and "poll_mode_io" files on the sysfs file system ("/sys/") had
world-writable permissions. This could allow local, unprivileged users to
change the behavior of the driver. (CVE-2009-3889, CVE-2009-3939, Moderate)

* a NULL pointer dereference flaw was found in the firewire-ohci driver
used for OHCI compliant IEEE 1394 controllers. A local, unprivileged user
with access to /dev/fw* files could issue certain IOCTL calls, causing a
denial of service or privilege escalation. The FireWire modules are
blacklisted by default, and if enabled, only root has access to the files
noted above by default. (CVE-2009-4138, Moderate)

* a buffer overflow flaw was found in the hfs_bnode_read() function in the
HFS file system implementation. This could lead to a denial of service if a
user browsed a specially-crafted HFS file system, for example, by running
"ls". (CVE-2009-4020, Low)

Bug fix documentation for this update will be available shortly from
www.redhat.com/docs/en-US/errata/RHSA-2010-0046/Kernel_Security_Update/
index.html

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0046</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-6304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4272</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100046"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100054" severity="medium">
    <xccdf:title>RHSA-2010:0054: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that the OpenSSL library did not properly re-initialize its
internal state in the SSL_library_init() function after previous calls to
the CRYPTO_cleanup_all_ex_data() function, which would cause a memory leak
for each subsequent SSL connection. This flaw could cause server
applications that call those functions during reload, such as a combination
of the Apache HTTP Server, mod_ssl, PHP, and cURL, to consume all available
memory, resulting in a denial of service. (CVE-2009-4355)

Dan Kaminsky found that browsers could accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser.
OpenSSL now disables the use of the MD2 algorithm inside signatures by
default. (CVE-2009-2409)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4355</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100054"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100061" severity="medium">
    <xccdf:title>RHSA-2010:0061: gzip security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gzip package provides the GNU gzip data compression program.

An integer underflow flaw, leading to an array index error, was found in
the way gzip expanded archive files compressed with the Lempel-Ziv-Welch
(LZW) compression algorithm. If a victim expanded a specially-crafted
archive, it could cause gzip to crash or, potentially, execute arbitrary
code with the privileges of the user running gzip. This flaw only affects
64-bit systems. (CVE-2010-0001)

Red Hat would like to thank Aki Helin of the Oulu University Secure
Programming Group for responsibly reporting this flaw.

Users of gzip should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0001</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100061"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100062" severity="medium">
    <xccdf:title>RHSA-2010:0062: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the BIND DNSSEC NSEC/NSEC3 validation code. If BIND was
running as a DNSSEC-validating resolver, it could incorrectly cache
NXDOMAIN responses, as if they were valid, for records proven by NSEC or
NSEC3 to exist. A remote attacker could use this flaw to cause a BIND
server to return the bogus, cached NXDOMAIN responses for valid records and
prevent users from retrieving those records (denial of service).
(CVE-2010-0097)

The original fix for CVE-2009-4022 was found to be incomplete. BIND was
incorrectly caching certain responses without performing proper DNSSEC
validation. CNAME and DNAME records could be cached, without proper DNSSEC
validation, when received from processing recursive client queries that
requested DNSSEC records but indicated that checking should be disabled. A
remote attacker could use this flaw to bypass the DNSSEC validation check
and perform a cache poisoning attack if the target BIND server was
receiving such client queries. (CVE-2010-0290)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0382</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100062"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100076" severity="high">
    <xccdf:title>RHSA-2010:0076: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* an array index error was found in the gdth driver in the Linux kernel. A
local user could send a specially-crafted IOCTL request that would cause a
denial of service or, possibly, privilege escalation. (CVE-2009-3080,
Important)

* a flaw was found in the collect_rx_frame() function in the HiSax ISDN
driver (hfc_usb) in the Linux kernel. An attacker could use this flaw to
send a specially-crafted HDLC packet that could trigger a buffer out of
bounds, possibly resulting in a denial of service. (CVE-2009-4005,
Important)

* permission issues were found in the megaraid_sas driver (for SAS based
RAID controllers) in the Linux kernel. The "dbg_lvl" and "poll_mode_io"
files on the sysfs file system ("/sys/") had world-writable permissions.
This could allow local, unprivileged users to change the behavior of the
driver. (CVE-2009-3889, CVE-2009-3939, Moderate)

* a buffer overflow flaw was found in the hfs_bnode_read() function in the
HFS file system implementation in the Linux kernel. This could lead to a
denial of service if a user browsed a specially-crafted HFS file system,
for example, by running "ls". (CVE-2009-4020, Low)

This update also fixes the following bugs:

* if a process was using ptrace() to trace a multi-threaded process, and
that multi-threaded process dumped its core, the process performing the
trace could hang in wait4(). This issue could be triggered by running
"strace -f" on a multi-threaded process that was dumping its core,
resulting in the strace command hanging. (BZ#555869)

* a bug in the ptrace() implementation could have, in some cases, caused
ptrace_detach() to create a zombie process if the process being traced
was terminated with a SIGKILL signal. (BZ#555869)

* the RHSA-2010:0020 update resolved an issue (CVE-2009-4537) in the
Realtek r8169 Ethernet driver. This update implements a better solution for
that issue. Note: This is not a security regression. The original fix was
complete. This update is adding the official upstream fix. (BZ#556406)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4020</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100076"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100088" severity="high">
    <xccdf:title>RHSA-2010:0088: kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

The x86 emulator implementation was missing a check for the Current
Privilege Level (CPL) and I/O Privilege Level (IOPL). A user in a guest
could leverage these flaws to cause a denial of service (guest crash) or
possibly escalate their privileges within that guest. (CVE-2010-0298,
CVE-2010-0306)

A flaw was found in the Programmable Interval Timer (PIT) emulation. Access
to the internal data structure pit_state, which represents the data state
of the emulated PIT, was not properly validated in the pit_ioport_read()
function. A privileged guest user could use this flaw to crash the host.
(CVE-2010-0309)

A flaw was found in the USB passthrough handling code. A specially-crafted
USB packet sent from inside a guest could be used to trigger a buffer
overflow in the usb_host_handle_control() function, which runs under the
QEMU-KVM context on the host. A user in a guest could leverage this flaw to
cause a denial of service (guest hang or crash) or possibly escalate their
privileges within the host. (CVE-2010-0297)

This update also fixes the following bugs: 

* pvclock MSR values were not preserved during remote migration, causing
time drift for guests. (BZ#537028)

* SMBIOS table 4 data is now generated for Windows guests. (BZ#545874)

* if the qemu-kvm "-net user" option was used, unattended Windows XP
installations did not receive an IP address after reboot. (BZ#546562)

* when being restored from migration, a race condition caused Windows
Server 2008 R2 guests to hang during shutdown. (BZ#546563)

* the kernel symbol checking on the kvm-kmod build process has a safety
check for ABI changes. (BZ#547293)

* on hosts without high-res timers, Windows Server 2003 guests experienced
significant time drift. (BZ#547625)

* in some situations, installing Windows Server 2008 R2 from an ISO image
resulted in a blue screen "BAD_POOL_HEADER" stop error. (BZ#548368)

* a bug in the grow_refcount_table() error handling caused infinite
recursion in some cases. This caused the qemu-kvm process to hang and
eventually crash. (BZ#552159)

* for Windows Server 2003 R2, Service Pack 2, 32-bit guests, an "unhandled
vm exit" error could occur during reboot on some systems. (BZ#552518)

* for Windows guests, QEMU could attempt to stop a stopped audio device,
resulting in a "snd_playback_stop: ASSERT playback_channel-&gt;base.active
failed" error. (BZ#552519)

* the Hypercall driver did not reset the device on power-down. (BZ#552528)

* mechanisms have been added to make older savevm versions to be emitted in
some cases. (BZ#552529)

* an error in the Makefile prevented users from using the source RPM to
install KVM. (BZ#552530)

* guests became unresponsive and could use up to 100% CPU when running
certain benchmark tests with more than 7 guests running simultaneously.
(BZ#553249)

* QEMU could terminate randomly with virtio-net and SMP enabled.
(BZ#561022)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0297</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0309</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100088"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100094" severity="high">
    <xccdf:title>RHSA-2010:0094: HelixPlayer security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HelixPlayer is a media player.

Multiple buffer and integer overflow flaws were found in the way
HelixPlayer processed Graphics Interchange Format (GIF) files. An attacker
could create a specially-crafted GIF file which would cause HelixPlayer to
crash or, potentially, execute arbitrary code when opened. (CVE-2009-4242,
CVE-2009-4245)

A buffer overflow flaw was found in the way HelixPlayer processed
Synchronized Multimedia Integration Language (SMIL) files. An attacker
could create a specially-crafted SMIL file which would cause HelixPlayer to
crash or, potentially, execute arbitrary code when opened. (CVE-2009-4257)

A buffer overflow flaw was found in the way HelixPlayer handled the Real
Time Streaming Protocol (RTSP) SET_PARAMETER directive. A malicious RTSP
server could use this flaw to crash HelixPlayer or, potentially, execute
arbitrary code. (CVE-2009-4248)

Multiple buffer overflow flaws were discovered in the way HelixPlayer
handled RuleBook structures in media files and RTSP streams.
Specially-crafted input could cause HelixPlayer to crash or, potentially,
execute arbitrary code. (CVE-2009-4247, CVE-2010-0417)

A buffer overflow flaw was found in the way HelixPlayer performed URL
un-escaping. A specially-crafted URL string could cause HelixPlayer to
crash or, potentially, execute arbitrary code. (CVE-2010-0416)

All HelixPlayer users are advised to upgrade to this updated package,
which contains backported patches to resolve these issues. All running
instances of HelixPlayer must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4376</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100094"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100101" severity="high">
    <xccdf:title>RHSA-2010:0101: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way OpenOffice.org parsed XPM files. An attacker could create
a specially-crafted document, which once opened by a local, unsuspecting
user, could lead to arbitrary code execution with the permissions of the
user running OpenOffice.org. Note: This flaw affects embedded XPM files in
OpenOffice.org documents as well as stand-alone XPM files. (CVE-2009-2949)

An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parsed certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by a
local, unsuspecting user, could cause OpenOffice.org to crash or,
potentially, execute arbitrary code with the permissions of the user
running OpenOffice.org. (CVE-2009-3301, CVE-2009-3302)

A heap-based buffer overflow flaw, leading to memory corruption, was found
in the way OpenOffice.org parsed GIF files. An attacker could create a
specially-crafted document, which once opened by a local, unsuspecting
user, could cause OpenOffice.org to crash. Note: This flaw affects embedded
GIF files in OpenOffice.org documents as well as stand-alone GIF files.
(CVE-2009-2950)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2949</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2950</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3302</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100101"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100108" severity="medium">
    <xccdf:title>RHSA-2010:0108: NetworkManager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

A missing network certificate verification flaw was found in
NetworkManager. If a user created a WPA Enterprise or 802.1x wireless
network connection that was verified using a Certificate Authority (CA)
certificate, and then later removed that CA certificate file,
NetworkManager failed to verify the identity of the network on the
following connection attempts. In these situations, a malicious wireless
network spoofing the original network could trick a user into disclosing
authentication credentials or communicating over an untrusted network.
(CVE-2009-4144)

An information disclosure flaw was found in NetworkManager's
nm-connection-editor D-Bus interface. If a user edited network connection
options using nm-connection-editor, a summary of those changes was
broadcasted over the D-Bus message bus, possibly disclosing sensitive
information (such as wireless network authentication credentials) to other
local users. (CVE-2009-4145)

Users of NetworkManager should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4145</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100108"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100109" severity="medium">
    <xccdf:title>RHSA-2010:0109: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

It was discovered that the MySQL client ignored certain SSL certificate
verification errors when connecting to servers. A man-in-the-middle
attacker could use this flaw to trick MySQL clients into connecting to a
spoofed MySQL server. (CVE-2009-4028)

Note: This fix may uncover previously hidden SSL configuration issues, such
as incorrect CA certificates being used by clients or expired server
certificates. This update should be carefully tested in deployments where
SSL connections are used.

A flaw was found in the way MySQL handled SELECT statements with subqueries
in the WHERE clause, that assigned results to a user variable. A remote,
authenticated attacker could use this flaw to crash the MySQL server daemon
(mysqld). This issue only caused a temporary denial of service, as the
MySQL daemon was automatically restarted after the crash. (CVE-2009-4019)

When the "datadir" option was configured with a relative path, MySQL did
not properly check paths used as arguments for the DATA DIRECTORY and INDEX
DIRECTORY directives. An authenticated attacker could use this flaw to
bypass the restriction preventing the use of subdirectories of the MySQL
data directory being used as DATA DIRECTORY and INDEX DIRECTORY paths.
(CVE-2009-4030)

Note: Due to the security risks and previous security issues related to the
use of the DATA DIRECTORY and INDEX DIRECTORY directives, users not
depending on this feature should consider disabling it by adding
"symbolic-links=0" to the "[mysqld]" section of the "my.cnf" configuration
file. In this update, an example of such a configuration was added to the
default "my.cnf" file.

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0109</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4030</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100109"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100110" severity="medium">
    <xccdf:title>RHSA-2010:0110: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

Multiple flaws were discovered in the way MySQL handled symbolic links to
tables created using the DATA DIRECTORY and INDEX DIRECTORY directives in
CREATE TABLE statements. An attacker with CREATE and DROP table privileges
and shell access to the database server could use these flaws to escalate
their database privileges, or gain access to tables created by other
database users. (CVE-2008-4098, CVE-2009-4030)

Note: Due to the security risks and previous security issues related to the
use of the DATA DIRECTORY and INDEX DIRECTORY directives, users not
depending on this feature should consider disabling it by adding
"symbolic-links=0" to the "[mysqld]" section of the "my.cnf" configuration
file. In this update, an example of such a configuration was added to the
default "my.cnf" file.

An insufficient HTML entities quoting flaw was found in the mysql command
line client's HTML output mode. If an attacker was able to inject arbitrary
HTML tags into data stored in a MySQL database, which was later retrieved
using the mysql command line client and its HTML output mode, they could
perform a cross-site scripting (XSS) attack against victims viewing the
HTML output in a web browser. (CVE-2008-4456)

Multiple format string flaws were found in the way the MySQL server logged
user commands when creating and deleting databases. A remote, authenticated
attacker with permissions to CREATE and DROP databases could use these
flaws to formulate a specially-crafted SQL command that would cause a
temporary denial of service (open connections to mysqld are terminated).
(CVE-2009-2446)

Note: To exploit the CVE-2009-2446 flaws, the general query log (the mysqld
"--log" command line option or the "log" option in "my.cnf") must be
enabled. This logging is not enabled by default.

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0110</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-4456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4030</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100110"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100112" severity="high">
    <xccdf:title>RHSA-2010:0112: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A use-after-free flaw was found in Firefox. Under low memory conditions,
visiting a web page containing malicious content could result in Firefox
executing arbitrary code with the privileges of the user running Firefox.
(CVE-2009-1571)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-0159, CVE-2010-0160)

Two flaws were found in the way certain content was processed. An attacker
could use these flaws to create a malicious web page that could bypass the
same-origin policy, or possibly run untrusted JavaScript. (CVE-2009-3988,
CVE-2010-0162)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.18. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.18, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0171</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100112"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100113" severity="high">
    <xccdf:title>RHSA-2010:0113: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A use-after-free flaw was found in SeaMonkey. Under low memory conditions,
visiting a web page containing malicious content could result in SeaMonkey
executing arbitrary code with the privileges of the user running SeaMonkey.
(CVE-2009-1571)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-0159)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0171</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100113"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100115" severity="medium">
    <xccdf:title>RHSA-2010:0115: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way Pidgin's MSN protocol
implementation handled MSNSLP invitations. A remote attacker could send a
specially-crafted INVITE request that would cause a denial of service
(memory corruption and Pidgin crash). (CVE-2010-0277)

A denial of service flaw was found in Finch's XMPP chat implementation,
when using multi-user chat. If a Finch user in a multi-user chat session
were to change their nickname to contain the HTML "br" element, it would
cause Finch to crash. (CVE-2010-0420)

Red Hat would like to thank Sadrul Habib Chowdhury of the Pidgin project
for responsibly reporting the CVE-2010-0420 issue.

A denial of service flaw was found in the way Pidgin processed emoticon
images. A remote attacker could flood the victim with emoticon images
during mutual communication, leading to excessive CPU use. (CVE-2010-0423)

These packages upgrade Pidgin to version 2.6.6. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users are advised to upgrade to these updated packages, which
correct these issues. Pidgin must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0277</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0423</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100115"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100122" severity="high">
    <xccdf:title>RHSA-2010:0122: sudo security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A privilege escalation flaw was found in the way sudo handled the sudoedit
pseudo-command. If a local user were authorized by the sudoers file to use
this pseudo-command, they could possibly leverage this flaw to execute
arbitrary code with the privileges of the root user. (CVE-2010-0426)

The sudo utility did not properly initialize supplementary groups when the
"runas_default" option (in the sudoers file) was used. If a local user
were authorized by the sudoers file to perform their sudo commands under
the account specified with "runas_default", they would receive the root
user's supplementary groups instead of those of the intended target user,
giving them unintended privileges. (CVE-2010-0427)

Users of sudo should upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100122"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100124" severity="high">
    <xccdf:title>RHSA-2010:0124: systemtap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

A flaw was found in the SystemTap compile server, stap-server, an optional
component of SystemTap. This server did not adequately sanitize input
provided by the stap-client program, which may allow a remote user to
execute arbitrary shell code with the privileges of the compile server
process, which could possibly be running as the root user. (CVE-2009-4273)

Note: stap-server is not run by default. It must be started by a user or
administrator.

A buffer overflow flaw was found in SystemTap's tapset __get_argv()
function. If a privileged user ran a SystemTap script that called this
function, a local, unprivileged user could, while that script is still
running, trigger this flaw and cause memory corruption by running a command
with a large argument list, which may lead to a system crash or,
potentially, arbitrary code execution with root privileges. (CVE-2010-0411)

Note: SystemTap scripts that call __get_argv(), being a privileged
function, can only be executed by the root user or users in the stapdev
group. As well, if such a script was compiled and installed by root, users
in the stapusr group would also be able to execute it.

SystemTap users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0124</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100124"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100125" severity="medium">
    <xccdf:title>RHSA-2010:0125: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

A buffer overflow flaw was found in SystemTap's tapset __get_argv()
function. If a privileged user ran a SystemTap script that called this
function, a local, unprivileged user could, while that script is still
running, trigger this flaw and cause memory corruption by running a command
with a large argument list, which may lead to a system crash or,
potentially, arbitrary code execution with root privileges. (CVE-2010-0411)

Note: SystemTap scripts that call __get_argv(), being a privileged
function, can only be executed by the root user or users in the stapdev
group. As well, if such a script was compiled and installed by root, users
in the stapusr group would also be able to execute it.

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100125"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100126" severity="high">
    <xccdf:title>RHSA-2010:0126: kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way the x86 emulator loaded segment selectors (used
for memory segmentation and protection) into segment registers. In some
guest system configurations, an unprivileged guest user could leverage this
flaw to crash the guest or possibly escalate their privileges within the
guest. (CVE-2010-0419)

The x86 emulator implementation was missing a check for the Current
Privilege Level (CPL) while accessing debug registers. An unprivileged
user in a guest could leverage this flaw to crash the guest.
(CVE-2009-3722)

This update also fixes the following bugs:

With Red Hat Enterprise Virtualization, the virtio_blk_dma_restart_bh()
function was previously used to handle write errors; however, a bug fix
provided by the RHSA-2009:1659 update meant that read errors would also
have to be handled by this function. The function was not updated for this,
causing read errors to be resubmitted as writes. This caused guest image
corruption in some cases.

Additionally, the return values of the bdrv_aio_write() and bdrv_aio_read()
functions were ignored. If an immediate failure occurred in one of these
functions, errors would be missed and the guest could hang or read
corrupted data. (BZ#562776)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0419</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100129" severity="medium">
    <xccdf:title>RHSA-2010:0129: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

It was discovered that the Red Hat Security Advisory RHSA-2009:1595 did not
fully correct the use-after-free flaw in the way CUPS handled references in
its file descriptors-handling interface. A remote attacker could send
specially-crafted queries to the CUPS server, causing it to crash.
(CVE-2010-0302)

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0129</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0302</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100129"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100140" severity="medium">
    <xccdf:title>RHSA-2010:0140: pango security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

An input sanitization flaw, leading to an array index error, was found in
the way the Pango font rendering library synthesized the Glyph Definition
(GDEF) table from a font's character map and the Unicode property database.
If an attacker created a specially-crafted font file and tricked a local,
unsuspecting user into loading the font file in an application that uses
the Pango font rendering library, it could cause that application to crash.
(CVE-2010-0421)

Users of pango and evolution28-pango are advised to upgrade to these
updated packages, which contain a backported patch to resolve this issue.
After installing this update, you must restart your system or restart your
X session for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0421</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100141" severity="medium">
    <xccdf:title>RHSA-2010:0141: tar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive.

A heap-based buffer overflow flaw was found in the way tar expanded archive
files. If a user were tricked into expanding a specially-crafted archive,
it could cause the tar executable to crash or execute arbitrary code with
the privileges of the user running tar. (CVE-2010-0624)

Red Hat would like to thank Jakob Lell for responsibly reporting the
CVE-2010-0624 issue.

A denial of service flaw was found in the way tar expanded archive files.
If a user expanded a specially-crafted archive, it could cause the tar
executable to crash. (CVE-2007-4476)

Users of tar are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0624</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100141"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100143" severity="medium">
    <xccdf:title>RHSA-2010:0143: cpio security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU cpio copies files into or out of a cpio or tar archive.

A heap-based buffer overflow flaw was found in the way cpio expanded
archive files. If a user were tricked into expanding a specially-crafted
archive, it could cause the cpio executable to crash or execute arbitrary
code with the privileges of the user running cpio. (CVE-2010-0624)

Red Hat would like to thank Jakob Lell for responsibly reporting this
issue.

Users of cpio are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0624</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100143"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100144" severity="medium">
    <xccdf:title>RHSA-2010:0144: cpio security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNU cpio copies files into or out of a cpio or tar archive.

A heap-based buffer overflow flaw was found in the way cpio expanded
archive files. If a user were tricked into expanding a specially-crafted
archive, it could cause the cpio executable to crash or execute arbitrary
code with the privileges of the user running cpio. (CVE-2010-0624)

Red Hat would like to thank Jakob Lell for responsibly reporting the
CVE-2010-0624 issue.

A denial of service flaw was found in the way cpio expanded archive files.
If a user expanded a specially-crafted archive, it could cause the cpio
executable to crash. (CVE-2007-4476)

Users of cpio are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0624</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100144"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100146" severity="high">
    <xccdf:title>RHSA-2010:0146: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a NULL pointer dereference flaw was found in the sctp_rcv_ootb() function
in the Linux kernel Stream Control Transmission Protocol (SCTP)
implementation. A remote attacker could send a specially-crafted SCTP
packet to a target system, resulting in a denial of service.
(CVE-2010-0008, Important)

* a NULL pointer dereference flaw was found in the Linux kernel. During a
core dump, the kernel did not check if the Virtual Dynamically-linked
Shared Object page was accessible. On Intel 64 and AMD64 systems, a local,
unprivileged user could use this flaw to cause a kernel panic by running a
crafted 32-bit application. (CVE-2009-4271, Important)

* an information leak was found in the print_fatal_signal() implementation
in the Linux kernel. When "/proc/sys/kernel/print-fatal-signals" is set to
1 (the default value is 0), memory that is reachable by the kernel could be
leaked to user-space. This issue could also result in a system crash. Note
that this flaw only affected the i386 architecture. (CVE-2010-0003,
Moderate)

* on AMD64 systems, it was discovered that the kernel did not ensure the
ELF interpreter was available before making a call to the SET_PERSONALITY
macro. A local attacker could use this flaw to cause a denial of service by
running a 32-bit application that attempts to execute a 64-bit application.
(CVE-2010-0307, Moderate)

* missing capability checks were found in the ebtables implementation, used
for creating an Ethernet bridge firewall. This could allow a local,
unprivileged user to bypass intended capability restrictions and modify
ebtables rules. (CVE-2010-0007, Low)

This update also fixes the following bugs:

* under some circumstances, a locking bug could have caused an online ext3
file system resize to deadlock, which may have, in turn, caused the file
system or the entire system to become unresponsive. In either case, a
reboot was required after the deadlock. With this update, using resize2fs
to perform an online resize of an ext3 file system works as expected.
(BZ#553135)

* some ATA and SCSI devices were not honoring the barrier=1 mount option,
which could result in data loss after a crash or power loss. This update
applies a patch to the Linux SCSI driver to ensure ordered write caching.
This solution does not provide cache flushes; however, it does provide
data integrity on devices that have no write caching (or where write
caching is disabled) and no command queuing. For systems that have command
queuing or write cache enabled there is no guarantee of data integrity
after a crash. (BZ#560563)

* it was found that lpfc_find_target() could loop continuously when
scanning a list of nodes due to a missing spinlock. This missing spinlock
allowed the list to be changed after the list_empty() test, resulting in a
NULL value, causing the loop. This update adds the spinlock, resolving the
issue. (BZ#561453)

* the fix for CVE-2009-4538 provided by RHSA-2010:0020 introduced a
regression, preventing Wake on LAN (WoL) working for network devices using
the Intel PRO/1000 Linux driver, e1000e. Attempting to configure WoL for
such devices resulted in the following error, even when configuring valid
options:

"Cannot set new wake-on-lan settings: Operation not supported
not setting wol"

This update resolves this regression, and WoL now works as expected for
network devices using the e1000e driver. (BZ#565496)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0307</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100146"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100147" severity="high">
    <xccdf:title>RHSA-2010:0147: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a NULL pointer dereference flaw was found in the sctp_rcv_ootb() function
in the Linux kernel Stream Control Transmission Protocol (SCTP)
implementation. A remote attacker could send a specially-crafted SCTP
packet to a target system, resulting in a denial of service.
(CVE-2010-0008, Important)

* a missing boundary check was found in the do_move_pages() function in the
memory migration functionality in the Linux kernel. A local user could use
this flaw to cause a local denial of service or an information leak.
(CVE-2010-0415, Important)

* a NULL pointer dereference flaw was found in the ip6_dst_lookup_tail()
function in the Linux kernel. An attacker on the local network could
trigger this flaw by sending IPv6 traffic to a target system, leading to a
system crash (kernel OOPS) if dst-&gt;neighbour is NULL on the target system
when receiving an IPv6 packet. (CVE-2010-0437, Important)

* a NULL pointer dereference flaw was found in the ext4 file system code in
the Linux kernel. A local attacker could use this flaw to trigger a local
denial of service by mounting a specially-crafted, journal-less ext4 file
system, if that file system forced an EROFS error. (CVE-2009-4308,
Moderate)

* an information leak was found in the print_fatal_signal() implementation
in the Linux kernel. When "/proc/sys/kernel/print-fatal-signals" is set to
1 (the default value is 0), memory that is reachable by the kernel could be
leaked to user-space. This issue could also result in a system crash. Note
that this flaw only affected the i386 architecture. (CVE-2010-0003,
Moderate)

* missing capability checks were found in the ebtables implementation, used
for creating an Ethernet bridge firewall. This could allow a local,
unprivileged user to bypass intended capability restrictions and modify
ebtables rules. (CVE-2010-0007, Low)

Bug fixes:

* a bug prevented Wake on LAN (WoL) being enabled on certain Intel
hardware. (BZ#543449)

* a race issue in the Journaling Block Device. (BZ#553132)

* 32-bit x86 timespec structures are not the same size as on 64-bit
systems. A 32-bit compatible function -- sys32_sched_rr_get_interval() --
is available. However, when 32-bit programs running on 64-bit systems
called sched_rr_get_interval(), it was not called and the kernel wrote data
past the allocated space, causing user stack corruption.
sys32_sched_rr_get_interval() is now called as expected. (BZ#557684)

* the RHSA-2010:0019 update introduced a regression, preventing WoL from
working for network devices using the e1000e driver. (BZ#559335)

* adding a bonding interface in mode balance-alb to a bridge was not
functional. (BZ#560588)

* some KVM (Kernel-based Virtual Machine) guests experienced slow
performance (and possibly a crash) after suspend/resume. (BZ#560640)

* on some systems, VF cannot be enabled in dom0. (BZ#560665)

* on systems with certain network cards, a system crash occurred after
enabling GRO. (BZ#561417)

* for x86 KVM guests with pvclock enabled, the boot clocks were registered
twice, possibly causing KVM to write data to a random memory area during
the guest's life. (BZ#561454)

* serious performance degradation for 32-bit applications, that map (mmap)
thousands of small files, when run on a 64-bit system. (BZ#562746)

* improved kexec/kdump handling. Previously, on some systems under heavy
load, kexec/kdump was not functional. (BZ#562772)

* dom0 was unable to boot when using the Xen hypervisor on a system with a
large number of logical CPUs. (BZ#562777)

* a fix for a bug that could potentially cause file system corruption.
(BZ#564281)

* a bug caused infrequent cluster issues for users of GFS2. (BZ#564288)

* gfs2_delete_inode failed on read-only file systems. (BZ#564290)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100147"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100153" severity="medium">
    <xccdf:title>RHSA-2010:0153: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2009-2462, CVE-2009-2463, CVE-2009-2466,
CVE-2009-3072, CVE-2009-3075, CVE-2009-3380, CVE-2009-3979, CVE-2010-0159)

A use-after-free flaw was found in Thunderbird. An attacker could use this
flaw to crash Thunderbird or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2009-3077)

A heap-based buffer overflow flaw was found in the Thunderbird string to
floating point conversion routines. An HTML mail message containing
malicious JavaScript could crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2009-0689)

A use-after-free flaw was found in Thunderbird. Under low memory
conditions, viewing an HTML mail message containing malicious content could
result in Thunderbird executing arbitrary code with the privileges of the
user running Thunderbird. (CVE-2009-1571)

A flaw was found in the way Thunderbird created temporary file names for
downloaded files. If a local attacker knows the name of a file Thunderbird
is going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A flaw was found in the way Thunderbird displayed a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differed from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that is different from what the user expected.
(CVE-2009-3376)

A flaw was found in the way Thunderbird processed SOCKS5 proxy replies. A
malicious SOCKS5 server could send a specially-crafted reply that would
cause Thunderbird to crash. (CVE-2009-2470)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing trusted content or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2009-3076)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0171</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100153"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100154" severity="medium">
    <xccdf:title>RHSA-2010:0154: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2009-2462, CVE-2009-2463, CVE-2009-2466,
CVE-2009-3072, CVE-2009-3075, CVE-2009-3380, CVE-2009-3979, CVE-2010-0159)

A use-after-free flaw was found in Thunderbird. An attacker could use this
flaw to crash Thunderbird or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2009-3077)

A heap-based buffer overflow flaw was found in the Thunderbird string to
floating point conversion routines. An HTML mail message containing
malicious JavaScript could crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2009-0689)

A use-after-free flaw was found in Thunderbird. Under low memory
conditions, viewing an HTML mail message containing malicious content could
result in Thunderbird executing arbitrary code with the privileges of the
user running Thunderbird. (CVE-2009-1571)

A flaw was found in the way Thunderbird created temporary file names for
downloaded files. If a local attacker knows the name of a file Thunderbird
is going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A flaw was found in the way Thunderbird displayed a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differed from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that is different from what the user expected.
(CVE-2009-3376)

A flaw was found in the way Thunderbird processed SOCKS5 proxy replies. A
malicious SOCKS5 server could send a specially-crafted reply that would
cause Thunderbird to crash. (CVE-2009-2470)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing trusted content or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2009-3076)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0171</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100162" severity="high">
    <xccdf:title>RHSA-2010:0162: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that OpenSSL did not always check the return value of the
bn_wexpand() function. An attacker able to trigger a memory allocation
failure in that function could cause an application using the OpenSSL
library to crash or, possibly, execute arbitrary code. (CVE-2009-3245)

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
the CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491

A missing return value check flaw was discovered in OpenSSL, that could
possibly cause OpenSSL to call a Kerberos library function with invalid
arguments, resulting in a NULL pointer dereference crash in the MIT
Kerberos library. In certain configurations, a remote attacker could use
this flaw to crash a TLS/SSL server using OpenSSL by requesting Kerberos
cipher suites during the TLS handshake. (CVE-2010-0433)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0433</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100162"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100163" severity="medium">
    <xccdf:title>RHSA-2010:0163: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
the CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491

Dan Kaminsky found that browsers could accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser.
OpenSSL now disables the use of the MD2 algorithm inside signatures by
default. (CVE-2009-2409)

An input validation flaw was found in the handling of the BMPString and
UniversalString ASN1 string types in OpenSSL's ASN1_STRING_print_ex()
function. An attacker could use this flaw to create a specially-crafted
X.509 certificate that could cause applications using the affected function
to crash when printing certificate contents. (CVE-2009-0590)

Note: The affected function is rarely used. No application shipped with Red
Hat Enterprise Linux calls this function, for example.

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100164" severity="medium">
    <xccdf:title>RHSA-2010:0164: openssl097a security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
this flaw: http://kbase.redhat.com/faq/docs/DOC-20491

All openssl097a users should upgrade to these updated packages, which
contain a backported patch to resolve this issue. For the update to take
effect, all services linked to the openssl097a library must be restarted,
or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100165" severity="medium">
    <xccdf:title>RHSA-2010:0165: nss security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv2, SSLv3, TLS,
and other security standards.

Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities. These facilities include threads, thread
synchronization, normal file and network I/O, interval timing, calendar
time, basic memory management (malloc and free), and shared library
linking.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
this flaw: http://kbase.redhat.com/faq/docs/DOC-20491

Users of Red Hat Certificate System 7.3 and 8.0 should review the following
Knowledgebase article before installing this update:
http://kbase.redhat.com/faq/docs/DOC-28439

All users of NSS are advised to upgrade to these updated packages, which
update NSS to version 3.12.6. This erratum also updates the NSPR packages
to the version required by NSS 3.12.6. All running applications using the
NSS library must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100165"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100166" severity="medium">
    <xccdf:title>RHSA-2010:0166: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
the CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491

Dan Kaminsky found that browsers could accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. GnuTLS
now disables the use of the MD2 algorithm inside signatures by default.
(CVE-2009-2409)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all applications linked to the GnuTLS library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100167" severity="medium">
    <xccdf:title>RHSA-2010:0167: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handled session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update addresses this flaw by implementing the
TLS Renegotiation Indication Extension, as defined in RFC 5746.
(CVE-2009-3555)

Refer to the following Knowledgebase article for additional details about
the CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491

A flaw was found in the way GnuTLS extracted serial numbers from X.509
certificates. On 64-bit big endian platforms, this flaw could cause the
certificate revocation list (CRL) check to be bypassed; cause various
GnuTLS utilities to crash; or, possibly, execute arbitrary code.
(CVE-2010-0731)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all applications linked to the GnuTLS library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0731</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100167"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100168" severity="medium">
    <xccdf:title>RHSA-2010:0168: httpd security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

It was discovered that mod_proxy_ajp incorrectly returned an "Internal
Server Error" response when processing certain malformed requests, which
caused the back-end server to be marked as failed in configurations where
mod_proxy is used in load balancer mode. A remote attacker could cause
mod_proxy to not send requests to back-end AJP (Apache JServ Protocol)
servers for the retry timeout period (60 seconds by default) by sending
specially-crafted requests. (CVE-2010-0408)

A use-after-free flaw was discovered in the way the Apache HTTP Server
handled request headers in subrequests. In configurations where subrequests
are used, a multithreaded MPM (Multi-Processing Module) could possibly leak
information from other requests in request replies. (CVE-2010-0434)

This update also adds the following enhancement:

* with the updated openssl packages from RHSA-2010:0162 installed, mod_ssl
will refuse to renegotiate a TLS/SSL connection with an unpatched client
that does not support RFC 5746. This update adds the
"SSLInsecureRenegotiation" configuration directive. If this directive is
enabled, mod_ssl will renegotiate insecurely with unpatched clients.
(BZ#567980)

Refer to the following Red Hat Knowledgebase article for more details about
the changed mod_ssl behavior: http://kbase.redhat.com/faq/docs/DOC-20491

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues and add this enhancement. After
installing the updated packages, the httpd daemon must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0434</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100168"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100173" severity="high">
    <xccdf:title>RHSA-2010:0173: openssl096b security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that OpenSSL did not always check the return value of the
bn_wexpand() function. An attacker able to trigger a memory allocation
failure in that function could cause an application using the OpenSSL
library to crash or, possibly, execute arbitrary code. (CVE-2009-3245)

All openssl096b users should upgrade to these updated packages, which
contain a backported patch to resolve this issue. For the update to take
effect, all programs using the openssl096b library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3245</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100173"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100175" severity="low">
    <xccdf:title>RHSA-2010:0175: httpd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

A use-after-free flaw was discovered in the way the Apache HTTP Server
handled request headers in subrequests. In configurations where subrequests
are used, a multithreaded MPM (Multi-Processing Module) could possibly leak
information from other requests in request replies. (CVE-2010-0434)

This update also fixes the following bug:

* a bug was found in the mod_dav module. If a PUT request for an existing
file failed, that file would be unexpectedly deleted and a "Could not get
next bucket brigade" error logged. With this update, failed PUT requests no
longer cause mod_dav to delete files, which resolves this issue.
(BZ#572932)

As well, this update adds the following enhancement:

* with the updated openssl packages from RHSA-2010:0163 installed, mod_ssl
will refuse to renegotiate a TLS/SSL connection with an unpatched client
that does not support RFC 5746. This update adds the
"SSLInsecureRenegotiation" configuration directive. If this directive is
enabled, mod_ssl will renegotiate insecurely with unpatched clients.
(BZ#575805)

Refer to the following Red Hat Knowledgebase article for more details about
the changed mod_ssl behavior: http://kbase.redhat.com/faq/docs/DOC-20491

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues and add this enhancement. After
installing the updated packages, the httpd daemon must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0434</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100175"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100178" severity="high">
    <xccdf:title>RHSA-2010:0178: Red Hat Enterprise Linux 5.5 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a race condition was found in the mac80211 implementation, a framework
used for writing drivers for wireless devices. An attacker could trigger
this flaw by sending a Delete Block ACK (DELBA) packet to a target system,
resulting in a remote denial of service. Note: This issue only affected
users on 802.11n networks, and that also use the iwlagn driver with Intel
wireless hardware. (CVE-2009-4027, Important)

* a flaw was found in the gfs2_lock() implementation. The GFS2 locking code
could skip the lock operation for files that have the S_ISGID bit
(set-group-ID on execution) in their mode set. A local, unprivileged user
on a system that has a GFS2 file system mounted could use this flaw to
cause a kernel panic. (CVE-2010-0727, Moderate)

* a divide-by-zero flaw was found in the ext4 file system code. A local
attacker could use this flaw to cause a denial of service by mounting a
specially-crafted ext4 file system. (CVE-2009-4307, Low)

These updated packages also include several hundred bug fixes for and
enhancements to the Linux kernel. Space precludes documenting each of these
changes in this advisory and users are directed to the Red Hat Enterprise
Linux 5.5 Release Notes for information on the most significant of these
changes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.5/html/Release_Notes/

Also, for details concerning every bug fixed in and every enhancement added
to the kernel for this release, refer to the kernel chapter in the Red Hat
Enterprise Linux 5.5 Technical Notes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.5/html/Technical_Notes/kernel.html

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which address these vulnerabilities as well as fixing the bugs
and adding the enhancements noted in the Red Hat Enterprise Linux 5.5
Release Notes and Technical Notes. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100178"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100181" severity="low">
    <xccdf:title>RHSA-2010:0181: brltty security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>brltty (Braille TTY) is a background process (daemon) which provides access
to the Linux console (when in text mode) for a blind person using a
refreshable braille display. It drives the braille display, and provides
complete screen review functionality.

It was discovered that a brltty library had an insecure relative RPATH
(runtime library search path) set in the ELF (Executable and Linking
Format) header. A local user able to convince another user to run an
application using brltty in an attacker-controlled directory, could run
arbitrary code with the privileges of the victim. (CVE-2008-3279)

These updated packages also provide fixes for the following bugs:

* the brltty configuration file is documented in the brltty manual page,
but there is no separate manual page for the /etc/brltty.conf configuration
file: running "man brltty.conf" returned "No manual entry for brltty.conf"
rather than opening the brltty manual entry. This update adds brltty.conf.5
as an alias to the brltty manual page. Consequently, running "man
brltty.conf" now opens the manual entry documenting the brltty.conf
specification. (BZ#530554)

* previously, the brltty-pm.conf configuration file was installed in the
/etc/brltty/ directory. This file, which configures Papenmeier Braille
Terminals for use with Red Hat Enterprise Linux, is optional. As well, it
did not come with a corresponding manual page. With this update, the file
has been moved to /usr/share/doc/brltty-3.7.2/BrailleDrivers/Papenmeier/.
This directory also includes a README document that explains the file's
purpose and format. (BZ#530554)

* during the brltty packages installation, the message

Creating screen inspection device /dev/vcsa...done.

was presented at the console. This was inadequate, especially during the
initial install of the system. These updated packages do not send any
message to the console during installation. (BZ#529163)

* although brltty contains ELF objects, the brltty-debuginfo package was
empty. With this update, the -debuginfo package contains valid debugging
information as expected. (BZ#500545)

* the MAX_NR_CONSOLES definition was acquired by brltty by #including
linux/tty.h in Programs/api_client.c. MAX_NR_CONSOLES has since moved to
linux/vt.h but the #include in api_client.c was not updated. Consequently,
brltty could not be built from the source RPM against the Red Hat
Enterprise Linux 5 kernel. This update corrects the #include in
api_client.c to linux/vt.h and brltty now builds from source as expected.
(BZ#456247)

All brltty users are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3279</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100181"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100198" severity="medium">
    <xccdf:title>RHSA-2010:0198: openldap security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick applications using OpenLDAP libraries into accepting it by
mistake, allowing the attacker to perform a man-in-the-middle attack.
(CVE-2009-3767)

This update also fixes the following bugs:

* the ldap init script did not provide a way to alter system limits for the
slapd daemon. A variable is now available in "/etc/sysconfig/ldap" for this
option. (BZ#527313)

* applications that use the OpenLDAP libraries to contact a Microsoft
Active Directory server could crash when a large number of network
interfaces existed. This update implements locks in the OpenLDAP library
code to resolve this issue. (BZ#510522)

* when slapd was configured to allow client certificates, approximately 90%
of connections froze because of a large CA certificate file and slapd not
checking the success of the SSL handshake. (BZ#509230)

* the OpenLDAP server would freeze for unknown reasons under high load.
These packages add support for accepting incoming connections by new
threads, resolving the issue. (BZ#507276)

* the compat-openldap libraries did not list dependencies on other
libraries, causing programs that did not specifically specify the libraries
to fail. Detection of the Application Binary Interface (ABI) in use on
64-bit systems has been added with this update. (BZ#503734)

* the OpenLDAP libraries caused applications to crash due to an unprocessed
network timeout. A timeval of -1 is now passed when NULL is passed to LDAP.
(BZ#495701)

* slapd could crash on a server under heavy load when using rwm overlay,
caused by freeing non-allocated memory during operation cleanup.
(BZ#495628)

* the ldap init script made a temporary script in "/tmp/" and attempted to
execute it. Problems arose when "/tmp/" was mounted with the noexec option.
The temporary script is no longer created. (BZ#483356)

* the ldap init script always started slapd listening on ldap:/// even if
instructed to listen only on ldaps:///. By correcting the init script, a
user can now select which ports slapd should listen on. (BZ#481003)

* the slapd manual page did not mention the supported options -V and -o.
(BZ#468206)

* slapd.conf had a commented-out option to load the syncprov.la module.
Once un-commented, slapd crashed at start-up because the module had already
been statically linked to OpenLDAP. This update removes "moduleload
syncprov.la" from slapd.conf, which resolves this issue. (BZ#466937)

* the migrate_automount.pl script produced output that was unsupported by
autofs. This is corrected by updating the output LDIF format for automount
records. (BZ#460331)

* the ldap init script uses the TERM signal followed by the KILL signal
when shutting down slapd. Minimal delay between the two signals could cause
the LDAP database to become corrupted if it had not finished saving its
state. A delay between the signals has been added via the "STOP_DELAY"
option in "/etc/sysconfig/ldap". (BZ#452064)

* the migrate_passwd.pl migration script had a problem when number fields
contained only a zero. Such fields were considered to be empty, leading to
the attribute not being set in the LDIF output. The condition in
dump_shadow_attributes has been corrected to allow for the attributes to
contain only a zero. (BZ#113857)

* the migrate_base.pl migration script did not handle third level domains
correctly, creating a second level domain that could not be held by a
database with a three level base. This is now allowed by modifying the
migrate_base.pl script to generate only one domain. (BZ#104585)

Users of OpenLDAP should upgrade to these updated packages, which resolve
these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3767</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100198"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100221" severity="low">
    <xccdf:title>RHSA-2010:0221: squid security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A flaw was found in the way Squid processed certain external ACL helper
HTTP header fields that contained a delimiter that was not a comma. A
remote attacker could issue a crafted request to the Squid server, causing
excessive CPU use (up to 100%). (CVE-2009-2855)

Note: The CVE-2009-2855 issue only affected non-default configurations that
use an external ACL helper script.

A flaw was found in the way Squid handled truncated DNS replies. A remote
attacker able to send specially-crafted UDP packets to Squid's DNS client
port could trigger an assertion failure in Squid's child process, causing
that child process to exit. (CVE-2010-0308)

This update also fixes the following bugs:

* Squid's init script returns a non-zero value when trying to stop a
stopped service. This is not LSB compliant and can generate difficulties in
cluster environments. This update makes stopping LSB compliant. (BZ#521926)

* Squid is not currently built to support MAC address filtering in ACLs.
This update includes support for MAC address filtering. (BZ#496170)

* Squid is not currently built to support Kerberos negotiate
authentication. This update enables Kerberos authentication. (BZ#516245)

* Squid does not include the port number as part of URIs it constructs when
configured as an accelerator. This results in a 403 error. This update
corrects this behavior. (BZ#538738)

* the error_map feature does not work if the same handling is set also on
the HTTP server that operates in deflate mode. This update fixes this
issue. (BZ#470843)

All users of squid should upgrade to this updated package, which resolves
these issues. After installing this update, the squid service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2855</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0308</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100221"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100237" severity="low">
    <xccdf:title>RHSA-2010:0237: sendmail security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sendmail is a very widely used Mail Transport Agent (MTA). MTAs deliver
mail from one machine to another. Sendmail is not a client program, but
rather a behind-the-scenes daemon that moves email over networks or the
Internet to its final destination.

The configuration of sendmail in Red Hat Enterprise Linux was found to not
reject the "localhost.localdomain" domain name for email messages that come
from external hosts. This could allow remote attackers to disguise spoofed
messages. (CVE-2006-7176)

A flaw was found in the way sendmail handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick sendmail into accepting it by mistake, allowing the attacker to
perform a man-in-the-middle attack or bypass intended client certificate
authentication. (CVE-2009-4565)

Note: The CVE-2009-4565 issue only affected configurations using TLS with
certificate verification and CommonName checking enabled, which is not a
typical configuration.

This update also fixes the following bugs:

* sendmail was unable to parse files specified by the ServiceSwitchFile
option which used a colon as a separator. (BZ#512871)

* sendmail incorrectly returned a zero exit code when free space was low.
(BZ#299951)

* the sendmail manual page had a blank space between the -qG option and
parameter. (BZ#250552)

* the comments in the sendmail.mc file specified the wrong path to SSL
certificates. (BZ#244012)

* the sendmail packages did not provide the MTA capability. (BZ#494408)

All users of sendmail are advised to upgrade to these updated packages,
which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4565</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100237"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100258" severity="low">
    <xccdf:title>RHSA-2010:0258: pam_krb5 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware
applications to use Kerberos to verify user identities by obtaining user
credentials at log in time.

A flaw was found in pam_krb5. In some non-default configurations
(specifically, those where pam_krb5 would be the first module to prompt for
a password), the text of the password prompt varied based on whether or not
the username provided was a username known to the system. A remote attacker
could use this flaw to recognize valid usernames, which would aid a
dictionary-based password guess attack. (CVE-2009-1384)

This update also fixes the following bugs:

* certain applications which do not properly implement PAM conversations
may fail to authenticate users whose passwords have expired and must be
changed, or may succeed without forcing the user's password to be changed.
This bug is triggered by a previously-applied fix to pam_krb5 which makes
it comply more closely to PAM specifications. If an application misbehaves,
enabling the "chpw_prompt" option for its service should restore the old
behavior. (BZ#509092)

* pam_krb5 does not allow the user to change an expired password in cases
where the Key Distribution Center (KDC) is configured to refuse attempts to
obtain forwardable password-changing credentials. This update fixes this
issue. (BZ#489015)

* failure to verify TGT because of wrong keytab handling. (BZ#450776)

Users of pam_krb5 are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1384</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100258"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100271" severity="high">
    <xccdf:title>RHSA-2010:0271: kvm security, bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way QEMU-KVM handled erroneous data provided by
the Linux virtio-net driver, used by guest operating systems. Due to a
deficiency in the TSO (TCP segment offloading) implementation, a guest's
virtio-net driver would transmit improper data to a certain QEMU-KVM
process on the host, causing the guest to crash. A remote attacker could
use this flaw to send specially-crafted data to a target guest system,
causing that guest to crash. (CVE-2010-0741)

Additionally, these updated packages include numerous bug fixes and
enhancements. Refer to the KVM chapter of the Red Hat Enterprise Linux 5.5
Technical Notes for details:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.5/html/Technical_Notes/kvm.html       

All KVM users should upgrade to these updated packages, which resolve this
issue as well as fixing the bugs and adding the enhancements noted in the
Technical Notes. Note: The procedure in the Solution section must be
performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0741</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100271"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100273" severity="medium">
    <xccdf:title>RHSA-2010:0273: curl security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and DICT
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

Wesley Miaw discovered that when deflate compression was used, libcurl
could call the registered write callback function with data exceeding the
documented limit. A malicious server could use this flaw to crash an
application using libcurl or, potentially, execute arbitrary code. Note:
This issue only affected applications using libcurl that rely on the
documented data size limit, and that copy the data to the insufficiently
sized buffer. (CVE-2010-0734)

This update also fixes the following bugs:

* when using curl to upload a file, if the connection was broken or reset
by the server during the transfer, curl immediately started using 100% CPU
and failed to acknowledge that the transfer had failed. With this update,
curl displays an appropriate error message and exits when an upload fails
mid-transfer due to a broken or reset connection. (BZ#479967)

* libcurl experienced a segmentation fault when attempting to reuse a
connection after performing GSS-negotiate authentication, which in turn
caused the curl program to crash. This update fixes this bug so that reused
connections are able to be successfully established even after
GSS-negotiate authentication has been performed. (BZ#517199)

As well, this update adds the following enhancements:

* curl now supports loading Certificate Revocation Lists (CRLs) from a
Privacy Enhanced Mail (PEM) file. When curl attempts to access sites that
have had their certificate revoked in a CRL, curl refuses access to those
sites. (BZ#532069)

* the curl(1) manual page has been updated to clarify that the "--socks4"
and "--socks5" options do not work with the IPv6, FTPS, or LDAP protocols.
(BZ#473128)

* the curl utility's program help, which is accessed by running "curl -h",
has been updated with descriptions for the "--ftp-account" and
"--ftp-alternative-to-user" options. (BZ#517084)

Users of curl should upgrade to these updated packages, which contain
backported patches to correct these issues and add these enhancements. All
running applications using libcurl must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0734</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100273"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100291" severity="medium">
    <xccdf:title>RHSA-2010:0291: gfs-kmod security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gfs-kmod packages contain modules that provide the ability to mount and
use GFS file systems.

A flaw was found in the gfs_lock() implementation. The GFS locking code
could skip the lock operation for files that have the S_ISGID bit
(set-group-ID on execution) in their mode set. A local, unprivileged user
on a system that has a GFS file system mounted could use this flaw to cause
a kernel panic. (CVE-2010-0727)

These updated gfs-kmod packages are in sync with the latest kernel
(2.6.18-194.el5). The modules in earlier gfs-kmod packages failed to load
because they did not match the running kernel. It was possible to
force-load the modules. With this update, however, users no longer need to.

These updated gfs-kmod packages also fix the following bugs:

* when SELinux was in permissive mode, a race condition during file
creation could have caused one or more cluster nodes to be fenced and lock
the remaining nodes out of the GFS file system. This race condition no
longer occurs with this update. (BZ#471258)

* when ACLs (Access Control Lists) are enabled on a GFS file system, if a
transaction that has started to do a write request does not have enough
spare blocks for the operation it causes a kernel panic. This update
ensures that there are enough blocks for the write request before starting
the operation. (BZ#513885)

* requesting a "flock" on a file in GFS in either read-only or read-write
mode would sometimes cause a "Resource temporarily unavailable" state error
(error 11 for EWOULDBLOCK) to occur. In these cases, a flock could not be
obtained on the file in question. This has been fixed with this update so
that flocks can successfully be obtained on GFS files without this error
occurring. (BZ#515717)

* the GFS withdraw function is a data integrity feature of GFS file systems
in a cluster. If the GFS kernel module detects an inconsistency in a GFS
file system following an I/O operation, the file system becomes unavailable
to the cluster. The GFS withdraw function is less severe than a kernel
panic, which would cause another node to fence the node. With this update,
you can override the GFS withdraw function by mounting the file system with
the "-o errors=panic" option specified. When this option is specified, any
errors that would normally cause the system to withdraw cause the system to
panic instead. This stops the node's cluster communications, which causes
the node to be fenced. (BZ#517145)

Finally, these updated gfs-kmod packages provide the following enhancement:

* the GFS kernel modules have been updated to use the new generic freeze
and unfreeze ioctl interface that is also supported by the following file
systems: ext3, ext4, GFS2, JFS and ReiserFS. With this update, GFS supports
freeze/unfreeze through the VFS-level FIFREEZE/FITHAW ioctl interface.
(BZ#487610)

Users are advised to upgrade to these latest gfs-kmod packages, updated for
use with the 2.6.18-194.el5 kernel, which contain backported patches to
correct these issues, fix these bugs, and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0291</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0727</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100291"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100321" severity="low">
    <xccdf:title>RHSA-2010:0321: automake security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Automake is a tool for automatically generating Makefile.in files compliant
with the GNU Coding Standards.

Automake-generated Makefiles made certain directories world-writable when
preparing source archives, as was recommended by the GNU Coding Standards.
If a malicious, local user could access the directory where a victim was
creating distribution archives, they could use this flaw to modify the
files being added to those archives. Makefiles generated by these updated
automake packages no longer make distribution directories world-writable,
as recommended by the updated GNU Coding Standards. (CVE-2009-4029)

Note: This issue affected Makefile targets used by developers to prepare
distribution source archives. Those targets are not used when compiling
programs from the source code.

All users of automake, automake14, automake15, automake16, and automake17
should upgrade to these updated packages, which resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100321"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100329" severity="medium">
    <xccdf:title>RHSA-2010:0329: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and DICT
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

Wesley Miaw discovered that when deflate compression was used, libcurl
could call the registered write callback function with data exceeding the
documented limit. A malicious server could use this flaw to crash an
application using libcurl or, potentially, execute arbitrary code. Note:
This issue only affected applications using libcurl that rely on the
documented data size limit, and that copy the data to the insufficiently
sized buffer. (CVE-2010-0734)

Users of curl should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0734</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100329"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100332" severity="high">
    <xccdf:title>RHSA-2010:0332: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several use-after-free flaws were found in Firefox. Visiting a web page
containing malicious content could result in Firefox executing arbitrary
code with the privileges of the user running Firefox. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)

A flaw was found in Firefox that could allow an applet to generate a drag
and drop action from a mouse click. Such an action could be used to execute
arbitrary JavaScript with the privileges of the user running Firefox.
(CVE-2010-0178)

A privilege escalation flaw was found in Firefox when the Firebug add-on is
in use. The XMLHttpRequestSpy module in the Firebug add-on exposes a Chrome
privilege escalation flaw that could be used to execute arbitrary
JavaScript with the privileges of the user running Firefox. (CVE-2010-0179)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-0174)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.19. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.19, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0332</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0179</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100332"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100333" severity="high">
    <xccdf:title>RHSA-2010:0333: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several use-after-free flaws were found in SeaMonkey. Visiting a web page
containing malicious content could result in SeaMonkey executing arbitrary
code with the privileges of the user running SeaMonkey. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-0174)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0333</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0177</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100333"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100339" severity="high">
    <xccdf:title>RHSA-2010:0339: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. (CVE-2009-3555)

This update disables renegotiation in the Java Secure Socket Extension
(JSSE) component. Unsafe renegotiation can be re-enabled using the
sun.security.ssl.allowUnsafeRenegotiation property. Refer to the following
Knowledgebase article for details:
http://kbase.redhat.com/faq/docs/DOC-20491

A number of flaws have been fixed in the Java Virtual Machine (JVM) and in
various Java class implementations. These flaws could allow an unsigned
applet or application to bypass intended access restrictions.
(CVE-2010-0082, CVE-2010-0084, CVE-2010-0085, CVE-2010-0088, CVE-2010-0094)

An untrusted applet could access clipboard information if a drag operation
was performed over that applet's canvas. This could lead to an information
leak. (CVE-2010-0091)

The rawIndex operation incorrectly handled large values, causing the
corruption of internal memory structures, resulting in an untrusted applet
or application crashing. (CVE-2010-0092)

The System.arraycopy operation incorrectly handled large index values,
potentially causing array corruption in an untrusted applet or application.
(CVE-2010-0093)

Subclasses of InetAddress may incorrectly interpret network addresses,
allowing an untrusted applet or application to bypass network access
restrictions. (CVE-2010-0095)

In certain cases, type assignments could result in "non-exact" interface
types. This could be used to bypass type-safety restrictions.
(CVE-2010-0845)

A buffer overflow flaw in LittleCMS (embedded in OpenJDK) could cause an
untrusted applet or application using color profiles from untrusted sources
to crash. (CVE-2010-0838)

An input validation flaw was found in the JRE unpack200 functionality. An
untrusted applet or application could use this flaw to elevate its
privileges. (CVE-2010-0837)

Deferred calls to trusted applet methods could be granted incorrect
permissions, allowing an untrusted applet or application to extend its
privileges. (CVE-2010-0840)

A missing input validation flaw in the JRE could allow an attacker to crash
an untrusted applet or application. (CVE-2010-0848)

A flaw in Java2D could allow an attacker to execute arbitrary code with the
privileges of a user running an untrusted applet or application that uses
Java2D. (CVE-2010-0847)

Note: The flaws concerning applets in this advisory, CVE-2010-0082,
CVE-2010-0084, CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0092,
CVE-2010-0093, CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838,
CVE-2010-0840, CVE-2010-0847, and CVE-2010-0848, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

This update also provides three defense in depth patches. (BZ#575745,
BZ#575861, BZ#575789)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0848</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100339"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100343" severity="high">
    <xccdf:title>RHSA-2010:0343: krb5 security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

A use-after-free flaw was discovered in the MIT Kerberos administration
daemon, kadmind. A remote, authenticated attacker could use this flaw to
crash the kadmind daemon. Administrative privileges are not required to
trigger this flaw, as any realm user can request information about their
own principal from kadmind. (CVE-2010-0629)

This update also fixes the following bug:

* when a Kerberos client seeks tickets for use with a service, it must
contact the Key Distribution Center (KDC) to obtain them. The client must
also determine which realm the service belongs to and it typically does
this with a combination of client configuration detail, DNS information and
guesswork.

If the service belongs to a realm other than the client's, cross-realm
authentication is required. Using a combination of client configuration and
guesswork, the client determines the trust relationship sequence which
forms the trusted path between the client's realm and the service's realm.
This may include one or more intermediate realms.

Anticipating the KDC has better knowledge of extant trust relationships,
the client then requests a ticket from the service's KDC, indicating it
will accept guidance from the service's KDC by setting a special flag in
the request. A KDC which recognizes the flag can, at its option, return a
ticket-granting ticket for the next realm along the trust path the client
should be following.

If the ticket-granting ticket returned by the service's KDC is for use with
a realm the client has already determined was in the trusted path, the
client accepts this as an optimization and continues. If, however, the
ticket is for use in a realm the client is not expecting, the client
responds incorrectly: it treats the case as an error rather than continuing
along the path suggested by the service's KDC.

For this update, the krb5 1.7 modifications which allow the client to trust
such KDCs to send them along the correct path, resulting in the client
obtaining the tickets it originally desired, were backported to krb 1.6.1
(the version shipped with Red Hat Enterprise Linux 5.5). (BZ#578540)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running KDC services must
be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0629</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100343"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100347" severity="medium">
    <xccdf:title>RHSA-2010:0347: nss_db security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nss_db packages provide a set of C library extensions which allow
Berkeley Database (Berkeley DB) databases to be used as a primary source of
aliases, ethers, groups, hosts, networks, protocols, users, RPCs, services,
and shadow passwords. These databases are used instead of or in addition to
the flat files used by these tools by default.

It was discovered that nss_db did not specify a path to the directory to be
used as the database environment for the Berkeley Database library, causing
it to use the current working directory as the default. This could possibly
allow a local attacker to obtain sensitive information. (CVE-2010-0826)

Users of nss_db are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0826</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100347"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100348" severity="high">
    <xccdf:title>RHSA-2010:0348: kdebase security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The K Desktop Environment (KDE) is a graphical desktop environment for the
X Window System. The kdebase packages include core applications for KDE.

A privilege escalation flaw was found in the KDE Display Manager (KDM). A
local user with console access could trigger a race condition, possibly
resulting in the permissions of an arbitrary file being set to world
writable, allowing privilege escalation. (CVE-2010-0436)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
responsibly reporting this issue.

Users of KDE should upgrade to these updated packages, which contain a
backported patch to correct this issue. The system should be rebooted for
this update to take effect. After the reboot, administrators should
manually remove all leftover user-owned dmctl-* directories in
"/var/run/xdmctl/".</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0436</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100348"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100360" severity="medium">
    <xccdf:title>RHSA-2010:0360: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

An invalid pointer dereference flaw was found in the Wireshark SMB and SMB2
dissectors. If Wireshark read a malformed packet off a network or opened a
malicious dump file, it could crash or, possibly, execute arbitrary code as
the user running Wireshark. (CVE-2009-4377)

Several buffer overflow flaws were found in the Wireshark LWRES dissector.
If Wireshark read a malformed packet off a network or opened a malicious
dump file, it could crash or, possibly, execute arbitrary code as the user
running Wireshark. (CVE-2010-0304)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2009-2560, CVE-2009-2562, CVE-2009-2563,
CVE-2009-3550, CVE-2009-3829)

Users of Wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.11, and resolve these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0360</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2560</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3550</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0304</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100360"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100361" severity="medium">
    <xccdf:title>RHSA-2010:0361: sudo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

The RHBA-2010:0212 sudo update released as part of Red Hat Enterprise Linux
5.5 added the ability to change the value of the ignore_dot option in the
"/etc/sudoers" configuration file. This ability introduced a regression in
the upstream fix for CVE-2010-0426. In configurations where the ignore_dot
option was set to off (the default is on for the Red Hat Enterprise Linux 5
sudo package), a local user authorized to use the sudoedit pseudo-command
could possibly run arbitrary commands with the privileges of the users
sudoedit was authorized to run as. (CVE-2010-1163)

Red Hat would like to thank Todd C. Miller, the upstream sudo maintainer,
for responsibly reporting this issue. Upstream acknowledges Valerio
Costamagna as the original reporter.

Users of sudo should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0361</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1163</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100361"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100362" severity="high">
    <xccdf:title>RHSA-2010:0362: scsi-target-utils security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The scsi-target-utils package contains the daemon and tools to set up and
monitor SCSI targets. Currently, iSCSI software and iSER targets are
supported.

A format string flaw was found in scsi-target-utils' tgtd daemon. A
remote attacker could trigger this flaw by sending a carefully-crafted
Internet Storage Name Service (iSNS) request, causing the tgtd daemon to
crash. (CVE-2010-0743)

All scsi-target-utils users should upgrade to this updated package, which
contains a backported patch to correct this issue. All running
scsi-target-utils services must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0743</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100362"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100382" severity="high">
    <xccdf:title>RHSA-2010:0382: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

An incorrect calculation flaw was discovered in the X.Org Render extension.
A malicious, authorized client could exploit this issue to crash the X.Org
server or, potentially, execute arbitrary code with root privileges.
(CVE-2010-1166)

Users of xorg-x11-server should upgrade to these updated packages, which
contain a backported patch to resolve this issue. All running X.Org server
instances must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1166</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100382"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100394" severity="high">
    <xccdf:title>RHSA-2010:0394: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* RHSA-2009:1024 introduced a flaw in the ptrace implementation on Itanium
systems. ptrace_check_attach() was not called during certain ptrace()
requests. Under certain circumstances, a local, unprivileged user could use
this flaw to call ptrace() on a process they do not own, giving them
control over that process. (CVE-2010-0729, Important)

* a flaw was found in the kernel's Unidirectional Lightweight Encapsulation
(ULE) implementation. A remote attacker could send a specially-crafted ISO
MPEG-2 Transport Stream (TS) frame to a target system, resulting in a
denial of service. (CVE-2010-1086, Important)

* a use-after-free flaw was found in tcp_rcv_state_process() in the
kernel's TCP/IP protocol suite implementation. If a system using IPv6 had
the IPV6_RECVPKTINFO option set on a listening socket, a remote attacker
could send an IPv6 packet to that system, causing a kernel panic.
(CVE-2010-1188, Important)

* a divide-by-zero flaw was found in azx_position_ok() in the Intel High
Definition Audio driver, snd-hda-intel. A local, unprivileged user could
trigger this flaw to cause a denial of service. (CVE-2010-1085, Moderate)

* an information leak flaw was found in the kernel's USB implementation.
Certain USB errors could result in an uninitialized kernel buffer being
sent to user-space. An attacker with physical access to a target system
could use this flaw to cause an information leak. (CVE-2010-1083, Low)

Red Hat would like to thank Ang Way Chuang for reporting CVE-2010-1086.

Bug fixes:

* a regression prevented the Broadcom BCM5761 network device from working
when in the first (top) PCI-E slot of Hewlett-Packard (HP) Z600 systems.
Note: The card worked in the 2nd or 3rd PCI-E slot. (BZ#567205)

* the Xen hypervisor supports 168 GB of RAM for 32-bit guests. The physical
address range was set incorrectly, however, causing 32-bit,
para-virtualized Red Hat Enterprise Linux 4.8 guests to crash when launched
on AMD64 or Intel 64 hosts that have more than 64 GB of RAM. (BZ#574392)

* RHSA-2009:1024 introduced a regression, causing diskdump to fail on
systems with certain adapters using the qla2xxx driver. (BZ#577234)

* a race condition caused TX to stop in a guest using the virtio_net
driver. (BZ#580089)

* on some systems, using the "arp_validate=3" bonding option caused both
links to show as "down" even though the arp_target was responding to ARP
requests sent by the bonding driver. (BZ#580842)

* in some circumstances, when a Red Hat Enterprise Linux client connected
to a re-booted Windows-based NFS server, server-side filehandle-to-inode
mapping changes caused a kernel panic. "bad_inode_ops" handling was changed
to prevent this. Note: filehandle-to-inode mapping changes may still cause
errors, but not panics. (BZ#582908)

* when installing a Red Hat Enterprise Linux 4 guest via PXE, hard-coded
fixed-size scatterlists could conflict with host requests, causing the
guest's kernel to panic. With this update, dynamically allocated
scatterlists are used, resolving this issue. (BZ#582911)

Enhancements:

* kernel support for connlimit. Note: iptables errata update RHBA-2010:0395
is also required for connlimit to work correctly. (BZ#563223)

* support for the Intel architectural performance monitoring subsystem
(arch_perfmon). On supported CPUs, arch_perfmon offers means to mark
performance events and options for configuring and counting these events.
(BZ#582913)

* kernel support for OProfile sampling of Intel microarchitecture (Nehalem)
CPUs. This update alone does not address OProfile support for such CPUs. A
future oprofile package update will allow OProfile to work on Intel Nehalem
CPUs. (BZ#582241)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add these enhancements. The system must
be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0394</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100394"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100398" severity="high">
    <xccdf:title>RHSA-2010:0398: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in the Unidirectional Lightweight Encapsulation (ULE)
implementation. A remote attacker could send a specially-crafted ISO
MPEG-2 Transport Stream (TS) frame to a target system, resulting in an
infinite loop (denial of service). (CVE-2010-1086, Important)

* on AMD64 systems, it was discovered that the kernel did not ensure the
ELF interpreter was available before making a call to the SET_PERSONALITY
macro. A local attacker could use this flaw to cause a denial of service by
running a 32-bit application that attempts to execute a 64-bit application.
(CVE-2010-0307, Moderate)

* a flaw was found in the kernel connector implementation. A local,
unprivileged user could trigger this flaw by sending an arbitrary number
of notification requests using specially-crafted netlink messages,
resulting in a denial of service. (CVE-2010-0410, Moderate)

* a flaw was found in the Memory-mapped I/O (MMIO) instruction decoder in
the Xen hypervisor implementation. An unprivileged guest user could use
this flaw to trick the hypervisor into emulating a certain instruction,
which could crash the guest (denial of service). (CVE-2010-0730, Moderate)

* a divide-by-zero flaw was found in the azx_position_ok() function in the
driver for Intel High Definition Audio, snd-hda-intel. A local,
unprivileged user could trigger this flaw to cause a kernel crash (denial
of service). (CVE-2010-1085, Moderate)

This update also fixes the following bugs:

* in some cases, booting a system with the "iommu=on" kernel parameter
resulted in a Xen hypervisor panic. (BZ#580199)

* the fnic driver flushed the Rx queue instead of the Tx queue after
fabric login. This caused crashes in some cases. (BZ#580829)

* "kernel unaligned access" warnings were logged to the dmesg log on some
systems. (BZ#580832)

* the "Northbridge Error, node 1, core: -1 K8 ECC error" error occurred on
some systems using the amd64_edac driver. (BZ#580836)

* in rare circumstances, when using kdump and booting a kernel with
"crashkernel=128M@16M", the kdump kernel did not boot after a crash.
(BZ#580838)

* TLB page table entry flushing was done incorrectly on IBM System z,
possibly causing crashes, subtle data inconsistency, or other issues.
(BZ#580839)

* iSCSI failover times were slower than in Red Hat Enterprise Linux 5.3.
(BZ#580840)

* fixed floating point state corruption after signal. (BZ#580841)

* in certain circumstances, under heavy load, certain network interface
cards using the bnx2 driver and configured to use MSI-X, could stop
processing interrupts and then network connectivity would cease.
(BZ#587799)

* cnic parts resets could cause a deadlock when the bnx2 device was
enslaved in a bonding device and that device had an associated VLAN.
(BZ#581148)

* some BIOS implementations initialized interrupt remapping hardware in a
way the Xen hypervisor implementation did not expect. This could have
caused a system hang during boot. (BZ#581150)

* AMD Magny-Cours systems panicked when booting a 32-bit kernel.
(BZ#580846)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1086</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100398"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100399" severity="medium">
    <xccdf:title>RHSA-2010:0399: tetex security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>teTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (DVI) file as output.

A buffer overflow flaw was found in the way teTeX processed virtual font
files when converting DVI files into PostScript. An attacker could create a
malicious DVI file that would cause the dvips executable to crash or,
potentially, execute arbitrary code. (CVE-2010-0827)

Multiple integer overflow flaws were found in the way teTeX processed
special commands when converting DVI files into PostScript. An attacker
could create a malicious DVI file that would cause the dvips executable to
crash or, potentially, execute arbitrary code. (CVE-2010-0739,
CVE-2010-1440)

A stack-based buffer overflow flaw was found in the way teTeX processed DVI
files containing HyperTeX references with long titles, when converting them
into PostScript. An attacker could create a malicious DVI file that would
cause the dvips executable to crash. (CVE-2007-5935)

teTeX embeds a copy of Xpdf, an open source Portable Document Format (PDF)
file viewer, to allow adding images in PDF format to the generated PDF
documents. The following issues affect Xpdf code:

Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0147, CVE-2009-1179)

Multiple integer overflow flaws were found in Xpdf. If a local user
generated a PDF file from a TeX document, referencing a specially-crafted
PDF file, it would cause Xpdf to crash or, potentially, execute arbitrary
code with the privileges of the user running pdflatex. (CVE-2009-0791,
CVE-2009-3609)

A heap-based buffer overflow flaw was found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0195)

Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. If a local user generated a PDF file from a
TeX document, referencing a specially-crafted PDF file, it would cause
Xpdf to crash or, potentially, execute arbitrary code with the privileges
of the user running pdflatex. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0800)

Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash. (CVE-2009-0799,
CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, Will Dormann of the CERT/CC, and Alin Rad Pop of Secunia
Research, for responsibly reporting the Xpdf flaws.

All users of tetex are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0399</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1440</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100399"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100400" severity="medium">
    <xccdf:title>RHSA-2010:0400: tetex security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>teTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (DVI) file as output.

Multiple integer overflow flaws were found in the way teTeX processed
special commands when converting DVI files into PostScript. An attacker
could create a malicious DVI file that would cause the dvips executable to
crash or, potentially, execute arbitrary code. (CVE-2010-0739,
CVE-2010-1440)

Multiple array index errors were found in the way teTeX converted DVI files
into the Portable Network Graphics (PNG) format. An attacker could create a
malicious DVI file that would cause the dvipng executable to crash.
(CVE-2010-0829)

teTeX embeds a copy of Xpdf, an open source Portable Document Format (PDF)
file viewer, to allow adding images in PDF format to the generated PDF
documents. The following issues affect Xpdf code:

Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0147, CVE-2009-1179)

Multiple integer overflow flaws were found in Xpdf. If a local user
generated a PDF file from a TeX document, referencing a specially-crafted
PDF file, it would cause Xpdf to crash or, potentially, execute arbitrary
code with the privileges of the user running pdflatex. (CVE-2009-0791,
CVE-2009-3608, CVE-2009-3609)

A heap-based buffer overflow flaw was found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0195)

Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. If a local user generated a PDF file from a
TeX document, referencing a specially-crafted PDF file, it would cause
Xpdf to crash or, potentially, execute arbitrary code with the privileges
of the user running pdflatex. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash or, potentially,
execute arbitrary code with the privileges of the user running pdflatex.
(CVE-2009-0800)

Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. If a
local user generated a PDF file from a TeX document, referencing a
specially-crafted PDF file, it would cause Xpdf to crash. (CVE-2009-0799,
CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, Will Dormann of the CERT/CC, Alin Rad Pop of Secunia
Research, and Chris Rohlf, for responsibly reporting the Xpdf flaws.

All users of tetex are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0400</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1440</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100400"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100423" severity="high">
    <xccdf:title>RHSA-2010:0423: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was discovered in the MIT Kerberos Generic
Security Service Application Program Interface (GSS-API) library. A remote,
authenticated attacker could use this flaw to crash any server application
using the GSS-API authentication mechanism, by sending a specially-crafted
GSS-API token with a missing checksum field. (CVE-2010-1321)

Red Hat would like to thank the MIT Kerberos Team for responsibly reporting
this issue. Upstream acknowledges Shawn Emery of Oracle as the original
reporter.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1321</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100423"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100428" severity="medium">
    <xccdf:title>RHSA-2010:0428: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS). PL/Perl and PL/Tcl allow users to write PostgreSQL functions in the
Perl and Tcl languages, and are installed in trusted mode by default. In
trusted mode, certain operations, such as operating system level access,
are restricted.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Perl. If the PL/Perl procedural language was
registered on a particular database, an authenticated database user running
a specially-crafted PL/Perl script could use this flaw to bypass intended
PL/Perl trusted mode restrictions, allowing them to run arbitrary Perl
scripts with the privileges of the database server. (CVE-2010-1169)

Red Hat would like to thank Tim Bunce for responsibly reporting the
CVE-2010-1169 flaw.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Tcl. If the PL/Tcl procedural language was registered
on a particular database, an authenticated database user running a
specially-crafted PL/Tcl script could use this flaw to bypass intended
PL/Tcl trusted mode restrictions, allowing them to run arbitrary Tcl
scripts with the privileges of the database server. (CVE-2010-1170)

A buffer overflow flaw was found in the way PostgreSQL retrieved a
substring from the bit string for BIT() and BIT VARYING() SQL data types.
An authenticated database user running a specially-crafted SQL query could
use this flaw to cause a temporary denial of service (postgres daemon
crash) or, potentially, execute arbitrary code with the privileges of the
database server. (CVE-2010-0442)

An integer overflow flaw was found in the way PostgreSQL used to calculate
the size of the hash table for joined relations. An authenticated database
user could create a specially-crafted SQL query which could cause a
temporary denial of service (postgres daemon crash) or, potentially,
execute arbitrary code with the privileges of the database server.
(CVE-2010-0733)

PostgreSQL improperly protected session-local state during the execution of
an index function by a database superuser during the database maintenance
operations. An authenticated database user could use this flaw to elevate
their privileges via specially-crafted index functions. (CVE-2009-4136)

These packages upgrade PostgreSQL to version 7.4.29. Refer to the
PostgreSQL Release Notes for a list of changes:

http://www.postgresql.org/docs/7.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1975</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100428"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100429" severity="medium">
    <xccdf:title>RHSA-2010:0429: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS). PL/Perl and PL/Tcl allow users to write PostgreSQL functions in the
Perl and Tcl languages, and are installed in trusted mode by default. In
trusted mode, certain operations, such as operating system level access,
are restricted.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Perl. If the PL/Perl procedural language was
registered on a particular database, an authenticated database user running
a specially-crafted PL/Perl script could use this flaw to bypass intended
PL/Perl trusted mode restrictions, allowing them to run arbitrary Perl
scripts with the privileges of the database server. (CVE-2010-1169)

Red Hat would like to thank Tim Bunce for responsibly reporting the
CVE-2010-1169 flaw.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Tcl. If the PL/Tcl procedural language was registered
on a particular database, an authenticated database user running a
specially-crafted PL/Tcl script could use this flaw to bypass intended
PL/Tcl trusted mode restrictions, allowing them to run arbitrary Tcl
scripts with the privileges of the database server. (CVE-2010-1170)

A buffer overflow flaw was found in the way PostgreSQL retrieved a
substring from the bit string for BIT() and BIT VARYING() SQL data types.
An authenticated database user running a specially-crafted SQL query could
use this flaw to cause a temporary denial of service (postgres daemon
crash) or, potentially, execute arbitrary code with the privileges of the
database server. (CVE-2010-0442)

An integer overflow flaw was found in the way PostgreSQL used to calculate
the size of the hash table for joined relations. An authenticated database
user could create a specially-crafted SQL query which could cause a
temporary denial of service (postgres daemon crash) or, potentially,
execute arbitrary code with the privileges of the database server.
(CVE-2010-0733)

PostgreSQL improperly protected session-local state during the execution of
an index function by a database superuser during the database maintenance
operations. An authenticated database user could use this flaw to elevate
their privileges via specially-crafted index functions. (CVE-2009-4136)

These packages upgrade PostgreSQL to version 8.1.21. Refer to the
PostgreSQL Release Notes for a list of changes:

http://www.postgresql.org/docs/8.1/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1975</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100429"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100430" severity="medium">
    <xccdf:title>RHSA-2010:0430: postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS). PL/Perl and PL/Tcl allow users to write PostgreSQL functions in the
Perl and Tcl languages, and are installed in trusted mode by default. In
trusted mode, certain operations, such as operating system level access,
are restricted.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Perl. If the PL/Perl procedural language was
registered on a particular database, an authenticated database user running
a specially-crafted PL/Perl script could use this flaw to bypass intended
PL/Perl trusted mode restrictions, allowing them to run arbitrary Perl
scripts with the privileges of the database server. (CVE-2010-1169)

Red Hat would like to thank Tim Bunce for responsibly reporting the
CVE-2010-1169 flaw.

A flaw was found in the way PostgreSQL enforced permission checks on
scripts written in PL/Tcl. If the PL/Tcl procedural language was registered
on a particular database, an authenticated database user running a
specially-crafted PL/Tcl script could use this flaw to bypass intended
PL/Tcl trusted mode restrictions, allowing them to run arbitrary Tcl
scripts with the privileges of the database server. (CVE-2010-1170)

These packages upgrade PostgreSQL to version 8.4.4. Refer to the PostgreSQL
Release Notes for a list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1975</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100430"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100442" severity="high">
    <xccdf:title>RHSA-2010:0442: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

A buffer overflow flaw was found in the way MySQL handled the parameters of
the MySQL COM_FIELD_LIST network protocol command (this command is sent
when a client uses the MySQL mysql_list_fields() client library function).
An authenticated database user could send a request with an excessively
long table name to cause a temporary denial of service (mysqld crash) or,
potentially, execute arbitrary code with the privileges of the database
server. (CVE-2010-1850)

A directory traversal flaw was found in the way MySQL handled the
parameters of the MySQL COM_FIELD_LIST network protocol command. An
authenticated database user could use this flaw to obtain descriptions of
the fields of an arbitrary table using a request with a specially-crafted
table name. (CVE-2010-1848)

A flaw was discovered in the way MySQL handled symbolic links to tables
created using the DATA DIRECTORY and INDEX DIRECTORY directives in CREATE
TABLE statements. An attacker with CREATE and DROP table privileges, and
shell access to the database server, could use this flaw to remove data and
index files of tables created by other database users using the MyISAM
storage engine. (CVE-2010-1626)

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1850</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100442"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100449" severity="medium">
    <xccdf:title>RHSA-2010:0449: rhn-client-tools security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Network Client Tools provide programs and libraries that allow your
system to receive software updates from the Red Hat Network (RHN).

It was discovered that rhn-client-tools set insecure permissions on the
loginAuth.pkl file, used to store session credentials for authenticating
connections to Red Hat Network servers. A local, unprivileged user could
use these credentials to download packages from the Red Hat Network. They
could also manipulate package or action lists associated with the system's
profile. (CVE-2010-1439)

Users of rhn-client-tools are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1439</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100449"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100457" severity="medium">
    <xccdf:title>RHSA-2010:0457: perl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming. The Safe extension module
allows users to compile and execute Perl code in restricted compartments.

The Safe module did not properly restrict the code of implicitly called
methods (such as DESTROY and AUTOLOAD) on implicitly blessed objects
returned as a result of unsafe code evaluation. These methods could have
been executed unrestricted by Safe when such objects were accessed or
destroyed. A specially-crafted Perl script executed inside of a Safe
compartment could use this flaw to bypass intended Safe module
restrictions. (CVE-2010-1168)

The Safe module did not properly restrict code compiled in a Safe
compartment and executed out of the compartment via a subroutine reference
returned as a result of unsafe code evaluation. A specially-crafted Perl
script executed inside of a Safe compartment could use this flaw to bypass
intended Safe module restrictions, if the returned subroutine reference was
called from outside of the compartment. (CVE-2010-1447)

Red Hat would like to thank Tim Bunce for responsibly reporting the
CVE-2010-1168 and CVE-2010-1447 issues. Upstream acknowledges Nick Cleaton
as the original reporter of CVE-2010-1168, and Tim Bunce and Rafaël
Garcia-Suarez as the original reporters of CVE-2010-1447.

These packages upgrade the Safe extension module to version 2.27. Refer to
the Safe module's Changes file, linked to in the References, for a full
list of changes.

Users of perl are advised to upgrade to these updated packages, which
correct these issues. All applications using the Safe extension module must
be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100457"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100458" severity="medium">
    <xccdf:title>RHSA-2010:0458: perl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming. The Safe extension module
allows users to compile and execute Perl code in restricted compartments.
The File::Path module allows users to create and remove directory trees.

The Safe module did not properly restrict the code of implicitly called
methods (such as DESTROY and AUTOLOAD) on implicitly blessed objects
returned as a result of unsafe code evaluation. These methods could have
been executed unrestricted by Safe when such objects were accessed or
destroyed. A specially-crafted Perl script executed inside of a Safe
compartment could use this flaw to bypass intended Safe module
restrictions. (CVE-2010-1168)

The Safe module did not properly restrict code compiled in a Safe
compartment and executed out of the compartment via a subroutine reference
returned as a result of unsafe code evaluation. A specially-crafted Perl
script executed inside of a Safe compartment could use this flaw to bypass
intended Safe module restrictions, if the returned subroutine reference was
called from outside of the compartment. (CVE-2010-1447)

Multiple race conditions were found in the way the File::Path module's
rmtree function removed directory trees. A malicious, local user with write
access to a directory being removed by a victim, running a Perl script
using rmtree, could cause the permissions of arbitrary files to be changed
to world-writable and setuid, or delete arbitrary files via a symbolic link
attack, if the victim had the privileges to change the permissions of the
target files or to remove them. (CVE-2008-5302, CVE-2008-5303)

Red Hat would like to thank Tim Bunce for responsibly reporting the
CVE-2010-1168 and CVE-2010-1447 issues. Upstream acknowledges Nick Cleaton
as the original reporter of CVE-2010-1168, and Tim Bunce and Rafaël
Garcia-Suarez as the original reporters of CVE-2010-1447.

These packages upgrade the Safe extension module to version 2.27. Refer to
the Safe module's Changes file, linked to in the References, for a full
list of changes.

Users of perl are advised to upgrade to these updated packages, which
correct these issues. All applications using the Safe or File::Path modules
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100458"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100459" severity="medium">
    <xccdf:title>RHSA-2010:0459: openoffice.org security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

A flaw was found in the way OpenOffice.org enforced a macro security
setting for macros, written in the Python scripting language, that were
embedded in OpenOffice.org documents. If a user were tricked into opening
a specially-crafted OpenOffice.org document and previewed the macro
directory structure, it could lead to Python macro execution even if macro
execution was disabled. (CVE-2010-0395)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. For Red
Hat Enterprise Linux 4, this erratum provides updated openoffice.org2
packages. For Red Hat Enterprise Linux 5, this erratum provides updated
openoffice.org packages. All running instances of OpenOffice.org
applications must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0395</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100474" severity="high">
    <xccdf:title>RHSA-2010:0474: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a NULL pointer dereference flaw was found in the Linux kernel NFSv4
implementation. Several of the NFSv4 file locking functions failed to check
whether a file had been opened on the server before performing locking
operations on it. A local, unprivileged user on a system with an NFSv4
share mounted could possibly use this flaw to cause a kernel panic (denial
of service) or escalate their privileges. (CVE-2009-3726, Important)

* a flaw was found in the sctp_process_unk_param() function in the Linux
kernel Stream Control Transmission Protocol (SCTP) implementation. A remote
attacker could send a specially-crafted SCTP packet to an SCTP listening
port on a target system, causing a kernel panic (denial of service).
(CVE-2010-1173, Important)

* a race condition between finding a keyring by name and destroying a freed
keyring was found in the Linux kernel key management facility. A local,
unprivileged user could use this flaw to cause a kernel panic (denial of
service) or escalate their privileges. (CVE-2010-1437, Important)

Red Hat would like to thank Simon Vallet for responsibly reporting
CVE-2009-3726; and Jukka Taimisto and Olli Jarva of Codenomicon Ltd, Nokia
Siemens Networks, and Wind River on behalf of their customer, for
responsibly reporting CVE-2010-1173.

Bug fixes:

* RHBA-2007:0791 introduced a regression in the Journaling Block Device
(JBD). Under certain circumstances, removing a large file (such as 300 MB
or more) did not result in inactive memory being freed, leading to the
system having a large amount of inactive memory. Now, the memory is
correctly freed. (BZ#589155)

* the timer_interrupt() routine did not scale lost real ticks to logical
ticks correctly, possibly causing time drift for 64-bit Red Hat Enterprise
Linux 4 KVM (Kernel-based Virtual Machine) guests that were booted with the
"divider=x" kernel parameter set to a value greater than 1. "warning: many
lost ticks" messages may have been logged on the affected guest systems.
(BZ#590551)

* a bug could have prevented NFSv3 clients from having the most up-to-date
file attributes for files on a given NFSv3 file system. In cases where a
file type changed, such as if a file was removed and replaced with a
directory of the same name, the NFSv3 client may not have noticed this
change until stat(2) was called (for example, by running "ls -l").
(BZ#596372)

* RHBA-2007:0791 introduced bugs in the Linux kernel PCI-X subsystem. These
could have caused a system deadlock on some systems where the BIOS set the
default Maximum Memory Read Byte Count (MMRBC) to 4096, and that also use
the Intel PRO/1000 Linux driver, e1000. Errors such as "e1000: eth[x]:
e1000_clean_tx_irq: Detected Tx Unit Hang" were logged. (BZ#596374)

* an out of memory condition in a KVM guest, using the virtio-net network
driver and also under heavy network stress, could have resulted in
that guest being unable to receive network traffic. Users had to manually
remove and re-add the virtio_net module and restart the network service
before networking worked as expected. Such memory conditions no longer
prevent KVM guests receiving network traffic. (BZ#597310)

* when an SFQ qdisc that limited the queue size to two packets was added to
a network interface, sending traffic through that interface resulted in a
kernel crash. Such a qdisc no longer results in a kernel crash. (BZ#597312)

* when an NFS client opened a file with the O_TRUNC flag set, it received
a valid stateid, but did not use that stateid to perform the SETATTR call.
Such cases were rejected by Red Hat Enterprise Linux 4 NFS servers with an
"NFS4ERR_BAD_STATEID" error, possibly preventing some NFS clients from
writing files to an NFS file system. (BZ#597314)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3726</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100475" severity="medium">
    <xccdf:title>RHSA-2010:0475: sudo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled the presence of duplicated
environment variables. A local user authorized to run commands using sudo
could use this flaw to set additional values for the environment variables
set by sudo, which could result in those values being used by the executed
command instead of the values set by sudo. This could possibly lead to
certain intended restrictions being bypassed, such as the secure_path
setting. (CVE-2010-1646)

Red Hat would like to thank Anders Kaseorg and Evan Broder of Ksplice, Inc.
for responsibly reporting this issue.

Users of sudo should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1646</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100475"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100488" severity="high">
    <xccdf:title>RHSA-2010:0488: samba and samba3x security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

An input sanitization flaw was found in the way Samba parsed client data. A
malicious client could send a specially-crafted SMB packet to the Samba
server, resulting in arbitrary code execution with the privileges of the
Samba server (smbd). (CVE-2010-2063)

Red Hat would like to thank the Samba team for responsibly reporting this
issue. Upstream acknowledges Jun Mao as the original reporter.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2063</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100488"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100490" severity="high">
    <xccdf:title>RHSA-2010:0490: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The CUPS "texttops" filter converts text files
to PostScript.

A missing memory allocation failure check flaw, leading to a NULL pointer
dereference, was found in the CUPS "texttops" filter. An attacker could
create a malicious text file that would cause "texttops" to crash or,
potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2010-0542)

A Cross-Site Request Forgery (CSRF) issue was found in the CUPS web
interface. If a remote attacker could trick a user, who is logged into the
CUPS web interface as an administrator, into visiting a specially-crafted
website, the attacker could reconfigure and disable CUPS, and gain access
to print jobs and system files. (CVE-2010-0540)

Note: As a result of the fix for CVE-2010-0540, cookies must now be enabled
in your web browser to use the CUPS web interface.

An uninitialized memory read issue was found in the CUPS web interface. If
an attacker had access to the CUPS web interface, they could use a
specially-crafted URL to leverage this flaw to read a limited amount of
memory from the cupsd process, possibly obtaining sensitive information.
(CVE-2010-1748)

Red Hat would like to thank the Apple Product Security team for responsibly
reporting these issues. Upstream acknowledges regenrecht as the original
reporter of CVE-2010-0542; Adrian 'pagvac' Pastor of GNUCITIZEN and Tim
Starling as the original reporters of CVE-2010-0540; and Luca Carettoni as
the original reporter of CVE-2010-1748.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1748</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100490"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100499" severity="high">
    <xccdf:title>RHSA-2010:0499: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-1200)

A flaw was found in the way browser plug-ins interact. It was possible for
a plug-in to reference the freed memory from a different plug-in, resulting
in the execution of arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-1198)

An integer overflow flaw was found in the processing of malformed web
content. A web page containing malicious content could cause SeaMonkey to
crash or, potentially, execute arbitrary code with the privileges of the
user running SeaMonkey. (CVE-2010-1199)

A flaw was found in the way SeaMonkey processed mail attachments. A
specially-crafted mail message could cause SeaMonkey to crash.
(CVE-2010-0163)

A flaw was found in the way SeaMonkey handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. A website that allows arbitrary uploads and relies on the
"Content-Disposition: attachment" HTTP header to prevent content from being
displayed inline, could be used by an attacker to serve malicious content
to users. (CVE-2010-1197)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100499"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100500" severity="high">
    <xccdf:title>RHSA-2010:0500: firefox security, bug fix, and enhancement update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1121, CVE-2010-1200, CVE-2010-1202, CVE-2010-1203)

A flaw was found in the way browser plug-ins interact. It was possible for
a plug-in to reference the freed memory from a different plug-in, resulting
in the execution of arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1198)

Several integer overflow flaws were found in the processing of malformed
web content. A web page containing malicious content could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2010-1196, CVE-2010-1199)

A focus stealing flaw was found in the way Firefox handled focus changes. A
malicious website could use this flaw to steal sensitive data from a user,
such as usernames and passwords. (CVE-2010-1125)

A flaw was found in the way Firefox handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. A website that allows arbitrary uploads and relies on the
"Content-Disposition: attachment" HTTP header to prevent content from being
displayed inline, could be used by an attacker to serve malicious content
to users. (CVE-2010-1197)

A flaw was found in the Firefox Math.random() function. This function could
be used to identify a browsing session and track a user across different
websites. (CVE-2008-5913)

A flaw was found in the Firefox XML document loading security checks.
Certain security checks were not being called when an XML document was
loaded. This could possibly be leveraged later by an attacker to load
certain resources that violate the security policies of the browser or its
add-ons. Note that this issue cannot be exploited by only loading an XML
document. (CVE-2010-0182)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.4. You can find a link to the Mozilla advisories
in the References section of this erratum.

This erratum upgrades Firefox from version 3.0.19 to version 3.6.4, and as
such, contains multiple bug fixes and numerous enhancements. Space
precludes documenting these changes in this advisory. For details
concerning these changes, refer to the Firefox Release Notes links in the
References section of this erratum.

Important: Firefox 3.6.4 is not completely backwards-compatible with all
Mozilla Add-ons and Firefox plug-ins that worked with Firefox 3.0.19.
Firefox 3.6 checks compatibility on first-launch, and, depending on the
individual configuration and the installed Add-ons and plug-ins, may
disable said Add-ons and plug-ins, or attempt to check for updates and
upgrade them. Add-ons and plug-ins may have to be manually updated.

All Firefox users should upgrade to this updated package, which contains
Firefox version 3.6.4. After installing the update, Firefox must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1203</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100500"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100501" severity="high">
    <xccdf:title>RHSA-2010:0501: firefox security, bug fix, and enhancement update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1121, CVE-2010-1200, CVE-2010-1202, CVE-2010-1203)

A flaw was found in the way browser plug-ins interact. It was possible for
a plug-in to reference the freed memory from a different plug-in, resulting
in the execution of arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1198)

Several integer overflow flaws were found in the processing of malformed
web content. A web page containing malicious content could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2010-1196, CVE-2010-1199)

A focus stealing flaw was found in the way Firefox handled focus changes. A
malicious website could use this flaw to steal sensitive data from a user,
such as usernames and passwords. (CVE-2010-1125)

A flaw was found in the way Firefox handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. A website that allows arbitrary uploads and relies on the
"Content-Disposition: attachment" HTTP header to prevent content from being
displayed inline, could be used by an attacker to serve malicious content
to users. (CVE-2010-1197)

A flaw was found in the Firefox Math.random() function. This function could
be used to identify a browsing session and track a user across different
websites. (CVE-2008-5913)

A flaw was found in the Firefox XML document loading security checks.
Certain security checks were not being called when an XML document was
loaded. This could possibly be leveraged later by an attacker to load
certain resources that violate the security policies of the browser or its
add-ons. Note that this issue cannot be exploited by only loading an XML
document. (CVE-2010-0182)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.4. You can find a link to the Mozilla advisories
in the References section of this erratum.

This erratum upgrades Firefox from version 3.0.19 to version 3.6.4. Due to
the requirements of Firefox 3.6.4, this erratum also provides a number of
other updated packages, including esc, totem, and yelp.

This erratum also contains multiple bug fixes and numerous enhancements.
Space precludes documenting these changes in this advisory. For details
concerning these changes, refer to the Firefox Release Notes links in the
References section of this erratum.

Important: Firefox 3.6.4 is not completely backwards-compatible with all
Mozilla Add-ons and Firefox plug-ins that worked with Firefox 3.0.19.
Firefox 3.6 checks compatibility on first-launch, and, depending on the
individual configuration and the installed Add-ons and plug-ins, may
disable said Add-ons and plug-ins, or attempt to check for updates and
upgrade them. Add-ons and plug-ins may have to be manually updated.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.4. After installing the update, Firefox must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1203</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100501"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100504" severity="high">
    <xccdf:title>RHSA-2010:0504: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* multiple flaws were found in the mmap and mremap implementations. A local
user could use these flaws to cause a local denial of service or escalate
their privileges. (CVE-2010-0291, Important)

* a NULL pointer dereference flaw was found in the Fast Userspace Mutexes
(futexes) implementation. The unlock code path did not check if the futex
value associated with pi_state-&gt;owner had been modified. A local user could
use this flaw to modify the futex value, possibly leading to a denial of
service or privilege escalation when the pi_state-&gt;owner pointer is
dereferenced. (CVE-2010-0622, Important)

* a NULL pointer dereference flaw was found in the Linux kernel Network
File System (NFS) implementation. A local user on a system that has an
NFS-mounted file system could use this flaw to cause a denial of service or
escalate their privileges on that system. (CVE-2010-1087, Important)

* a flaw was found in the sctp_process_unk_param() function in the Linux
kernel Stream Control Transmission Protocol (SCTP) implementation. A remote
attacker could send a specially-crafted SCTP packet to an SCTP listening
port on a target system, causing a kernel panic (denial of service).
(CVE-2010-1173, Important)

* a flaw was found in the Linux kernel Transparent Inter-Process
Communication protocol (TIPC) implementation. If a client application, on a
local system where the tipc module is not yet in network mode, attempted to
send a message to a remote TIPC node, it would dereference a NULL pointer
on the local system, causing a kernel panic (denial of service).
(CVE-2010-1187, Important)

* a buffer overflow flaw was found in the Linux kernel Global File System 2
(GFS2) implementation. In certain cases, a quota could be written past the
end of a memory page, causing memory corruption, leaving the quota stored
on disk in an invalid state. A user with write access to a GFS2 file system
could trigger this flaw to cause a kernel crash (denial of service) or
escalate their privileges on the GFS2 server. This issue can only be
triggered if the GFS2 file system is mounted with the "quota=on" or
"quota=account" mount option. (CVE-2010-1436, Important)

* a race condition between finding a keyring by name and destroying a freed
keyring was found in the Linux kernel key management facility. A local user
could use this flaw to cause a kernel panic (denial of service) or escalate
their privileges. (CVE-2010-1437, Important)

* a flaw was found in the link_path_walk() function in the Linux kernel.
Using the file descriptor returned by the open() function with the
O_NOFOLLOW flag on a subordinate NFS-mounted file system, could result in a
NULL pointer dereference, causing a denial of service or privilege
escalation. (CVE-2010-1088, Moderate)

* a missing permission check was found in the gfs2_set_flags() function in
the Linux kernel GFS2 implementation. A local user could use this flaw to
change certain file attributes of files, on a GFS2 file system, that they
do not own. (CVE-2010-1641, Low)

Red Hat would like to thank Jukka Taimisto and Olli Jarva of Codenomicon
Ltd, Nokia Siemens Networks, and Wind River on behalf of their customer,
for responsibly reporting CVE-2010-1173; Mario Mikocevic for responsibly
reporting CVE-2010-1436; and Dan Rosenberg for responsibly reporting
CVE-2010-1641.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from
http://www.redhat.com/docs/en-US/errata/RHSA-2010-0504/Kernel_Security_Update/index.html

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0291</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0622</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1187</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1437</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1641</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100504"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100505" severity="medium">
    <xccdf:title>RHSA-2010:0505: perl-Archive-Tar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Archive::Tar module provides a mechanism for Perl scripts to manipulate
tar archive files.

Multiple directory traversal flaws were discovered in the Archive::Tar
module. A specially-crafted tar file could cause a Perl script, using the
Archive::Tar module to extract the archive, to overwrite an arbitrary file
writable by the user running the script. (CVE-2007-4829)

This package upgrades the Archive::Tar module to version 1.39_01. Refer to
the Archive::Tar module's changes file, linked to in the References, for a
full list of changes.

Users of perl-Archive-Tar are advised to upgrade to this updated package,
which corrects these issues. All applications using the Archive::Tar module
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4829</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100505"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100518" severity="high">
    <xccdf:title>RHSA-2010:0518: scsi-target-utils security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The scsi-target-utils package contains the daemon and tools to set up and
monitor SCSI targets. Currently, iSCSI software and iSER targets are
supported.

Multiple buffer overflow flaws were found in scsi-target-utils' tgtd
daemon. A remote attacker could trigger these flaws by sending a
carefully-crafted Internet Storage Name Service (iSNS) request, causing the
tgtd daemon to crash. (CVE-2010-2221)

Red Hat would like to thank the Vulnerability Research Team at TELUS
Security Labs and Fujita Tomonori for responsibly reporting these flaws.

All scsi-target-utils users should upgrade to this updated package, which
contains a backported patch to correct these issues. All running
scsi-target-utils services must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2221</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100518"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100519" severity="high">
    <xccdf:title>RHSA-2010:0519: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple integer overflow flaws, leading to a buffer overflow, were
discovered in libtiff. An attacker could use these flaws to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2010-1411)

Multiple input validation flaws were discovered in libtiff. An attacker
could use these flaws to create a specially-crafted TIFF file that, when
opened, would cause an application linked against libtiff to crash.
(CVE-2010-2481, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597)

Red Hat would like to thank Apple Product Security for responsibly
reporting the CVE-2010-1411 flaw, who credit Kevin Finisterre of
digitalmunition.com for the discovery of the issue.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications linked against libtiff must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4665</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100519"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100528" severity="medium">
    <xccdf:title>RHSA-2010:0528: avahi security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zero Configuration Networking. It facilitates service
discovery on a local network. Avahi and Avahi-aware applications allow you
to plug your computer into a network and, with no configuration, view other
people to chat with, view printers to print to, and find shared files on
other computers.

A flaw was found in the way the Avahi daemon (avahi-daemon) processed
Multicast DNS (mDNS) packets with corrupted checksums. An attacker on the
local network could use this flaw to cause avahi-daemon on a target system
to exit unexpectedly via specially-crafted mDNS packets. (CVE-2010-2244)

A flaw was found in the way avahi-daemon processed incoming unicast mDNS
messages. If the mDNS reflector were enabled on a system, an attacker on
the local network could send a specially-crafted unicast mDNS message to
that system, resulting in its avahi-daemon flooding the network with a
multicast packet storm, and consuming a large amount of CPU. Note: The mDNS
reflector is disabled by default. (CVE-2009-0758)

All users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the update,
avahi-daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0758</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100528"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100533" severity="medium">
    <xccdf:title>RHSA-2010:0533: pcsc-lite security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PC/SC Lite provides a Windows SCard compatible interface for communicating
with smart cards, smart card readers, and other security tokens.

Multiple buffer overflow flaws were discovered in the way the pcscd daemon,
a resource manager that coordinates communications with smart card readers
and smart cards connected to the system, handled client requests. A local
user could create a specially-crafted request that would cause the pcscd
daemon to crash or, possibly, execute arbitrary code. (CVE-2010-0407,
CVE-2009-4901)

Users of pcsc-lite should upgrade to these updated packages, which contain
a backported patch to correct these issues. After installing this update,
the pcscd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4901</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0407</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100533"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100534" severity="high">
    <xccdf:title>RHSA-2010:0534: libpng security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A memory corruption flaw was found in the way applications, using the
libpng library and its progressive reading method, decoded certain PNG
images. An attacker could create a specially-crafted PNG image that, when
opened, could cause an application using libpng to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2010-1205)

A denial of service flaw was found in the way applications using the libpng
library decoded PNG images that have certain, highly compressed ancillary
chunks. An attacker could create a specially-crafted PNG image that could
cause an application using libpng to consume excessive amounts of memory
and CPU time, and possibly crash. (CVE-2010-0205)

A memory leak flaw was found in the way applications using the libpng
library decoded PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that could cause an
application using libpng to exhaust all available memory and possibly crash
or exit. (CVE-2010-2249)

A sensitive information disclosure flaw was found in the way applications
using the libpng library processed 1-bit interlaced PNG images. An attacker
could create a specially-crafted PNG image that could cause an application
using libpng to disclose uninitialized memory. (CVE-2009-2042)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2249</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100534"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100542" severity="medium">
    <xccdf:title>RHSA-2010:0542: openldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

Multiple flaws were discovered in the way the slapd daemon handled modify
relative distinguished name (modrdn) requests. An authenticated user with
privileges to perform modrdn operations could use these flaws to crash the
slapd daemon via specially-crafted modrdn requests. (CVE-2010-0211,
CVE-2010-0212)

Red Hat would like to thank CERT-FI for responsibly reporting these flaws,
who credit Ilkka Mattila and Tuomas Salomäki for the discovery of the
issues.

Users of OpenLDAP should upgrade to these updated packages, which contain
a backported patch to correct these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0212</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100542"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100543" severity="medium">
    <xccdf:title>RHSA-2010:0543: openldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

An uninitialized pointer use flaw was discovered in the way the slapd
daemon handled modify relative distinguished name (modrdn) requests. An
authenticated user with privileges to perform modrdn operations could use
this flaw to crash the slapd daemon via specially-crafted modrdn requests.
(CVE-2010-0211)

Red Hat would like to thank CERT-FI for responsibly reporting the
CVE-2010-0211 flaw, who credit Ilkka Mattila and Tuomas Salomäki for the
discovery of the issue.

A flaw was found in the way OpenLDAP handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick applications using OpenLDAP libraries into accepting it by
mistake, allowing the attacker to perform a man-in-the-middle attack.
(CVE-2009-3767)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0211</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100543"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100544" severity="medium">
    <xccdf:title>RHSA-2010:0544: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-0174, CVE-2010-1200, CVE-2010-1211,
CVE-2010-1214, CVE-2010-2753)

An integer overflow flaw was found in the processing of malformed HTML mail
content. An HTML mail message containing malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2010-1199)

Several use-after-free flaws were found in Thunderbird. Viewing an HTML
mail message containing malicious content could result in Thunderbird
executing arbitrary code with the privileges of the user running
Thunderbird. (CVE-2010-0175, CVE-2010-0176, CVE-2010-0177)

A flaw was found in the way Thunderbird plug-ins interact. It was possible
for a plug-in to reference the freed memory from a different plug-in,
resulting in the execution of arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-1198)

A flaw was found in the way Thunderbird handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. Loading remote HTTP content that allows arbitrary uploads and
relies on the "Content-Disposition: attachment" HTTP header to prevent
content from being displayed inline, could be used by an attacker to serve
malicious content to users. (CVE-2010-1197)

A same-origin policy bypass flaw was found in Thunderbird. Remote HTML
content could steal private data from different remote HTML content
Thunderbird has loaded. (CVE-2010-2754)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100544"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100545" severity="high">
    <xccdf:title>RHSA-2010:0545: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A memory corruption flaw was found in the way Thunderbird decoded certain
PNG images. An attacker could create a mail message containing a
specially-crafted PNG image that, when opened, could cause Thunderbird to
crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-1205)

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-0174, CVE-2010-1200, CVE-2010-1211,
CVE-2010-1214, CVE-2010-2753)

An integer overflow flaw was found in the processing of malformed HTML mail
content. An HTML mail message containing malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2010-1199)

Several use-after-free flaws were found in Thunderbird. Viewing an HTML
mail message containing malicious content could result in Thunderbird
executing arbitrary code with the privileges of the user running
Thunderbird. (CVE-2010-0175, CVE-2010-0176, CVE-2010-0177)

A flaw was found in the way Thunderbird plug-ins interact. It was possible
for a plug-in to reference the freed memory from a different plug-in,
resulting in the execution of arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-1198)

A flaw was found in the way Thunderbird handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. Loading remote HTTP content that allows arbitrary uploads and
relies on the "Content-Disposition: attachment" HTTP header to prevent
content from being displayed inline, could be used by an attacker to serve
malicious content to users. (CVE-2010-1197)

A same-origin policy bypass flaw was found in Thunderbird. Remote HTML
content could steal private data from different remote HTML content
Thunderbird has loaded. (CVE-2010-2754)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100545"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100546" severity="high">
    <xccdf:title>RHSA-2010:0546: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-1211, CVE-2010-2753, CVE-2010-1214)

A memory corruption flaw was found in the way SeaMonkey decoded certain PNG
images. An attacker could create a specially-crafted PNG image that, when
opened, could cause SeaMonkey to crash or, potentially, execute arbitrary
code with the privileges of the user running SeaMonkey. (CVE-2010-1205)

A same-origin policy bypass flaw was found in SeaMonkey. An attacker could
create a malicious web page that, when viewed by a victim, could steal
private data from a different website the victim has loaded with SeaMonkey.
(CVE-2010-2754)

A flaw was found in the way SeaMonkey displayed the location bar when
visiting a secure web page. A malicious server could use this flaw to
present data that appears to originate from a secure server, even though it
does not. (CVE-2010-2751)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100546"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100547" severity="high">
    <xccdf:title>RHSA-2010:0547: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211, CVE-2010-1212,
CVE-2010-1214, CVE-2010-1215, CVE-2010-2752, CVE-2010-2753)

A memory corruption flaw was found in the way Firefox decoded certain PNG
images. An attacker could create a specially-crafted PNG image that, when
opened, could cause Firefox to crash or, potentially, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2010-1205)

Several same-origin policy bypass flaws were found in Firefox. An attacker
could create a malicious web page that, when viewed by a victim, could
steal private data from a different website the victim has loaded with
Firefox. (CVE-2010-0654, CVE-2010-1207, CVE-2010-1213, CVE-2010-2754)

A flaw was found in the way Firefox presented the location bar to a user. A
malicious website could trick a user into thinking they are visiting the
site reported by the location bar, when the page is actually content
controlled by an attacker. (CVE-2010-1206)

A flaw was found in the way Firefox displayed the location bar when
visiting a secure web page. A malicious server could use this flaw to
present data that appears to originate from a secure server, even though it
does not. (CVE-2010-2751)

A flaw was found in the way Firefox displayed certain malformed characters.
A malicious web page could use this flaw to bypass certain string
sanitization methods, allowing it to display malicious information to
users. (CVE-2010-1210)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.7. You can find a link to the Mozilla advisories
in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.7, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2754</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100547"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100556" severity="high">
    <xccdf:title>RHSA-2010:0556: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox.

An invalid free flaw was found in Firefox's plugin handler. Malicious web content could result in an invalid memory pointer being freed, causing Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running the Firefox application. (CVE-2010-2755)

All Firefox users should upgrade to these updated packages, which contain a backported patch that corrects this issue. After installing the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2755</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100556"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100557" severity="high">
    <xccdf:title>RHSA-2010:0557: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

An invalid free flaw was found in SeaMonkey's plugin handler. Malicious web content could result in an invalid memory pointer being freed, causing SeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. (CVE-2010-2755)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2755</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100557"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100558" severity="high">
    <xccdf:title>RHSA-2010:0558: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

An invalid free flaw was found in Firefox's plugin handler. Malicious web content could result in an invalid memory pointer being freed, causing Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-2755)

All Firefox users should upgrade to these updated packages, which contain a backported patch that corrects this issue. After installing the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2755</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100558"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100565" severity="medium">
    <xccdf:title>RHSA-2010:0565: w3m security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The w3m program is a pager (or text file viewer) that can also be used as a
text mode web browser.

It was discovered that w3m is affected by the previously published "null
prefix attack", caused by incorrect handling of NULL characters in X.509
certificates. If an attacker is able to get a carefully-crafted certificate
signed by a trusted Certificate Authority, the attacker could use the
certificate during a man-in-the-middle attack and potentially confuse w3m
into accepting it by mistake. (CVE-2010-2074)

All w3m users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2074</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100565"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100567" severity="medium">
    <xccdf:title>RHSA-2010:0567: lvm2-cluster security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The lvm2-cluster package contains support for Logical Volume Management
(LVM) in a clustered environment.

It was discovered that the cluster logical volume manager daemon (clvmd)
did not verify the credentials of clients connecting to its control UNIX
abstract socket, allowing local, unprivileged users to send control
commands that were intended to only be available to the privileged root
user. This could allow a local, unprivileged user to cause clvmd to exit,
or request clvmd to activate, deactivate, or reload any logical volume on
the local system or another system in the cluster. (CVE-2010-2526)

Note: This update changes clvmd to use a pathname-based socket rather than
an abstract socket. As such, the lvm2 update RHBA-2010:0569, which changes
LVM to also use this pathname-based socket, must also be installed for LVM
to be able to communicate with the updated clvmd.

All lvm2-cluster users should upgrade to this updated package, which
contains a backported patch to correct this issue. After installing the
updated package, clvmd must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2526</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100567"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100578" severity="high">
    <xccdf:title>RHSA-2010:0578: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 provide only the FreeType 2 font engine.

An invalid memory management flaw was found in the way the FreeType font
engine processed font files. If a user loaded a carefully-crafted font file
with an application linked against FreeType, it could cause the application
to crash or, possibly, execute arbitrary code with the privileges of the
user running the application. (CVE-2010-2498)

An integer overflow flaw was found in the way the FreeType font engine
processed font files. If a user loaded a carefully-crafted font file with
an application linked against FreeType, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2010-2500)

Several buffer overflow flaws were found in the way the FreeType font
engine processed font files. If a user loaded a carefully-crafted font file
with an application linked against FreeType, it could cause the application
to crash or, possibly, execute arbitrary code with the privileges of the
user running the application. (CVE-2010-2499, CVE-2010-2519)

Several buffer overflow flaws were found in the FreeType demo applications.
If a user loaded a carefully-crafted font file with a demo application, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2527,
CVE-2010-2541)

Red Hat would like to thank Robert Swiecki of the Google Security Team for
the discovery of the CVE-2010-2498, CVE-2010-2500, CVE-2010-2499,
CVE-2010-2519, and CVE-2010-2527 issues.

Note: All of the issues in this erratum only affect the FreeType 2 font
engine.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2541</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100578"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100580" severity="high">
    <xccdf:title>RHSA-2010:0580: tomcat5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A flaw was found in the way Tomcat handled the Transfer-Encoding header in
HTTP requests. A specially-crafted HTTP request could prevent Tomcat from
sending replies, or cause Tomcat to return truncated replies, or replies
containing data related to the requests of other users, for all subsequent
HTTP requests. (CVE-2010-2227)

The Tomcat security update RHSA-2009:1164 did not, unlike the erratum text
stated, provide a fix for CVE-2009-0781, a cross-site scripting (XSS) flaw
in the examples calendar application. With some web browsers, remote
attackers could use this flaw to inject arbitrary web script or HTML via
the "time" parameter. (CVE-2009-2696)

Two directory traversal flaws were found in the Tomcat deployment process.
A specially-crafted WAR file could, when deployed, cause a file to be
created outside of the web root into any directory writable by the Tomcat
user, or could lead to the deletion of files in the Tomcat host's work
directory. (CVE-2009-2693, CVE-2009-2902)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to resolve these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2693</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2696</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2227</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100585" severity="medium">
    <xccdf:title>RHSA-2010:0585: lftp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LFTP is a sophisticated file transfer program for the FTP and HTTP
protocols. Like Bash, it has job control and uses the Readline library for
input. It has bookmarks, built-in mirroring, and can transfer several files
in parallel. It is designed with reliability in mind.

It was discovered that lftp trusted the file name provided in the
Content-Disposition HTTP header. A malicious HTTP server could use this
flaw to write or overwrite files in the current working directory of a
victim running lftp, by sending a different file from what the victim
requested. (CVE-2010-2251)

To correct this flaw, the following changes were made to lftp: the
"xfer:clobber" option now defaults to "no", causing lftp to not overwrite
existing files, and a new option, "xfer:auto-rename", which defaults to
"no", has been introduced to control whether lftp should use
server-suggested file names. Refer to the "Settings" section of the lftp(1)
manual page for additional details on changing lftp settings.

All lftp users should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2251</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100585"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100603" severity="medium">
    <xccdf:title>RHSA-2010:0603: gnupg2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and
creating digital signatures, compliant with the proposed OpenPGP Internet
standard and the S/MIME standard.

A use-after-free flaw was found in the way gpgsm, a Cryptographic Message
Syntax (CMS) encryption and signing tool, handled X.509 certificates with
a large number of Subject Alternate Names. A specially-crafted X.509
certificate could, when imported, cause gpgsm to crash or, possibly,
execute arbitrary code. (CVE-2010-2547)

All gnupg2 users should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100603"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100606" severity="high">
    <xccdf:title>RHSA-2010:0606: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in the CIFSSMBWrite() function in the Linux kernel
Common Internet File System (CIFS) implementation. A remote attacker could
send a specially-crafted SMB response packet to a target CIFS client,
resulting in a kernel panic (denial of service). (CVE-2010-2248, Important)

* buffer overflow flaws were found in the Linux kernel's implementation of
the server-side External Data Representation (XDR) for the Network File
System (NFS) version 4. An attacker on the local network could send a
specially-crafted large compound request to the NFSv4 server, which could
possibly result in a kernel panic (denial of service) or, potentially, code
execution. (CVE-2010-2521, Important)

This update also fixes the following bug:

* the rpc_call_async() function in the SUN Remote Procedure Call (RPC)
subsystem in the Linux kernel had a reference counting bug. In certain
situations, some Network Lock Manager (NLM) messages may have triggered
this bug on NFSv2 and NFSv3 servers, leading to a kernel panic (with
"kernel BUG at fs/lockd/host.c:[xxx]!" logged to "/var/log/messages").
(BZ#612962)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100606"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100607" severity="high">
    <xccdf:title>RHSA-2010:0607: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 3 and 4
provide both the FreeType 1 and FreeType 2 font engines. The freetype
packages for Red Hat Enterprise Linux 5 provide only the FreeType 2 font
engine.

Two stack overflow flaws were found in the way the FreeType font engine
processed certain Compact Font Format (CFF) character strings (opcodes). If
a user loaded a specially-crafted font file with an application linked
against FreeType, it could cause the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2010-1797)

Red Hat would like to thank Braden Thomas of the Apple Product Security
team for reporting these issues.

Note: CVE-2010-1797 only affects the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0607</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1797</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100607"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100610" severity="high">
    <xccdf:title>RHSA-2010:0610: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* instances of unsafe sprintf() use were found in the Linux kernel
Bluetooth implementation. Creating a large number of Bluetooth L2CAP, SCO,
or RFCOMM sockets could result in arbitrary memory pages being overwritten.
A local, unprivileged user could use this flaw to cause a kernel panic
(denial of service) or escalate their privileges. (CVE-2010-1084,
Important)

* a flaw was found in the Xen hypervisor implementation when using the
Intel Itanium architecture, allowing guests to enter an unsupported state.
An unprivileged guest user could trigger this flaw by setting the BE (Big
Endian) bit of the Processor Status Register (PSR), leading to the guest
crashing (denial of service). (CVE-2010-2070, Important)

* a flaw was found in the CIFSSMBWrite() function in the Linux kernel
Common Internet File System (CIFS) implementation. A remote attacker could
send a specially-crafted SMB response packet to a target CIFS client,
resulting in a kernel panic (denial of service). (CVE-2010-2248, Important)

* buffer overflow flaws were found in the Linux kernel's implementation of
the server-side External Data Representation (XDR) for the Network File
System (NFS) version 4. An attacker on the local network could send a
specially-crafted large compound request to the NFSv4 server, which could
possibly result in a kernel panic (denial of service) or, potentially, code
execution. (CVE-2010-2521, Important)

* a flaw was found in the handling of the SWAPEXT IOCTL in the Linux kernel
XFS file system implementation. A local user could use this flaw to read
write-only files, that they do not own, on an XFS file system. This could
lead to unintended information disclosure. (CVE-2010-2226, Moderate)

* a flaw was found in the dns_resolver upcall used by CIFS. A local,
unprivileged user could redirect a Microsoft Distributed File System link
to another IP address, tricking the client into mounting the share from a
server of the user's choosing. (CVE-2010-2524, Moderate)

* a missing check was found in the mext_check_arguments() function in the
ext4 file system code. A local user could use this flaw to cause the
MOVE_EXT IOCTL to overwrite the contents of an append-only file on an ext4
file system, if they have write permissions for that file. (CVE-2010-2066,
Low)

Red Hat would like to thank Neil Brown for reporting CVE-2010-1084, and Dan
Rosenberg for reporting CVE-2010-2226 and CVE-2010-2066.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0610</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2226</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2524</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100610"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100615" severity="low">
    <xccdf:title>RHSA-2010:0615: libvirt security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

It was found that libvirt did not set the user-defined backing store format
when creating a new image, possibly resulting in applications having to
probe the backing store to discover the format. A privileged guest user
could use this flaw to read arbitrary files on the host. (CVE-2010-2239)

It was found that libvirt created insecure iptables rules on the host when
a guest system was configured for IP masquerading, allowing the guest to
use privileged ports on the host when accessing network resources. A
privileged guest user could use this flaw to access network resources that
would otherwise not be accessible to the guest. (CVE-2010-2242)

Red Hat would like to thank Jeremy Nickurak for reporting the CVE-2010-2242
issue.

This update also fixes the following bugs:

* a Linux software bridge assumes the MAC address of the enslaved interface
with the numerically lowest MAC address. When the bridge changes its MAC
address, for a period of time it does not relay packets across network
segments, resulting in a temporary network "blackout". The bridge should
thus avoid changing its MAC address in order not to disrupt network
communications.

The Linux kernel assigns network TAP devices a random MAC address.
Occasionally, this random MAC address is lower than that of the physical
interface which is enslaved (for example, eth0 or eth1), which causes the
bridge to change its MAC address, thereby disrupting network communications
for a period of time.

With this update, libvirt now sets an explicit MAC address for all TAP
devices created using the configured MAC address from the XML, but with the
high bit set to 0xFE. The result is that TAP device MAC addresses are now
numerically greater than those for physical interfaces, and bridges should
no longer attempt to switch their MAC address to that of the TAP device,
thus avoiding potential spurious network disruptions. (BZ#617243)

* a memory leak in the libvirt driver for the Xen hypervisor has been fixed
with this update. (BZ#619711)

* the xm and virsh management user interfaces for virtual guests can be
called on the command line to list the number of active guests. However,
under certain circumstances, running the "virsh list" command resulted in
virsh not listing all of the virtual guests that were active (that is,
running) at the time. This update incorporates a fix that matches the logic
used for determining active guests with that of "xm list", such that both
commands should now list the same number of active virtual guests under all
circumstances. (BZ#618200)

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, the system must be rebooted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2239</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2242</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100615"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100616" severity="medium">
    <xccdf:title>RHSA-2010:0616: dbus-glib security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>dbus-glib is an add-on library to integrate the standard D-Bus library with
the GLib main loop and threading model. NetworkManager is a network link
manager that attempts to keep a wired or wireless network connection active
at all times.

It was discovered that dbus-glib did not enforce the "access" flag on
exported GObject properties. If such a property were read/write internally
but specified as read-only externally, a malicious, local user could use
this flaw to modify that property of an application. Such a change could
impact the application's behavior (for example, if an IP address were
changed the network may not come up properly after reboot) and possibly
lead to a denial of service. (CVE-2010-1172)

Due to the way dbus-glib translates an application's XML definitions of
service interfaces and properties into C code at application build time,
applications built against dbus-glib that use read-only properties needed
to be rebuilt to fully fix the flaw. As such, this update provides
NetworkManager packages that have been rebuilt against the updated
dbus-glib packages. No other applications shipped with Red Hat Enterprise
Linux 5 were affected.

All dbus-glib and NetworkManager users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.
Running instances of NetworkManager must be restarted (service
NetworkManager restart) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1172</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100616"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100625" severity="medium">
    <xccdf:title>RHSA-2010:0625: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in the Wireshark SigComp
Universal Decompressor Virtual Machine (UDVM) dissector. If Wireshark read
a malformed packet off a network or opened a malicious dump file, it could
crash or, possibly, execute arbitrary code as the user running Wireshark.
(CVE-2010-2287, CVE-2010-2995)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2010-1455, CVE-2010-2283, CVE-2010-2284,
CVE-2010-2286)

Users of Wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.15, and resolve these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2284</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2995</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100625"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100627" severity="high">
    <xccdf:title>RHSA-2010:0627: kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

It was found that QEMU-KVM on the host did not validate all pointers
provided from a guest system's QXL graphics card driver. A privileged guest
user could use this flaw to cause the host to dereference an invalid
pointer, causing the guest to crash (denial of service) or, possibly,
resulting in the privileged guest user escalating their privileges on the
host. (CVE-2010-0431)

A flaw was found in QEMU-KVM, allowing the guest some control over the
index used to access the callback array during sub-page MMIO
initialization. A privileged guest user could use this flaw to crash the
guest (denial of service) or, possibly, escalate their privileges on the
host. (CVE-2010-2784)

A NULL pointer dereference flaw was found when the host system had a
processor with the Intel VT-x extension enabled. A privileged guest user
could use this flaw to trick the host into emulating a certain instruction,
which could crash the host (denial of service). (CVE-2010-0435)

This update also fixes the following bugs:

* running a "qemu-img" check on a faulty virtual machine image ended with a
segmentation fault. With this update, the segmentation fault no longer
occurs when running the "qemu-img" check. (BZ#610342)

* when attempting to transfer a file between two guests that were joined in
the same virtual LAN (VLAN), the receiving guest unexpectedly quit. With
this update, the transfer completes successfully. (BZ#610343)

* installation of a system was occasionally failing in KVM. This was caused
by KVM using wrong permissions for large guest pages. With this update, the
installation completes successfully. (BZ#616796)

* previously, the migration process would fail for a virtual machine
because the virtual machine could not map all the memory. This was caused
by a conflict that was initiated when a virtual machine was initially run
and then migrated right away. With this update, the conflict no longer
occurs and the migration process no longer fails. (BZ#618205)

* using a thinly provisioned VirtIO disk on iSCSI storage and performing a
"qemu-img" check during an "e_no_space" event returned cluster errors. With
this update, the errors no longer appear. (BZ#618206)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2784</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100627"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100632" severity="medium">
    <xccdf:title>RHSA-2010:0632: qspice-client security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The qspice-client package provides the client side of the SPICE protocol.

A race condition was found in the way the SPICE Mozilla Firefox plug-in and
the SPICE client communicated. A local attacker could use this flaw to
trick the plug-in and the SPICE client into communicating over an
attacker-controlled socket, possibly gaining access to authentication
details, or resulting in a man-in-the-middle attack on the SPICE
connection. (CVE-2010-2792)

Users of qspice-client should upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2792</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100632"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100633" severity="high">
    <xccdf:title>RHSA-2010:0633: qspice security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

It was found that the libspice component of QEMU-KVM on the host did not
validate all pointers provided from a guest system's QXL graphics card
driver. A privileged guest user could use this flaw to cause the host to
dereference an invalid pointer, causing the guest to crash (denial of
service) or, possibly, resulting in the privileged guest user escalating
their privileges on the host. (CVE-2010-0428)

It was found that the libspice component of QEMU-KVM on the host could be
forced to perform certain memory management operations on memory addresses
controlled by a guest. A privileged guest user could use this flaw to crash
the guest (denial of service) or, possibly, escalate their privileges on
the host. (CVE-2010-0429)

All qspice users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0429</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100633"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100643" severity="high">
    <xccdf:title>RHSA-2010:0643: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An integer truncation error, leading to a heap-based buffer overflow, was
found in the way the OpenOffice.org Impress presentation application
sanitized a file's dictionary property items. An attacker could use this
flaw to create a specially-crafted Microsoft Office PowerPoint file that,
when opened, would cause OpenOffice.org Impress to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org Impress. (CVE-2010-2935)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way OpenOffice.org Impress processed polygons in input
documents. An attacker could use this flaw to create a specially-crafted
Microsoft Office PowerPoint file that, when opened, would cause
OpenOffice.org Impress to crash or, possibly, execute arbitrary code with
the privileges of the user running OpenOffice.org Impress. (CVE-2010-2936)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. For Red
Hat Enterprise Linux 3, this erratum provides updated openoffice.org
packages. For Red Hat Enterprise Linux 4, this erratum provides updated
openoffice.org and openoffice.org2 packages. All running instances of
OpenOffice.org applications must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2936</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100643"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100651" severity="medium">
    <xccdf:title>RHSA-2010:0651: spice-xpi security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

A race condition was found in the way the SPICE Firefox plug-in and the
SPICE client communicated. A local attacker could use this flaw to trick
the plug-in and the SPICE client into communicating over an
attacker-controlled socket, possibly gaining access to authentication
details, or resulting in a man-in-the-middle attack on the SPICE
connection. (CVE-2010-2792)

It was found that the SPICE Firefox plug-in used a predictable name for its
log file. A local attacker could use this flaw to conduct a symbolic link
attack, allowing them to overwrite arbitrary files accessible to the user
running Firefox. (CVE-2010-2794)

This update also fixes the following bugs:

* a bug prevented users of Red Hat Enterprise Linux 5.5, with all updates
applied, from running the SPICE Firefox plug-in when using Firefox 3.6.4.
With this update, the plug-in works correctly with Firefox 3.6.4 and the
latest version in Red Hat Enterprise Linux 5.5, Firefox 3.6.7. (BZ#618244)

* unused code has been removed during source code refactoring. This also
resolves a bug in the SPICE Firefox plug-in that caused it to close random
file descriptors. (BZ#594006, BZ#619067)

Note: This update should be installed together with the RHSA-2010:0632
qspice-client update: https://rhn.redhat.com/errata/RHSA-2010-0632.html

Users of spice-xpi should upgrade to this updated package, which contains
backported patches to correct these issues. After installing the update,
Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0651</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2792</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2794</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100651"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100652" severity="medium">
    <xccdf:title>RHSA-2010:0652: ImageMagick security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the ImageMagick routine responsible for creating X11 images. An
attacker could create a specially-crafted image file that, when opened by a
victim, would cause ImageMagick to crash or, potentially, execute arbitrary
code. (CVE-2009-1882)

This update also fixes the following bug:

* previously, portions of certain RGB images on the right side were not
rendered and left black when converting or displaying them. With this
update, RGB images display correctly. (BZ#625058)

Users of ImageMagick are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of ImageMagick must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1882</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100652"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100653" severity="medium">
    <xccdf:title>RHSA-2010:0653: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the ImageMagick routine responsible for creating X11 images. An
attacker could create a specially-crafted image file that, when opened by a
victim, would cause ImageMagick to crash or, potentially, execute arbitrary
code. (CVE-2009-1882)

Users of ImageMagick are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. All running
instances of ImageMagick must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0653</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1882</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100653"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100657" severity="low">
    <xccdf:title>RHSA-2010:0657: gdm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNOME Display Manager (GDM) is a configurable re-implementation of XDM,
the X Display Manager. GDM allows you to log in to your system with the X
Window System running, and supports running several different X sessions on
your local machine at the same time.

A flaw was found in the way the gdm package was built. The gdm package was
missing TCP wrappers support on 64-bit platforms, which could result in an
administrator believing they had access restrictions enabled when they did
not. (CVE-2007-5079)

This update also fixes the following bug:

* sometimes the system would hang instead of properly shutting down when
a user chose "Shut down" from the login screen. (BZ#625818)

All users should upgrade to this updated package, which contains backported
patches to correct these issues. GDM must be restarted for this update to
take effect. Rebooting achieves this, but changing the runlevel from 5 to 3
and back to 5 also restarts GDM.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-5079</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100657"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100659" severity="medium">
    <xccdf:title>RHSA-2010:0659: httpd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

A flaw was discovered in the way the mod_proxy module of the Apache HTTP
Server handled the timeouts of requests forwarded by a reverse proxy to the
back-end server. If the proxy was configured to reuse existing back-end
connections, it could return a response intended for another user under
certain timeout conditions, possibly leading to information disclosure.
(CVE-2010-2791)

A flaw was found in the way the mod_dav module of the Apache HTTP Server
handled certain requests. If a remote attacker were to send a carefully
crafted request to the server, it could cause the httpd child process to
crash. (CVE-2010-1452)

This update also fixes the following bugs:

* numerous issues in the INFLATE filter provided by mod_deflate. "Inflate
error -5 on flush" errors may have been logged. This update upgrades
mod_deflate to the newer upstream version from Apache HTTP Server 2.2.15.
(BZ#625435)

* the response would be corrupted if mod_filter applied the DEFLATE filter
to a resource requiring a subrequest with an internal redirect. (BZ#625451)

* the OID() function used in the mod_ssl "SSLRequire" directive did not
correctly evaluate extensions of an unknown type. (BZ#625452)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2791</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100659"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100661" severity="high">
    <xccdf:title>RHSA-2010:0661: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* when an application has a stack overflow, the stack could silently
overwrite another memory mapped area instead of a segmentation fault
occurring, which could cause an application to execute arbitrary code,
possibly leading to privilege escalation. It is known that the X Window
System server can be used to trigger this flaw. (CVE-2010-2240, Important)

Red Hat would like to thank the X.Org security team for reporting this
issue. Upstream acknowledges Rafal Wojtczuk as the original reporter.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0661</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100661"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100675" severity="high">
    <xccdf:title>RHSA-2010:0675: sudo security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled Runas specifications containing
both a user and a group list. If a local user were authorized by the
sudoers file to perform their sudo commands with the privileges of a
specified user and group, they could use this flaw to run those commands
with the privileges of either an arbitrary user or group on the system.
(CVE-2010-2956)

Red Hat would like to thank Markus Wuethrich of Swiss Post - PostFinance
for reporting this issue.

Users of sudo should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2956</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100675"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100676" severity="high">
    <xccdf:title>RHSA-2010:0676: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* When an application has a stack overflow, the stack could silently
overwrite another memory mapped area instead of a segmentation fault
occurring, which could cause an application to execute arbitrary code,
possibly leading to privilege escalation. It is known that the X Window
System server can be used to trigger this flaw. (CVE-2010-2240, Important)

Red Hat would like to thank the X.Org security team for reporting this
issue. Upstream acknowledges Rafal Wojtczuk as the original reporter.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100676"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100678" severity="medium">
    <xccdf:title>RHSA-2010:0678: rpm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a command line driven package management
system capable of installing, uninstalling, verifying, querying, and
updating software packages.

It was discovered that RPM did not remove setuid and setgid bits set on
binaries when upgrading or removing packages. A local attacker able to
create hard links to binaries could use this flaw to keep those binaries on
the system, at a specific version level and with the setuid or setgid bit
set, even if the package providing them was upgraded or removed by a system
administrator. This could have security implications if a package was
upgraded or removed because of a security flaw in a setuid or setgid
program. (CVE-2005-4889, CVE-2010-2059)

All users of rpm are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-4889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2059</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100678"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100679" severity="medium">
    <xccdf:title>RHSA-2010:0679: rpm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a command line driven package management
system capable of installing, uninstalling, verifying, querying, and
updating software packages.

It was discovered that RPM did not remove setuid and setgid bits set on
binaries when upgrading packages. A local attacker able to create hard
links to binaries could use this flaw to keep those binaries on the system,
at a specific version level and with the setuid or setgid bit set, even if
the package providing them was upgraded by a system administrator. This
could have security implications if a package was upgraded because of a
security flaw in a setuid or setgid program. (CVE-2010-2059)

This update also fixes the following bug:

* A memory leak in the communication between RPM and the Security-Enhanced
Linux (SELinux) subsystem, which could have caused extensive memory
consumption. In reported cases, this issue was triggered by running
rhn_check when errata were scheduled to be applied. (BZ#627630)

All users of rpm are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2059</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100679"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100680" severity="high">
    <xccdf:title>RHSA-2010:0680: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-3169)

A buffer overflow flaw was found in SeaMonkey. A web page containing
malicious content could cause SeaMonkey to crash or, potentially, execute
arbitrary code with the privileges of the user running SeaMonkey.
(CVE-2010-2765)

A use-after-free flaw and several dangling pointer flaws were found in
SeaMonkey. A web page containing malicious content could cause SeaMonkey to
crash or, potentially, execute arbitrary code with the privileges of the
user running SeaMonkey. (CVE-2010-2760, CVE-2010-2767, CVE-2010-3167,
CVE-2010-3168)

A cross-site scripting (XSS) flaw was found in SeaMonkey. A web page
containing malicious content could cause SeaMonkey to run JavaScript code
with the permissions of a different website. (CVE-2010-2768)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2765</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100680"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100681" severity="high">
    <xccdf:title>RHSA-2010:0681: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-3169, CVE-2010-2762)

Several use-after-free and dangling pointer flaws were found in Firefox. A
web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-2760, CVE-2010-2766, CVE-2010-2767, CVE-2010-3167,
CVE-2010-3168)

Multiple buffer overflow flaws were found in Firefox. A web page containing
malicious content could cause Firefox to crash or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2010-2765, CVE-2010-3166)

Multiple cross-site scripting (XSS) flaws were found in Firefox. A web page
containing malicious content could cause Firefox to run JavaScript code
with the permissions of a different website. (CVE-2010-2768, CVE-2010-2769)

A flaw was found in the Firefox XMLHttpRequest object. A remote site could
use this flaw to gather information about servers on an internal private
network. (CVE-2010-2764)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.9. You can find a link to the Mozilla advisories
in the References section of this erratum.

Note: After installing this update, Firefox will fail to connect (with
HTTPS) to a server using the SSL DHE (Diffie-Hellman Ephemeral) key
exchange if the server's ephemeral key is too small. Connecting to such
servers is a security risk as an ephemeral key that is too small makes the
SSL connection vulnerable to attack. Refer to the Solution section for
further information.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.9, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2762</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2765</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2766</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2769</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100681"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100682" severity="medium">
    <xccdf:title>RHSA-2010:0682: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-3169)

A buffer overflow flaw was found in Thunderbird. An HTML mail message
containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2010-2765)

A use-after-free flaw and several dangling pointer flaws were found in
Thunderbird. An HTML mail message containing malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2010-2760, CVE-2010-2767,
CVE-2010-3167, CVE-2010-3168)

A cross-site scripting (XSS) flaw was found in Thunderbird. Remote HTML
content could cause Thunderbird to execute JavaScript code with the
permissions of different remote HTML content. (CVE-2010-2768)

Note: JavaScript support is disabled by default in Thunderbird. None of the
above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2760</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2765</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100682"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100697" severity="high">
    <xccdf:title>RHSA-2010:0697: samba security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A missing array boundary checking flaw was found in the way Samba parsed
the binary representation of Windows security identifiers (SIDs). A
malicious client could send a specially-crafted SMB request to the Samba
server, resulting in arbitrary code execution with the privileges of the
Samba server (smbd). (CVE-2010-3069)

For Red Hat Enterprise Linux 4, this update also fixes the following bug:

* Previously, the restorecon utility was required during the installation
of the samba-common package. As a result, attempting to update samba
without this utility installed may have failed with the following error:

/var/tmp/rpm-tmp.[xxxxx]: line 7: restorecon: command not found

With this update, the utility is only used when it is already present on
the system, and the package is now always updated as expected. (BZ#629602)

Users of Samba are advised to upgrade to these updated packages, which
correct these issues. After installing this update, the smb service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0697</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3069</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100697"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100698" severity="high">
    <xccdf:title>RHSA-2010:0698: samba3x security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A missing array boundary checking flaw was found in the way Samba parsed
the binary representation of Windows security identifiers (SIDs). A
malicious client could send a specially-crafted SMB request to the Samba
server, resulting in arbitrary code execution with the privileges of the
Samba server (smbd). (CVE-2010-3069)

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3069</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100698"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100703" severity="high">
    <xccdf:title>RHSA-2010:0703: bzip2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>bzip2 is a freely available, high-quality data compressor. It provides both
standalone compression and decompression utilities, as well as a shared
library for use with other programs.

An integer overflow flaw was discovered in the bzip2 decompression routine.
This issue could, when decompressing malformed archives, cause bzip2, or an
application linked against the libbz2 library, to crash or, potentially,
execute arbitrary code. (CVE-2010-0405)

Users of bzip2 should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications using the
libbz2 library must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0405</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100703"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100704" severity="high">
    <xccdf:title>RHSA-2010:0704: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* The compat_alloc_user_space() function in the Linux kernel 32/64-bit
compatibility layer implementation was missing sanity checks. This function
could be abused in other areas of the Linux kernel if its length argument
can be controlled from user-space. On 64-bit systems, a local, unprivileged
user could use this flaw to escalate their privileges. (CVE-2010-3081,
Important)

Red Hat would like to thank Ben Hawkes for reporting this issue.

Red Hat is aware that a public exploit for this issue is available. Refer
to Knowledgebase article DOC-40265 for further details:
https://access.redhat.com/kb/docs/DOC-40265

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0704</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3081</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100704"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100718" severity="high">
    <xccdf:title>RHSA-2010:0718: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* The compat_alloc_user_space() function in the Linux kernel 32/64-bit
compatibility layer implementation was missing sanity checks. This function
could be abused in other areas of the Linux kernel if its length argument
can be controlled from user-space. On 64-bit systems, a local, unprivileged
user could use this flaw to escalate their privileges. (CVE-2010-3081,
Important)

Red Hat would like to thank Ben Hawkes for reporting this issue.

Refer to Knowledgebase article DOC-40265 for further details:
https://access.redhat.com/kb/docs/DOC-40265

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3081</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100718"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100720" severity="medium">
    <xccdf:title>RHSA-2010:0720: mikmod security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MikMod is a MOD music file player for Linux, UNIX, and similar operating
systems. It supports various file formats including MOD, STM, S3M, MTM, XM,
ULT, and IT.

Multiple input validation flaws, resulting in buffer overflows, were
discovered in MikMod. Specially-crafted music files in various formats
could, when played, cause an application using the MikMod library to crash
or, potentially, execute arbitrary code. (CVE-2009-3995, CVE-2009-3996,
CVE-2007-6720)

All MikMod users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
the MikMod library must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3996</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100720"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100723" severity="high">
    <xccdf:title>RHSA-2010:0723: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the ecryptfs_uid_hash() function in
the Linux kernel eCryptfs implementation. On systems that have the eCryptfs
netlink transport (Red Hat Enterprise Linux 5 does) or where the
"/dev/ecryptfs" file has world writable permissions (which it does not, by
default, on Red Hat Enterprise Linux 5), a local, unprivileged user could
use this flaw to cause a denial of service or possibly escalate their
privileges. (CVE-2010-2492, Important)

* A miscalculation of the size of the free space of the initial directory
entry in a directory leaf block was found in the Linux kernel Global File
System 2 (GFS2) implementation. A local, unprivileged user with write
access to a GFS2-mounted file system could perform a rename operation on
that file system to trigger a NULL pointer dereference, possibly resulting
in a denial of service or privilege escalation. (CVE-2010-2798, Important)

* A flaw was found in the Xen hypervisor implementation when running a
system that has an Intel CPU without Extended Page Tables (EPT) support.
While attempting to dump information about a crashing fully-virtualized
guest, the flaw could cause the hypervisor to crash the host as well. A
user with permissions to configure a fully-virtualized guest system could
use this flaw to crash the host. (CVE-2010-2938, Moderate)

* Information leak flaws were found in the Linux kernel's Traffic Control
Unit implementation. A local attacker could use these flaws to cause the
kernel to leak kernel memory to user-space, possibly leading to the
disclosure of sensitive information. (CVE-2010-2942, Moderate)

* A flaw was found in the Linux kernel's XFS file system implementation.
The file handle lookup could return an invalid inode as valid. If an XFS
file system was mounted via NFS (Network File System), a local attacker
could access stale data or overwrite existing data that reused the inodes.
(CVE-2010-2943, Moderate)

* An integer overflow flaw was found in the extent range checking code in
the Linux kernel's ext4 file system implementation. A local, unprivileged
user with write access to an ext4-mounted file system could trigger this
flaw by writing to a file at a very large file offset, resulting in a local
denial of service. (CVE-2010-3015, Moderate)

* An information leak flaw was found in the Linux kernel's USB
implementation. Certain USB errors could result in an uninitialized kernel
buffer being sent to user-space. An attacker with physical access to a
target system could use this flaw to cause an information leak.
(CVE-2010-1083, Low)

Red Hat would like to thank Andre Osterhues for reporting CVE-2010-2492;
Grant Diffey of CenITex for reporting CVE-2010-2798; Toshiyuki Okajima for
reporting CVE-2010-3015; and Marcus Meissner for reporting CVE-2010-1083.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2938</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100723"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100737" severity="high">
    <xccdf:title>RHSA-2010:0737: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 provide only the FreeType 2 font engine.

It was discovered that the FreeType font rendering engine improperly
validated certain position values when processing input streams. If a user
loaded a specially-crafted font file with an application linked against
FreeType, and the relevant font glyphs were subsequently rendered with the
X FreeType library (libXft), it could trigger a heap-based buffer overflow
in the libXft library, causing the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2010-3311)

A stack-based buffer overflow flaw was found in the way the FreeType font
rendering engine processed some PostScript Type 1 fonts. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2808)

An array index error was found in the way the FreeType font rendering
engine processed certain PostScript Type 42 font files. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2806)

A stack overflow flaw was found in the way the FreeType font rendering
engine processed PostScript Type 1 font files that contain nested Standard
Encoding Accented Character (seac) calls. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash. (CVE-2010-3054)

Note: All of the issues in this erratum only affect the FreeType 2 font
engine.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3311</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100737"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100742" severity="medium">
    <xccdf:title>RHSA-2010:0742: postgresql and postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS). PL/Perl and PL/Tcl allow users to write PostgreSQL functions in the
Perl and Tcl languages. The PostgreSQL SECURITY DEFINER parameter, which
can be used when creating a new PostgreSQL function, specifies that the
function will be executed with the privileges of the user that created it.

It was discovered that a user could utilize the features of the PL/Perl and
PL/Tcl languages to modify the behavior of a SECURITY DEFINER function
created by a different user. If the PL/Perl or PL/Tcl language was used to
implement a SECURITY DEFINER function, an authenticated database user could
use a PL/Perl or PL/Tcl script to modify the behavior of that function
during subsequent calls in the same session. This would result in the
modified or injected code also being executed with the privileges of the
user who created the SECURITY DEFINER function, possibly leading to
privilege escalation. (CVE-2010-3433)

For Red Hat Enterprise Linux 4, the updated postgresql packages upgrade
PostgreSQL to version 7.4.30. Refer to the PostgreSQL Release Notes for a
list of changes:

http://www.postgresql.org/docs/7.4/static/release.html

For Red Hat Enterprise Linux 5, the updated postgresql packages upgrade
PostgreSQL to version 8.1.22, and the updated postgresql84 packages upgrade
PostgreSQL to version 8.4.5. Refer to the PostgreSQL Release Notes for a
list of changes:

http://www.postgresql.org/docs/8.1/static/release.html
http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3433</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100742"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100749" severity="high">
    <xccdf:title>RHSA-2010:0749: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

An uninitialized pointer use flaw was discovered in poppler. An attacker
could create a malicious PDF file that, when opened, would cause
applications that use poppler (such as Evince) to crash or, potentially,
execute arbitrary code. (CVE-2010-3702)

An array index error was found in the way poppler parsed PostScript Type 1
fonts embedded in PDF documents. An attacker could create a malicious PDF
file that, when opened, would cause applications that use poppler (such as
Evince) to crash or, potentially, execute arbitrary code. (CVE-2010-3704)

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100749"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100751" severity="high">
    <xccdf:title>RHSA-2010:0751: xpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

An uninitialized pointer use flaw was discovered in Xpdf. An attacker could
create a malicious PDF file that, when opened, would cause Xpdf to crash
or, potentially, execute arbitrary code. (CVE-2010-3702)

An array index error was found in the way Xpdf parsed PostScript Type 1
fonts embedded in PDF documents. An attacker could create a malicious PDF
file that, when opened, would cause Xpdf to crash or, potentially, execute
arbitrary code. (CVE-2010-3704)

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100751"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100752" severity="high">
    <xccdf:title>RHSA-2010:0752: gpdf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GPdf is a viewer for Portable Document Format (PDF) files.

An uninitialized pointer use flaw was discovered in GPdf. An attacker could
create a malicious PDF file that, when opened, would cause GPdf to crash
or, potentially, execute arbitrary code. (CVE-2010-3702)

An array index error was found in the way GPdf parsed PostScript Type 1
fonts embedded in PDF documents. An attacker could create a malicious PDF
file that, when opened, would cause GPdf to crash or, potentially, execute
arbitrary code. (CVE-2010-3704)

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100752"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100753" severity="high">
    <xccdf:title>RHSA-2010:0753: kdegraphics security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

An uninitialized pointer use flaw was discovered in KPDF. An attacker could
create a malicious PDF file that, when opened, would cause KPDF to crash
or, potentially, execute arbitrary code. (CVE-2010-3702)

An array index error was found in the way KPDF parsed PostScript Type 1
fonts embedded in PDF documents. An attacker could create a malicious PDF
file that, when opened, would cause KPDF to crash or, potentially, execute
arbitrary code. (CVE-2010-3704)

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100753"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100755" severity="high">
    <xccdf:title>RHSA-2010:0755: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The CUPS "pdftops" filter converts Portable
Document Format (PDF) files to PostScript.

Multiple flaws were discovered in the CUPS "pdftops" filter. An attacker
could create a malicious PDF file that, when printed, would cause "pdftops"
to crash or, potentially, execute arbitrary code as the "lp" user.
(CVE-2010-3702, CVE-2009-3609)

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0755</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100755"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100768" severity="high">
    <xccdf:title>RHSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

defaultReadObject of the Serialization API could be tricked into setting a
volatile field multiple times, which could allow a remote attacker to
execute arbitrary code with the privileges of the user running the applet
or application. (CVE-2010-3569)

Race condition in the way objects were deserialized could allow an
untrusted applet or application to misuse the privileges of the user
running the applet or application. (CVE-2010-3568)

Miscalculation in the OpenType font rendering implementation caused
out-of-bounds memory access, which could allow remote attackers to execute
code with the privileges of the user running the java process.
(CVE-2010-3567)

JPEGImageWriter.writeImage in the imageio API improperly checked certain
image metadata, which could allow a remote attacker to execute arbitrary
code in the context of the user running the applet or application.
(CVE-2010-3565)

Double free in IndexColorModel could cause an untrusted applet or
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the applet or application. (CVE-2010-3562)

The privileged accept method of the ServerSocket class in the Common Object
Request Broker Architecture (CORBA) implementation in OpenJDK allowed it to
receive connections from any host, instead of just the host of the current
connection. An attacker could use this flaw to bypass restrictions defined
by network permissions. (CVE-2010-3561)

Flaws in the Swing library could allow an untrusted application to modify
the behavior and state of certain JDK classes. (CVE-2010-3557)

Flaws in the CORBA implementation could allow an attacker to execute
arbitrary code by misusing permissions granted to certain system objects.
(CVE-2010-3554)

UIDefault.ProxyLazyValue had unsafe reflection usage, allowing untrusted
callers to create objects via ProxyLazyValue values. (CVE-2010-3553)

HttpURLConnection improperly handled the "chunked" transfer encoding
method, which could allow remote attackers to conduct HTTP response
splitting attacks. (CVE-2010-3549)

HttpURLConnection improperly checked whether the calling code was granted
the "allowHttpTrace" permission, allowing untrusted code to create HTTP
TRACE requests. (CVE-2010-3574)

HttpURLConnection did not validate request headers set by applets, which
could allow remote attackers to trigger actions otherwise restricted to
HTTP clients. (CVE-2010-3541, CVE-2010-3573)

The Kerberos implementation improperly checked the sanity of AP-REQ
requests, which could cause a denial of service condition in the receiving
Java Virtual Machine. (CVE-2010-3564)

The RHSA-2010:0339 update mitigated a man-in-the-middle attack in the way
the TLS/SSL (Transport Layer Security/Secure Sockets Layer) protocols
handle session renegotiation by disabling renegotiation. This update
implements the TLS Renegotiation Indication Extension as defined in RFC
5746, allowing secure renegotiation between updated clients and servers.
(CVE-2009-3555)

The NetworkInterface class improperly checked the network "connect"
permissions for local network addresses, which could allow remote attackers
to read local network addresses. (CVE-2010-3551)

Information leak flaw in the Java Naming and Directory Interface (JNDI)
could allow a remote attacker to access information about
otherwise-protected internal network names. (CVE-2010-3548)

Note: Flaws concerning applets in this advisory (CVE-2010-3568,
CVE-2010-3554, CVE-2009-3555, CVE-2010-3562, CVE-2010-3557, CVE-2010-3548,
CVE-2010-3564, CVE-2010-3565, CVE-2010-3569) can only be triggered in
OpenJDK by calling the "appletviewer" application.

Bug fixes:

* This update provides one defense in depth patch. (BZ#639922)

* Problems for certain SSL connections. In a reported case, this prevented
the JBoss JAAS modules from connecting over SSL to Microsoft Active
Directory servers. (BZ#618290)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3574</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100768"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100779" severity="medium">
    <xccdf:title>RHSA-2010:0779: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Information leak flaws were found in the Linux kernel Traffic Control
Unit implementation. A local attacker could use these flaws to cause the
kernel to leak kernel memory to user-space, possibly leading to the
disclosure of sensitive information. (CVE-2010-2942, Moderate)

* A flaw was found in the tcf_act_police_dump() function in the Linux
kernel network traffic policing implementation. A data structure in
tcf_act_police_dump() was not initialized properly before being copied to
user-space. A local, unprivileged user could use this flaw to cause an
information leak. (CVE-2010-3477, Moderate)

* A missing upper bound integer check was found in the sys_io_submit()
function in the Linux kernel asynchronous I/O implementation. A local,
unprivileged user could use this flaw to cause an information leak.
(CVE-2010-3067, Low)

Red Hat would like to thank Tavis Ormandy for reporting CVE-2010-3067.

This update also fixes the following bugs:

* When two systems using bonding devices in the adaptive load balancing
(ALB) mode communicated with each other, an endless loop of ARP replies
started between these two systems due to a faulty MAC address update. With
this update, the MAC address update no longer creates unneeded ARP replies.
(BZ#629239)

* When running the Connectathon NFS Testsuite with certain clients and Red
Hat Enterprise Linux 4.8 as the server, nfsvers4, lock, and test2 failed
the Connectathon test. (BZ#625535)

* For UDP/UNIX domain sockets, due to insufficient memory barriers in the
network code, a process sleeping in select() may have missed notifications
about new data. In rare cases, this bug may have caused a process to sleep
forever. (BZ#640117)

* In certain situations, a bug found in either the HTB or TBF network
packet schedulers in the Linux kernel could have caused a kernel panic when
using Broadcom network cards with the bnx2 driver. (BZ#624363)

* Previously, allocating fallback cqr for DASD reserve/release IOCTLs
failed because it used the memory pool of the respective device. This
update preallocates sufficient memory for a single reserve/release request.
(BZ#626828)

* In some situations a bug prevented "force online" succeeding for a DASD
device. (BZ#626827)

* Using the "fsstress" utility may have caused a kernel panic. (BZ#633968)

* This update introduces additional stack guard patches. (BZ#632515)

* A bug was found in the way the megaraid_sas driver handled physical disks
and management IOCTLs. All physical disks were exported to the disk layer,
allowing an oops in megasas_complete_cmd_dpc() when completing the IOCTL
command if a timeout occurred. (BZ#631903)

* Previously, a warning message was returned when a large amount of
messages was passed through netconsole and a considerable amount of network
load was added. With this update, the warning message is no longer
displayed. (BZ#637729)

* Executing a large "dd" command (1 to 5GB) on an iSCSI device with the
qla3xxx driver caused a system crash due to the incorrect storing of a
private data structure. With this update, the size of the stored data
structure is checked and the system crashes no longer occur. (BZ#624364)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3477</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100779"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100780" severity="medium">
    <xccdf:title>RHSA-2010:0780: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-3176, CVE-2010-3180)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the script that launches Thunderbird. The
LD_LIBRARY_PATH variable was appending a "." character, which could allow a
local attacker to execute arbitrary code with the privileges of a different
user running Thunderbird, if that user ran Thunderbird from within an
attacker-controlled directory. (CVE-2010-3182)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100780"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100781" severity="high">
    <xccdf:title>RHSA-2010:0781: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-3176, CVE-2010-3180)

A flaw was found in the way the Gopher parser in SeaMonkey converted text
into HTML. A malformed file name on a Gopher server could, when accessed by
a victim running SeaMonkey, allow arbitrary JavaScript to be executed in
the context of the Gopher domain. (CVE-2010-3177)

A flaw was found in the script that launches SeaMonkey. The LD_LIBRARY_PATH
variable was appending a "." character, which could allow a local attacker
to execute arbitrary code with the privileges of a different user running
SeaMonkey, if that user ran SeaMonkey from within an attacker-controlled
directory. (CVE-2010-3182)

It was found that the SSL DHE (Diffie-Hellman Ephemeral) mode
implementation for key exchanges in SeaMonkey accepted DHE keys that were
256 bits in length. This update removes support for 256 bit DHE keys, as
such keys are easily broken using modern hardware. (CVE-2010-3173)

A flaw was found in the way SeaMonkey matched SSL certificates when the
certificates had a Common Name containing a wildcard and a partial IP
address. SeaMonkey incorrectly accepted connections to IP addresses that
fell within the SSL certificate's wildcard range as valid SSL connections,
possibly allowing an attacker to conduct a man-in-the-middle attack.
(CVE-2010-3170)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100781"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100782" severity="high">
    <xccdf:title>RHSA-2010:0782: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. Network Security Services (NSS) is
a set of libraries designed to support the development of security-enabled
client and server applications.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-3175, CVE-2010-3176, CVE-2010-3179, CVE-2010-3183,
CVE-2010-3180)

A flaw was found in the way the Gopher parser in Firefox converted text
into HTML. A malformed file name on a Gopher server could, when accessed by
a victim running Firefox, allow arbitrary JavaScript to be executed in the
context of the Gopher domain. (CVE-2010-3177)

A same-origin policy bypass flaw was found in Firefox. An attacker could
create a malicious web page that, when viewed by a victim, could steal
private data from a different website the victim has loaded with Firefox.
(CVE-2010-3178)

A flaw was found in the script that launches Firefox. The LD_LIBRARY_PATH
variable was appending a "." character, which could allow a local attacker
to execute arbitrary code with the privileges of a different user running
Firefox, if that user ran Firefox from within an attacker-controlled
directory. (CVE-2010-3182)

This update also provides NSS version 3.12.8 which is required by the
updated Firefox version, fixing the following security issues:

It was found that the SSL DHE (Diffie-Hellman Ephemeral) mode
implementation for key exchanges in Firefox accepted DHE keys that were 256
bits in length. This update removes support for 256 bit DHE keys, as such
keys are easily broken using modern hardware. (CVE-2010-3173)

A flaw was found in the way NSS matched SSL certificates when the
certificates had a Common Name containing a wildcard and a partial IP
address. NSS incorrectly accepted connections to IP addresses that fell
within the SSL certificate's wildcard range as valid SSL connections,
possibly allowing an attacker to conduct a man-in-the-middle attack.
(CVE-2010-3170)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.11. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.11, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100782"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100785" severity="medium">
    <xccdf:title>RHSA-2010:0785: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol.

A stack-based buffer overflow flaw was found in the way the Quagga bgpd
daemon processed certain BGP Route Refresh (RR) messages. A configured BGP
peer could send a specially-crafted BGP message, causing bgpd on a target
system to crash or, possibly, execute arbitrary code with the privileges of
the user running bgpd. (CVE-2010-2948)

Note: On Red Hat Enterprise Linux 5 it is not possible to exploit
CVE-2010-2948 to run arbitrary code as the overflow is blocked by
FORTIFY_SOURCE.

Multiple NULL pointer dereference flaws were found in the way the Quagga
bgpd daemon processed certain specially-crafted BGP messages. A configured
BGP peer could crash bgpd on a target system via specially-crafted BGP
messages. (CVE-2007-4826)

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4826</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2948</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100785"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100787" severity="high">
    <xccdf:title>RHSA-2010:0787: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

It was discovered that the glibc dynamic linker/loader did not handle the
$ORIGIN dynamic string token set in the LD_AUDIT environment variable
securely. A local attacker with write access to a file system containing
setuid or setgid binaries could use this flaw to escalate their privileges.
(CVE-2010-3847)

Red Hat would like to thank Tavis Ormandy for reporting this issue.

All users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3847</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100787"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100788" severity="medium">
    <xccdf:title>RHSA-2010:0788: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Multiple NULL pointer dereference flaws were found in the way Pidgin
handled Base64 decoding. A remote attacker could use these flaws to crash
Pidgin if the target Pidgin user was using the Yahoo! Messenger Protocol,
MSN, MySpace, or Extensible Messaging and Presence Protocol (XMPP) protocol
plug-ins, or using the Microsoft NT LAN Manager (NTLM) protocol for
authentication. (CVE-2010-3711)

A NULL pointer dereference flaw was found in the way the Pidgin MSN
protocol plug-in processed custom emoticon messages. A remote attacker
could use this flaw to crash Pidgin by sending specially-crafted emoticon
messages during mutual communication. (CVE-2010-1624)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Daniel Atallah as the original reporter of
CVE-2010-3711, and Pierre Noguès of Meta Security as the original reporter
of CVE-2010-1624.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1624</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3711</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100788"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100792" severity="high">
    <xccdf:title>RHSA-2010:0792: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* The rds_page_copy_user() function in the Linux kernel Reliable Datagram
Sockets (RDS) protocol implementation was missing sanity checks. A local,
unprivileged user could use this flaw to escalate their privileges.
(CVE-2010-3904, Important)

Red Hat would like to thank Dan Rosenberg of Virtual Security Research for
reporting this issue.

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0792</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3904</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100792"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100793" severity="high">
    <xccdf:title>RHSA-2010:0793: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

It was discovered that the glibc dynamic linker/loader did not perform
sufficient safety checks when loading dynamic shared objects (DSOs) to
provide callbacks for its auditing API during the execution of
privileged programs. A local attacker could use this flaw to escalate
their privileges via a carefully-chosen system DSO library containing
unsafe constructors. (CVE-2010-3856)

Red Hat would like to thank Ben Hawkes and Tavis Ormandy for reporting this
issue.

All users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3856</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100793"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100808" severity="high">
    <xccdf:title>RHSA-2010:0808: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

A race condition flaw was found in the way Firefox handled Document Object
Model (DOM) element properties. A web page containing malicious content
could cause Firefox to crash or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2010-3765)

For technical details regarding this flaw, refer to the Mozilla security
advisories for Firefox 3.6.12. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing the update,
Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100808"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100809" severity="high">
    <xccdf:title>RHSA-2010:0809: xulrunner security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>XULRunner provides the XUL Runtime environment for applications using the
Gecko layout engine.

A race condition flaw was found in the way XULRunner handled Document
Object Model (DOM) element properties. Malicious HTML content could cause
an application linked against XULRunner (such as Firefox) to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2010-3765)

For technical details regarding this flaw, refer to the Mozilla security
advisories for Firefox 3.6.12. You can find a link to the Mozilla
advisories in the References section of this erratum.

All XULRunner users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update,
applications using XULRunner must be restarted for the changes to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100809"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100810" severity="high">
    <xccdf:title>RHSA-2010:0810: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A race condition flaw was found in the way SeaMonkey handled Document
Object Model (DOM) element properties. A web page containing malicious
content could cause SeaMonkey to crash or, potentially, execute arbitrary
code with the privileges of the user running SeaMonkey. (CVE-2010-3765)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100810"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100811" severity="high">
    <xccdf:title>RHSA-2010:0811: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A use-after-free flaw was found in the way the CUPS server parsed Internet
Printing Protocol (IPP) packets. A malicious user able to send IPP requests
to the CUPS server could use this flaw to crash the CUPS server or,
potentially, execute arbitrary code with the privileges of the CUPS server.
(CVE-2010-2941)

A possible privilege escalation flaw was found in CUPS. An unprivileged
process running as the "lp" user (such as a compromised external filter
program spawned by the CUPS server) could trick the CUPS server into
overwriting arbitrary files as the root user. (CVE-2010-2431)

Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for
reporting the CVE-2010-2941 issue.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2941</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100811"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100812" severity="medium">
    <xccdf:title>RHSA-2010:0812: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A race condition flaw was found in the way Thunderbird handled Document
Object Model (DOM) element properties. An HTML mail message containing
malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2010-3765)

Note: JavaScript support is disabled by default in Thunderbird. The
CVE-2010-3765 issue is not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be restarted
for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100812"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100819" severity="medium">
    <xccdf:title>RHSA-2010:0819: pam security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

It was discovered that the pam_namespace module executed the external
script namespace.init with an unchanged environment inherited from an
application calling PAM. In cases where such an environment was untrusted
(for example, when pam_namespace was configured for setuid applications
such as su or sudo), a local, unprivileged user could possibly use this
flaw to escalate their privileges. (CVE-2010-3853)

It was discovered that the pam_mail module used root privileges while
accessing users' files. In certain configurations, a local, unprivileged
user could use this flaw to obtain limited information about files or
directories that they do not have access to. (CVE-2010-3435)

It was discovered that the pam_xauth module did not verify the return
values of the setuid() and setgid() system calls. A local, unprivileged
user could use this flaw to execute the xauth command with root privileges
and make it read an arbitrary input file. (CVE-2010-3316)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting the CVE-2010-3435 issue.

All pam users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0819</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3316</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3853</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4707</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100819"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100824" severity="medium">
    <xccdf:title>RHSA-2010:0824: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

It was found that the MySQL PolyFromWKB() function did not sanity check
Well-Known Binary (WKB) data. A remote, authenticated attacker could use
specially-crafted WKB data to crash mysqld. This issue only caused a
temporary denial of service, as mysqld was automatically restarted after
the crash. (CVE-2010-3840)

A flaw was found in the way MySQL processed certain alternating READ
requests provided by HANDLER statements. A remote, authenticated attacker
could use this flaw to provide such requests, causing mysqld to crash. This
issue only caused a temporary denial of service, as mysqld was
automatically restarted after the crash. (CVE-2010-3681)

A directory traversal flaw was found in the way MySQL handled the
parameters of the MySQL COM_FIELD_LIST network protocol command. A remote,
authenticated attacker could use this flaw to obtain descriptions of the
fields of an arbitrary table using a request with a specially-crafted
table name. (CVE-2010-1848)

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0824</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3840</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100824"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100825" severity="medium">
    <xccdf:title>RHSA-2010:0825: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

It was found that the MySQL PolyFromWKB() function did not sanity check
Well-Known Binary (WKB) data. A remote, authenticated attacker could use
specially-crafted WKB data to crash mysqld. This issue only caused a
temporary denial of service, as mysqld was automatically restarted after
the crash. (CVE-2010-3840)

A flaw was found in the way MySQL processed certain JOIN queries. If a
stored procedure contained JOIN queries, and that procedure was executed
twice in sequence, it could cause an infinite loop, leading to excessive
CPU use (up to 100%). A remote, authenticated attacker could use this flaw
to cause a denial of service. (CVE-2010-3839)

A flaw was found in the way MySQL processed queries that provide a mixture
of numeric and longblob data types to the LEAST or GREATEST function. A
remote, authenticated attacker could use this flaw to crash mysqld. This
issue only caused a temporary denial of service, as mysqld was
automatically restarted after the crash. (CVE-2010-3838)

A flaw was found in the way MySQL processed PREPARE statements containing
both GROUP_CONCAT and the WITH ROLLUP modifier. A remote, authenticated
attacker could use this flaw to crash mysqld. This issue only caused a
temporary denial of service, as mysqld was automatically restarted after
the crash. (CVE-2010-3837)

It was found that MySQL did not properly pre-evaluate LIKE arguments in
view prepare mode. A remote, authenticated attacker could possibly use this
flaw to crash mysqld. (CVE-2010-3836)

A flaw was found in the way MySQL processed statements that assign a value
to a user-defined variable and that also contain a logical value
evaluation. A remote, authenticated attacker could use this flaw to crash
mysqld. This issue only caused a temporary denial of service, as mysqld was
automatically restarted after the crash. (CVE-2010-3835)

A flaw was found in the way MySQL evaluated the arguments of extreme-value
functions, such as LEAST and GREATEST. A remote, authenticated attacker
could use this flaw to crash mysqld. This issue only caused a temporary
denial of service, as mysqld was automatically restarted after the crash.
(CVE-2010-3833)

A flaw was found in the way MySQL processed EXPLAIN statements for some
complex SELECT queries. A remote, authenticated attacker could use this
flaw to crash mysqld. This issue only caused a temporary denial of service,
as mysqld was automatically restarted after the crash. (CVE-2010-3682)

A flaw was found in the way MySQL processed certain alternating READ
requests provided by HANDLER statements. A remote, authenticated attacker
could use this flaw to provide such requests, causing mysqld to crash. This
issue only caused a temporary denial of service, as mysqld was
automatically restarted after the crash. (CVE-2010-3681)

A flaw was found in the way MySQL processed CREATE TEMPORARY TABLE
statements that define NULL columns when using the InnoDB storage engine. A
remote, authenticated attacker could use this flaw to crash mysqld. This
issue only caused a temporary denial of service, as mysqld was
automatically restarted after the crash. (CVE-2010-3680)

A flaw was found in the way MySQL processed JOIN queries that attempt to
retrieve data from a unique SET column. A remote, authenticated attacker
could use this flaw to crash mysqld. This issue only caused a temporary
denial of service, as mysqld was automatically restarted after the crash.
(CVE-2010-3677)

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3840</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100825"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100839" severity="medium">
    <xccdf:title>RHSA-2010:0839: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the io_submit_one() function
in the Linux kernel asynchronous I/O implementation. A local, unprivileged
user could use this flaw to cause a denial of service. (CVE-2010-3066,
Moderate)

* A flaw was found in the xfs_ioc_fsgetxattr() function in the Linux kernel
XFS file system implementation. A data structure in xfs_ioc_fsgetxattr()
was not initialized properly before being copied to user-space. A local,
unprivileged user could use this flaw to cause an information leak.
(CVE-2010-3078, Moderate)

* The exception fixup code for the __futex_atomic_op1, __futex_atomic_op2,
and futex_atomic_cmpxchg_inatomic() macros replaced the LOCK prefix with a
NOP instruction. A local, unprivileged user could use this flaw to cause a
denial of service. (CVE-2010-3086, Moderate)

* A flaw was found in the tcf_act_police_dump() function in the Linux
kernel network traffic policing implementation. A data structure in
tcf_act_police_dump() was not initialized properly before being copied to
user-space. A local, unprivileged user could use this flaw to cause an
information leak. (CVE-2010-3477, Moderate)

* A missing upper bound integer check was found in the sys_io_submit()
function in the Linux kernel asynchronous I/O implementation. A local,
unprivileged user could use this flaw to cause an information leak.
(CVE-2010-3067, Low)

Red Hat would like to thank Tavis Ormandy for reporting CVE-2010-3066,
CVE-2010-3086, and CVE-2010-3067, and Dan Rosenberg for reporting
CVE-2010-3078.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3477</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100839"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100842" severity="high">
    <xccdf:title>RHSA-2010:0842: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Missing sanity checks in the Intel i915 driver in the Linux kernel could
allow a local, unprivileged user to escalate their privileges.
(CVE-2010-2962, Important)

* compat_alloc_user_space() in the Linux kernel 32/64-bit compatibility
layer implementation was missing sanity checks. This function could be
abused in other areas of the Linux kernel if its length argument can be
controlled from user-space. On 64-bit systems, a local, unprivileged user
could use this flaw to escalate their privileges. (CVE-2010-3081,
Important)

* A buffer overflow flaw in niu_get_ethtool_tcam_all() in the niu Ethernet
driver in the Linux kernel, could allow a local user to cause a denial of
service or escalate their privileges. (CVE-2010-3084, Important)

* A flaw in the IA32 system call emulation provided in 64-bit Linux kernels
could allow a local user to escalate their privileges. (CVE-2010-3301,
Important)

* A flaw in sctp_packet_config() in the Linux kernel's Stream Control
Transmission Protocol (SCTP) implementation could allow a remote attacker
to cause a denial of service. (CVE-2010-3432, Important)

* A missing integer overflow check in snd_ctl_new() in the Linux kernel's
sound subsystem could allow a local, unprivileged user on a 32-bit system
to cause a denial of service or escalate their privileges. (CVE-2010-3442,
Important)

* A flaw was found in sctp_auth_asoc_get_hmac() in the Linux kernel's SCTP
implementation. When iterating through the hmac_ids array, it did not reset
the last id element if it was out of range. This could allow a remote
attacker to cause a denial of service. (CVE-2010-3705, Important)

* A function in the Linux kernel's Reliable Datagram Sockets (RDS) protocol
implementation was missing sanity checks, which could allow a local,
unprivileged user to escalate their privileges. (CVE-2010-3904, Important)

* A flaw in drm_ioctl() in the Linux kernel's Direct Rendering Manager
(DRM) implementation could allow a local, unprivileged user to cause an
information leak. (CVE-2010-2803, Moderate)

* It was found that wireless drivers might not always clear allocated
buffers when handling a driver-specific IOCTL information request. A local
user could trigger this flaw to cause an information leak. (CVE-2010-2955,
Moderate)

* A NULL pointer dereference flaw in ftrace_regex_lseek() in the Linux
kernel's ftrace implementation could allow a local, unprivileged user to
cause a denial of service. Note: The debugfs file system must be mounted
locally to exploit this issue. It is not mounted by default.
(CVE-2010-3079, Moderate)

* A flaw in the Linux kernel's packet writing driver could be triggered
via the PKT_CTRL_CMD_STATUS IOCTL request, possibly allowing a local,
unprivileged user with access to "/dev/pktcdvd/control" to cause an
information leak. Note: By default, only users in the cdrom group have
access to "/dev/pktcdvd/control". (CVE-2010-3437, Moderate)

* A flaw was found in the way KVM (Kernel-based Virtual Machine) handled
the reloading of fs and gs segment registers when they had invalid
selectors. A privileged host user with access to "/dev/kvm" could use this
flaw to crash the host. (CVE-2010-3698, Moderate)

Red Hat would like to thank Kees Cook for reporting CVE-2010-2962 and
CVE-2010-2803; Ben Hawkes for reporting CVE-2010-3081 and CVE-2010-3301;
Dan Rosenberg for reporting CVE-2010-3442, CVE-2010-3705, CVE-2010-3904,
and CVE-2010-3437; and Robert Swiecki for reporting CVE-2010-3079.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3437</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3904</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100842"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100858" severity="high">
    <xccdf:title>RHSA-2010:0858: bzip2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>bzip2 is a freely available, high-quality data compressor. It provides both
standalone compression and decompression utilities, as well as a shared
library for use with other programs.

An integer overflow flaw was discovered in the bzip2 decompression routine.
This issue could, when decompressing malformed archives, cause bzip2, or an
application linked against the libbz2 library, to crash or, potentially,
execute arbitrary code. (CVE-2010-0405)

Users of bzip2 should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications using the
libbz2 library must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0405</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100858"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100859" severity="high">
    <xccdf:title>RHSA-2010:0859: poppler security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Two uninitialized pointer use flaws were discovered in poppler. An attacker
could create a malicious PDF file that, when opened, would cause
applications that use poppler (such as Evince) to crash or, potentially,
execute arbitrary code. (CVE-2010-3702, CVE-2010-3703)

An array index error was found in the way poppler parsed PostScript Type 1
fonts embedded in PDF documents. An attacker could create a malicious PDF
file that, when opened, would cause applications that use poppler (such as
Evince) to crash or, potentially, execute arbitrary code. (CVE-2010-3704)

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0859</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100859"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100860" severity="high">
    <xccdf:title>RHSA-2010:0860: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A missing array boundary checking flaw was found in the way Samba parsed
the binary representation of Windows security identifiers (SIDs). A
malicious client could send a specially-crafted SMB request to the Samba
server, resulting in arbitrary code execution with the privileges of the
Samba server (smbd). (CVE-2010-3069)

Users of Samba are advised to upgrade to these updated packages, which
correct this issue. After installing this update, the smb service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3069</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100860"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100861" severity="high">
    <xccdf:title>RHSA-2010:0861: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A race condition flaw was found in the way Firefox handled Document Object
Model (DOM) element properties. Malicious HTML content could cause Firefox
to crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2010-3765)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-3175, CVE-2010-3176, CVE-2010-3179, CVE-2010-3183,
CVE-2010-3180)

A flaw was found in the way the Gopher parser in Firefox converted text
into HTML. A malformed file name on a Gopher server could, when accessed by
a victim running Firefox, allow arbitrary JavaScript to be executed in the
context of the Gopher domain. (CVE-2010-3177)

A same-origin policy bypass flaw was found in Firefox. An attacker could
create a malicious web page that, when viewed by a victim, could steal
private data from a different website the victim had loaded with Firefox.
(CVE-2010-3178)

A flaw was found in the script that launches Firefox. The LD_LIBRARY_PATH
variable was appending a "." character, which could allow a local attacker
to execute arbitrary code with the privileges of a different user running
Firefox, if that user ran Firefox from within an attacker-controlled
directory. (CVE-2010-3182)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.11 and 3.6.12. You can find links to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.12, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100861"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100862" severity="low">
    <xccdf:title>RHSA-2010:0862: nss security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

A flaw was found in the way NSS matched SSL certificates when the
certificates had a Common Name containing a wildcard and a partial IP
address. NSS incorrectly accepted connections to IP addresses that fell
within the SSL certificate's wildcard range as valid SSL connections,
possibly allowing an attacker to conduct a man-in-the-middle attack.
(CVE-2010-3170)

All NSS users should upgrade to these updated packages, which provide NSS
version 3.12.8 to resolve this issue. After installing the update,
applications using NSS must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3170</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100862"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100863" severity="high">
    <xccdf:title>RHSA-2010:0863: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An uninitialized pointer use flaw was found in the way the MIT Kerberos KDC
handled TGS (Ticket-granting Server) request messages. A remote,
authenticated attacker could use this flaw to crash the KDC or, possibly,
disclose KDC memory or execute arbitrary code with the privileges of the
KDC (krb5kdc). (CVE-2010-1322)

Red Hat would like to thank the MIT Kerberos Team for reporting this issue.
Upstream acknowledges Mike Roszkowski as the original reporter.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100863"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100864" severity="high">
    <xccdf:title>RHSA-2010:0864: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

It was found that the FreeType font rendering engine improperly validated
certain position values when processing input streams. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2805,
CVE-2010-3311)

A stack-based buffer overflow flaw was found in the way the FreeType font
rendering engine processed some PostScript Type 1 fonts. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2808)

An array index error was found in the way the FreeType font rendering
engine processed certain PostScript Type 42 font files. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2806)

Note: All of the issues in this erratum only affect the FreeType 2 font
engine.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3311</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100864"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100865" severity="high">
    <xccdf:title>RHSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

defaultReadObject of the Serialization API could be tricked into setting a
volatile field multiple times, which could allow a remote attacker to
execute arbitrary code with the privileges of the user running the applet
or application. (CVE-2010-3569)

Race condition in the way objects were deserialized could allow an
untrusted applet or application to misuse the privileges of the user
running the applet or application. (CVE-2010-3568)

Miscalculation in the OpenType font rendering implementation caused
out-of-bounds memory access, which could allow remote attackers to execute
code with the privileges of the user running the java process.
(CVE-2010-3567)

JPEGImageWriter.writeImage in the imageio API improperly checked certain
image metadata, which could allow a remote attacker to execute arbitrary
code in the context of the user running the applet or application.
(CVE-2010-3565)

Double free in IndexColorModel could cause an untrusted applet or
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the applet or application. (CVE-2010-3562)

The privileged accept method of the ServerSocket class in the Common Object
Request Broker Architecture (CORBA) implementation in OpenJDK allowed it to
receive connections from any host, instead of just the host of the current
connection. An attacker could use this flaw to bypass restrictions defined
by network permissions. (CVE-2010-3561)

Flaws in the Swing library could allow an untrusted application to modify
the behavior and state of certain JDK classes. (CVE-2010-3557)

Flaws in the CORBA implementation could allow an attacker to execute
arbitrary code by misusing permissions granted to certain system objects.
(CVE-2010-3554)

UIDefault.ProxyLazyValue had unsafe reflection usage, allowing untrusted
callers to create objects via ProxyLazyValue values. (CVE-2010-3553)

HttpURLConnection improperly handled the "chunked" transfer encoding
method, which could allow remote attackers to conduct HTTP response
splitting attacks. (CVE-2010-3549)

HttpURLConnection improperly checked whether the calling code was granted
the "allowHttpTrace" permission, allowing untrusted code to create HTTP
TRACE requests. (CVE-2010-3574)

HttpURLConnection did not validate request headers set by applets, which
could allow remote attackers to trigger actions otherwise restricted to
HTTP clients. (CVE-2010-3541, CVE-2010-3573)

The Kerberos implementation improperly checked the sanity of AP-REQ
requests, which could cause a denial of service condition in the receiving
Java Virtual Machine. (CVE-2010-3564)

The java-1.6.0-openjdk packages shipped with the GA release of Red Hat
Enterprise Linux 6 mitigated a man-in-the-middle attack in the way the
TLS/SSL protocols handle session renegotiation by disabling renegotiation.
This update implements the TLS Renegotiation Indication Extension as
defined in RFC 5746, allowing secure renegotiation between updated clients
and servers. (CVE-2009-3555)

The NetworkInterface class improperly checked the network "connect"
permissions for local network addresses, which could allow remote attackers
to read local network addresses. (CVE-2010-3551)

Information leak flaw in the Java Naming and Directory Interface (JNDI)
could allow a remote attacker to access information about
otherwise-protected internal network names. (CVE-2010-3548)

Note: Flaws concerning applets in this advisory (CVE-2010-3568,
CVE-2010-3554, CVE-2009-3555, CVE-2010-3562, CVE-2010-3557, CVE-2010-3548,
CVE-2010-3564, CVE-2010-3565, CVE-2010-3569) can only be triggered in
OpenJDK by calling the "appletviewer" application.

Bug fixes:

* One defense in depth patch. (BZ#639922)

* Problems for certain SSL connections. In a reported case, this prevented
the JBoss JAAS modules from connecting over SSL to Microsoft Active
Directory servers. (BZ#642779)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3574</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100865"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100866" severity="high">
    <xccdf:title>RHSA-2010:0866: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An invalid free flaw was found in the way the CUPS server parsed Internet
Printing Protocol (IPP) packets. A malicious user able to send IPP requests
to the CUPS server could use this flaw to crash the CUPS server.
(CVE-2010-2941)

Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for
reporting this issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0866</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2941</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100866"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100872" severity="high">
    <xccdf:title>RHSA-2010:0872: glibc security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system
cannot function properly.

It was discovered that the glibc dynamic linker/loader did not handle the
$ORIGIN dynamic string token set in the LD_AUDIT environment variable
securely. A local attacker with write access to a file system containing
setuid or setgid binaries could use this flaw to escalate their privileges.
(CVE-2010-3847)

It was discovered that the glibc dynamic linker/loader did not perform
sufficient safety checks when loading dynamic shared objects (DSOs) to
provide callbacks for its auditing API during the execution of privileged
programs. A local attacker could use this flaw to escalate their privileges
via a carefully-chosen system DSO library containing unsafe constructors.
(CVE-2010-3856)

Red Hat would like to thank Tavis Ormandy for reporting the CVE-2010-3847
issue, and Ben Hawkes and Tavis Ormandy for reporting the CVE-2010-3856
issue.

This update also fixes the following bugs:

* Previously, the generic implementation of the strstr() and memmem()
functions did not handle certain periodic patterns correctly and could find
a false positive match. This error has been fixed, and both functions now
work as expected. (BZ#643341)

* The "TCB_ALIGNMENT" value has been increased to 32 bytes to prevent
applications from crashing during symbol resolution on 64-bit systems with
support for Intel AVX vector registers. (BZ#643343)

All users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3856</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100872"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100888" severity="high">
    <xccdf:title>RHSA-2010:0888: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A race condition flaw has been found in the OpenSSL TLS server extension
parsing code, which could affect some multithreaded OpenSSL applications.
Under certain specific conditions, it may be possible for a remote attacker
to trigger this race condition and cause such an application to crash, or
possibly execute arbitrary code with the permissions of the application.
(CVE-2010-3864)

Note that this issue does not affect the Apache HTTP Server. Refer to Red
Hat Bugzilla bug 649304 for more technical details on how to determine if
your application is affected.

Red Hat would like to thank Rob Hulswit for reporting this issue.

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. For the update to take effect, all
services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0888</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3864</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100888"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100889" severity="high">
    <xccdf:title>RHSA-2010:0889: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.

A heap-based buffer overflow flaw was found in the way the FreeType font
rendering engine processed certain TrueType GX fonts. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-3855)

Note: This issue only affects the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3855</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100889"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100890" severity="medium">
    <xccdf:title>RHSA-2010:0890: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Multiple NULL pointer dereference flaws were found in the way Pidgin
handled Base64 decoding. A remote attacker could use these flaws to crash
Pidgin if the target Pidgin user was using the Yahoo! Messenger Protocol,
MSN, MySpace, or Extensible Messaging and Presence Protocol (XMPP) protocol
plug-ins, or using the Microsoft NT LAN Manager (NTLM) protocol for
authentication. (CVE-2010-3711)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Daniel Atallah as the original reporter.

All Pidgin users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. Pidgin must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3711</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100890"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100891" severity="medium">
    <xccdf:title>RHSA-2010:0891: pam security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

It was discovered that the pam_namespace module executed the external
script namespace.init with an unchanged environment inherited from an
application calling PAM. In cases where such an environment was untrusted
(for example, when pam_namespace was configured for setuid applications
such as su or sudo), a local, unprivileged user could possibly use this
flaw to escalate their privileges. (CVE-2010-3853)

It was discovered that the pam_env and pam_mail modules used root
privileges while accessing user's files. A local, unprivileged user could
use this flaw to obtain information, from the lines that have the KEY=VALUE
format expected by pam_env, from an arbitrary file. Also, in certain
configurations, a local, unprivileged user using a service for which the
pam_mail module was configured for, could use this flaw to obtain limited
information about files or directories that they do not have access to.
(CVE-2010-3435)

Note: As part of the fix for CVE-2010-3435, this update changes the default
value of pam_env's configuration option user_readenv to 0, causing the
module to not read user's ~/.pam_environment configuration file by default,
as reading it may introduce unexpected changes to the environment of the
service using PAM, or PAM modules consulted after pam_env.

It was discovered that the pam_xauth module did not verify the return
values of the setuid() and setgid() system calls. A local, unprivileged
user could use this flaw to execute the xauth command with root privileges
and make it read an arbitrary input file. (CVE-2010-3316)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting the CVE-2010-3435 issue.

All pam users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0891</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3316</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3853</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4708</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100891"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100892" severity="medium">
    <xccdf:title>RHSA-2010:0892: openswan security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks.

Two buffer overflow flaws were found in the Openswan client-side XAUTH
handling code used when connecting to certain Cisco gateways. A malicious
or compromised VPN gateway could use these flaws to execute arbitrary code
on the connecting Openswan client. (CVE-2010-3302, CVE-2010-3308)

Two input sanitization flaws were found in the Openswan client-side
handling of Cisco gateway banners. A malicious or compromised VPN gateway
could use these flaws to execute arbitrary code on the connecting Openswan
client. (CVE-2010-3752, CVE-2010-3753)

Red Hat would like to thank the Openswan project for reporting these
issues. Upstream acknowledges D. Hugh Redelmeier and Paul Wouters as the
original reporters.

All users of openswan are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0892</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3753</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100892"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100894" severity="high">
    <xccdf:title>RHSA-2010:0894: systemtap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system. staprun, the SystemTap runtime tool, is used for
managing SystemTap kernel modules (for example, loading them).

It was discovered that staprun did not properly sanitize the environment
before executing the modprobe command to load an additional kernel module.
A local, unprivileged user could use this flaw to escalate their
privileges. (CVE-2010-4170)

It was discovered that staprun did not check if the module to be unloaded
was previously loaded by SystemTap. A local, unprivileged user could use
this flaw to unload an arbitrary kernel module that was not in use.
(CVE-2010-4171)

Note: After installing this update, users already in the stapdev group must
be added to the stapusr group in order to be able to run the staprun tool.

Red Hat would like to thank Tavis Ormandy for reporting these issues.

SystemTap users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0894</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4171</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100894"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100895" severity="medium">
    <xccdf:title>RHSA-2010:0895: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system. staprun, the SystemTap runtime tool, is used for
managing SystemTap kernel modules (for example, loading them).

It was discovered that staprun did not properly sanitize the environment
before executing the modprobe command to load an additional kernel module.
A local, unprivileged user could use this flaw to escalate their
privileges. (CVE-2010-4170)

Note: On Red Hat Enterprise Linux 4, an attacker must be a member of the
stapusr group to exploit this issue. Also note that, after installing this
update, users already in the stapdev group must be added to the stapusr
group in order to be able to run the staprun tool.

Red Hat would like to thank Tavis Ormandy for reporting this issue.

SystemTap users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0895</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4170</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100895"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100896" severity="medium">
    <xccdf:title>RHSA-2010:0896: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A race condition flaw was found in the way Thunderbird handled Document
Object Model (DOM) element properties. An HTML mail message containing
malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2010-3765)

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2010-3175, CVE-2010-3176, CVE-2010-3179,
CVE-2010-3180, CVE-2010-3183)

A same-origin policy bypass flaw was found in Thunderbird. Remote HTML
content could steal private data from different remote HTML content
Thunderbird had loaded. (CVE-2010-3178)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the script that launches Thunderbird. The
LD_LIBRARY_PATH variable was appending a "." character, which could allow a
local attacker to execute arbitrary code with the privileges of a different
user running Thunderbird, if that user ran Thunderbird from within an
attacker-controlled directory. (CVE-2010-3182)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3765</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100896"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100898" severity="medium">
    <xccdf:title>RHSA-2010:0898: kvm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way QEMU-KVM handled the reloading of fs and gs
segment registers when they had invalid selectors. A privileged host user
with access to "/dev/kvm" could use this flaw to crash the host (denial of
service). (CVE-2010-3698)

All KVM users should upgrade to these updated packages, which contain a
backported patch to correct this issue. Note: The procedure in the Solution
section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100898"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100908" severity="medium">
    <xccdf:title>RHSA-2010:0908: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS). PL/Perl and PL/Tcl allow users to write PostgreSQL functions in the
Perl and Tcl languages. The PostgreSQL SECURITY DEFINER parameter, which
can be used when creating a new PostgreSQL function, specifies that the
function will be executed with the privileges of the user that created it.

It was discovered that a user could utilize the features of the PL/Perl and
PL/Tcl languages to modify the behavior of a SECURITY DEFINER function
created by a different user. If the PL/Perl or PL/Tcl language was used to
implement a SECURITY DEFINER function, an authenticated database user could
use a PL/Perl or PL/Tcl script to modify the behavior of that function
during subsequent calls in the same session. This would result in the
modified or injected code also being executed with the privileges of the
user who created the SECURITY DEFINER function, possibly leading to
privilege escalation. (CVE-2010-3433)

These updated postgresql packages upgrade PostgreSQL to version 8.4.5.
Refer to the PostgreSQL Release Notes for a list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3433</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100908"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100918" severity="medium">
    <xccdf:title>RHSA-2010:0918: cvs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Concurrent Version System (CVS) is a version control system that can record
the history of your files.

An array index error, leading to a heap-based buffer overflow, was found in
the way CVS applied certain delta fragment changes from input files in the
RCS (Revision Control System file) format. If an attacker in control of a
CVS repository stored a specially-crafted RCS file in that repository, and
then tricked a remote victim into checking out (updating their CVS
repository tree) a revision containing that file, it could lead to
arbitrary code execution with the privileges of the CVS server process
on the system hosting the CVS repository. (CVE-2010-3846)

Red Hat would like to thank Ralph Loader for reporting this issue.

All users of cvs are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0918</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3846</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100918"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100919" severity="medium">
    <xccdf:title>RHSA-2010:0919: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

An input validation flaw was discovered in the PHP session serializer. If a
PHP script generated session variable names from untrusted user input, a
remote attacker could use this flaw to inject an arbitrary variable into
the PHP session. (CVE-2010-3065)

An information leak flaw was discovered in the PHP var_export() function
implementation. If some fatal error occurred during the execution of this
function (such as the exhaustion of memory or script execution time limit),
part of the function's output was sent to the user as script output,
possibly leading to the disclosure of sensitive information.
(CVE-2010-2531)

A numeric truncation error and an input validation flaw were found in the
way the PHP utf8_decode() function decoded partial multi-byte sequences
for some multi-byte encodings, sending them to output without them being
escaped. An attacker could use these flaws to perform a cross-site
scripting attack. (CVE-2009-5016, CVE-2010-3870)

It was discovered that the PHP lcg_value() function used insufficient
entropy to seed the pseudo-random number generator. A remote attacker could
possibly use this flaw to predict values returned by the function, which
are used to generate session identifiers by default. This update changes
the function's implementation to use more entropy during seeding.
(CVE-2010-1128)

It was discovered that the PHP fnmatch() function did not restrict the
length of the pattern argument. A remote attacker could use this flaw to
crash the PHP interpreter where a script used fnmatch() on untrusted
matching patterns. (CVE-2010-1917)

A NULL pointer dereference flaw was discovered in the PHP XML-RPC
extension. A malicious XML-RPC client or server could use this flaw to
crash the PHP interpreter via a specially-crafted XML-RPC request.
(CVE-2010-0397)

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1917</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3870</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100919"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100923" severity="medium">
    <xccdf:title>RHSA-2010:0923: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. DHCPv6 is the DHCP protocol version for IPv6 networks.

A NULL pointer dereference flaw was discovered in the way the dhcpd daemon
parsed DHCPv6 packets. A remote attacker could use this flaw to crash dhcpd
via a specially-crafted DHCPv6 packet, if dhcpd was running as a DHCPv6
server. (CVE-2010-3611)

Users running dhcpd as a DHCPv6 server should upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0923</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3611</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100923"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100924" severity="medium">
    <xccdf:title>RHSA-2010:0924: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A heap-based buffer overflow flaw was found in the Wireshark Local Download
Sharing Service (LDSS) dissector. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2010-4300)

A denial of service flaw was found in Wireshark. Wireshark could crash or
stop responding if it read a malformed packet off a network, or opened a
malicious dump file. (CVE-2010-3445)

Users of Wireshark should upgrade to these updated packages, which contain
Wireshark version 1.2.13, and resolve these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0924</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4300</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100924"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100925" severity="high">
    <xccdf:title>RHSA-2010:0925: krb5 security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

Multiple checksum validation flaws were discovered in the MIT Kerberos
implementation. A remote attacker could use these flaws to tamper with
certain Kerberos protocol packets and, possibly, bypass authentication or
authorization mechanisms and escalate their privileges. (CVE-2010-1323,
CVE-2010-1324, CVE-2010-4020)

Red Hat would like to thank the MIT Kerberos Team for reporting these
issues.

This update also fixes the following bug:

* When attempting to perform PKINIT pre-authentication, if the client had
more than one possible candidate certificate the client could fail to
select the certificate and key to use. This usually occurred if certificate
selection was configured to use the value of the keyUsage extension, or if
any of the candidate certificates did not contain a subjectAltName
extension. Consequently, the client attempted to perform pre-authentication
using a different (usually password-based) mechanism. (BZ#644825)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4020</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100925"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100926" severity="medium">
    <xccdf:title>RHSA-2010:0926: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

Multiple checksum validation flaws were discovered in the MIT Kerberos
implementation. A remote attacker could use these flaws to tamper with
certain Kerberos protocol packets and, possibly, bypass authentication
mechanisms in certain configurations using Single-use Authentication
Mechanisms. (CVE-2010-1323)

Red Hat would like to thank the MIT Kerberos Team for reporting these
issues.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1323</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100926"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100936" severity="high">
    <xccdf:title>RHSA-2010:0936: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* A flaw in sctp_packet_config() in the Linux kernel's Stream Control
Transmission Protocol (SCTP) implementation could allow a remote attacker
to cause a denial of service. (CVE-2010-3432, Important)

* A missing integer overflow check in snd_ctl_new() in the Linux kernel's
sound subsystem could allow a local, unprivileged user on a 32-bit system
to cause a denial of service or escalate their privileges. (CVE-2010-3442,
Important)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-3442.

Bug fixes:

* Forward time drift was observed on virtual machines using PM
timer-based kernel tick accounting and running on KVM or the Microsoft
Hyper-V Server hypervisor. Virtual machines that were booted with the
divider=x kernel parameter set to a value greater than 1 and that showed
the following in the kernel boot messages were subject to this issue:

time.c: Using PM based timekeeping

Fine grained accounting for the PM timer is introduced which eliminates
this issue. However, this fix uncovered a bug in the Xen hypervisor,
possibly causing backward time drift. If this erratum is installed in Xen
HVM guests that meet the aforementioned conditions, it is recommended that
the host use kernel-xen-2.6.18-194.26.1.el5 or newer, which includes a fix
(BZ#641915) for the backward time drift. (BZ#629237)

* With multipath enabled, systems would occasionally halt when the
do_cciss_request function was used. This was caused by wrongly-generated
requests. Additional checks have been added to avoid the aforementioned
issue. (BZ#640193)

* A Sun X4200 system equipped with a QLogic HBA spontaneously rebooted and
logged a Hyper-Transport Sync Flood Error to the system event log. A
Maximum Memory Read Byte Count restriction was added to fix this bug.
(BZ#640919)

* For an active/backup bonding network interface with VLANs on top of it,
when a link failed over, it took a minute for the multicast domain to be
rejoined. This was caused by the driver not sending any IGMP join packets.
The driver now sends IGMP join packets and the multicast domain is rejoined
immediately. (BZ#641002)

* Replacing a disk and trying to rebuild it afterwards caused the system to
panic. When a domain validation request for a hot plugged drive was sent,
the mptscsi driver did not validate its existence. This could result in the
driver accessing random memory and causing the crash. A check has been
added that describes the newly-added device and reloads the iocPg3 data
from the firmware if needed. (BZ#641137)

* An attempt to create a VLAN interface on a bond of two bnx2 adapters in
two switch configurations resulted in a soft lockup after a few seconds.
This was caused by an incorrect use of a bonding pointer. With this update,
soft lockups no longer occur and creating a VLAN interface works as
expected. (BZ#641254)

* Erroneous pointer checks could have caused a kernel panic. This was due
to a critical value not being copied when a network buffer was duplicated
and consumed by multiple portions of the kernel's network stack. Fixing the
copy operation resolved this bug. (BZ#642746)

* A typo in a variable name caused it to be dereferenced in either mkdir()
or create() which could cause a kernel panic. (BZ#643342)

* SCSI high level drivers can submit SCSI commands which would never be
completed when the device was offline. This was caused by a missing
callback for the request to complete the given command. SCSI requests are
now terminated by calling their callback when a device is offline.
(BZ#644816)

* A kernel panic could have occurred on systems due to a recursive lock in
the 3c59x driver. Recursion is now avoided and this kernel panic no longer
occurs. (BZ#648407)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0936</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3442</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100936"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100945" severity="medium">
    <xccdf:title>RHSA-2010:0945: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol.

A stack-based buffer overflow flaw was found in the way the Quagga bgpd
daemon processed certain BGP Route Refresh (RR) messages. A configured BGP
peer could send a specially-crafted BGP message, causing bgpd on a target
system to crash or, possibly, execute arbitrary code with the privileges of
the user running bgpd. (CVE-2010-2948)

Note: On Red Hat Enterprise Linux 6 it is not possible to exploit
CVE-2010-2948 to run arbitrary code as the overflow is blocked by
FORTIFY_SOURCE.

A NULL pointer dereference flaw was found in the way the Quagga bgpd daemon
parsed the paths of autonomous systems (AS). A configured BGP peer could
crash bgpd on a target system via a specially-crafted BGP message.
(CVE-2010-2949)

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0945</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2948</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2949</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100945"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100950" severity="medium">
    <xccdf:title>RHSA-2010:0950: apr-util security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. apr-util is a library which provides
additional utility interfaces for APR; including support for XML parsing,
LDAP, database interfaces, URI parsing, and more.

It was found that certain input could cause the apr-util library to
allocate more memory than intended in the apr_brigade_split_line()
function. An attacker able to provide input in small chunks to an
application using the apr-util library (such as httpd) could possibly use
this flaw to trigger high memory consumption. (CVE-2010-1623)

All apr-util users should upgrade to these updated packages, which contain
a backported patch to correct this issue. Applications using the apr-util
library, such as httpd, must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0950</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1623</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100950"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100966" severity="high">
    <xccdf:title>RHSA-2010:0966: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-3766, CVE-2010-3767, CVE-2010-3772, CVE-2010-3776,
CVE-2010-3777)

A flaw was found in the way Firefox handled malformed JavaScript. A website
with an object containing malicious JavaScript could cause Firefox to
execute that JavaScript with the privileges of the user running Firefox.
(CVE-2010-3771)

This update adds support for the Sanitiser for OpenType (OTS) library to
Firefox. This library helps prevent potential exploits in malformed
OpenType fonts by verifying the font file prior to use. (CVE-2010-3768)

A flaw was found in the way Firefox loaded Java LiveConnect scripts.
Malicious web content could load a Java LiveConnect script in a way that
would result in the plug-in object having elevated privileges, allowing it
to execute Java code with the privileges of the user running Firefox.
(CVE-2010-3775)

It was found that the fix for CVE-2010-0179 was incomplete when the Firebug
add-on was used. If a user visited a website containing malicious
JavaScript while the Firebug add-on was enabled, it could cause Firefox to
execute arbitrary JavaScript with the privileges of the user running
Firefox. (CVE-2010-3773)

A flaw was found in the way Firefox presented the location bar to users. A
malicious website could trick a user into thinking they are visiting the
site reported by the location bar, when the page is actually content
controlled by an attacker. (CVE-2010-3774)

A cross-site scripting (XSS) flaw was found in the Firefox x-mac-arabic,
x-mac-farsi, and x-mac-hebrew character encodings. Certain characters were
converted to angle brackets when displayed. If server-side script filtering
missed these cases, it could result in Firefox executing JavaScript code
with the permissions of a different website. (CVE-2010-3770)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.13. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.13, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3766</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3770</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3773</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3777</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100966"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100967" severity="high">
    <xccdf:title>RHSA-2010:0967: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-3767, CVE-2010-3772, CVE-2010-3776)

A flaw was found in the way SeaMonkey loaded Java LiveConnect scripts.
Malicious web content could load a Java LiveConnect script in a way that
would result in the plug-in object having elevated privileges, allowing it
to execute Java code with the privileges of the user running SeaMonkey.
(CVE-2010-3775)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0967</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100967"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100968" severity="medium">
    <xccdf:title>RHSA-2010:0968: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. HTML
containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2010-3767, CVE-2010-3772, CVE-2010-3776)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0968</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100968"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100969" severity="medium">
    <xccdf:title>RHSA-2010:0969: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2010-3776, CVE-2010-3777)

Note: JavaScript support is disabled in Thunderbird for mail messages. The
above issues are believed to not be exploitable without JavaScript.

This update adds support for the Sanitiser for OpenType (OTS) library to Thunderbird. This library helps prevent potential exploits in malformed OpenType fonts by verifying the font file prior to use. (CVE-2010-3768)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0969</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3777</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100969"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100970" severity="high">
    <xccdf:title>RHSA-2010:0970: exim security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet.

A buffer overflow flaw was discovered in Exim's internal
string_vformat() function. A remote attacker could use this flaw to
execute arbitrary code on the mail server running Exim. (CVE-2010-4344)

Note: successful exploitation would allow a remote attacker to execute
arbitrary code as root on a Red Hat Enterprise Linux 4 or 5 system that
is running the Exim mail server. An exploit for this issue is known to
exist.

For additional information regarding this flaw, along with mitigation
advice, please see the Knowledge Base article linked to in the
References section of this advisory.

Users of Exim are advised to update to these erratum packages which
contain a backported patch to correct this issue. After installing this
update, the Exim daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4344</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100970"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100975" severity="high">
    <xccdf:title>RHSA-2010:0975: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

It was discovered that named did not invalidate previously cached RRSIG
records when adding an NCACHE record for the same entry to the cache. A
remote attacker allowed to send recursive DNS queries to named could use
this flaw to crash named. (CVE-2010-3613)

It was discovered that, in certain cases, named did not properly perform
DNSSEC validation of an NS RRset for zones in the middle of a DNSKEY
algorithm rollover. This flaw could cause the validator to incorrectly
determine that the zone is insecure and not protected by DNSSEC.
(CVE-2010-3614)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3614</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100975"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100976" severity="high">
    <xccdf:title>RHSA-2010:0976: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

It was discovered that named did not invalidate previously cached RRSIG
records when adding an NCACHE record for the same entry to the cache. A
remote attacker allowed to send recursive DNS queries to named could use
this flaw to crash named. (CVE-2010-3613)

A flaw was found in the DNSSEC validation code in named. If named had
multiple trust anchors configured for a zone, a response to a request for a
record in that zone with a bad signature could cause named to crash.
(CVE-2010-3762)

It was discovered that, in certain cases, named did not properly perform
DNSSEC validation of an NS RRset for zones in the middle of a DNSKEY
algorithm rollover. This flaw could cause the validator to incorrectly
determine that the zone is insecure and not protected by DNSSEC.
(CVE-2010-3614)

All BIND users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3614</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3762</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100976"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100977" severity="medium">
    <xccdf:title>RHSA-2010:0977: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A ciphersuite downgrade flaw was found in the OpenSSL SSL/TLS server code.
A remote attacker could possibly use this flaw to change the ciphersuite
associated with a cached session stored on the server, if the server
enabled the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG option, possibly
forcing the client to use a weaker ciphersuite after resuming the session.
(CVE-2010-4180, CVE-2008-7270)

Note: With this update, setting the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG
option has no effect and this bug workaround can no longer be enabled.

It was discovered that OpenSSL did not always check the return value of the
bn_wexpand() function. An attacker able to trigger a memory allocation
failure in that function could possibly crash an application using the
OpenSSL library and its UBSEC hardware engine support. (CVE-2009-3245)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0977</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-7270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4180</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100977"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100978" severity="medium">
    <xccdf:title>RHSA-2010:0978: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A ciphersuite downgrade flaw was found in the OpenSSL SSL/TLS server code.
A remote attacker could possibly use this flaw to change the ciphersuite
associated with a cached session stored on the server, if the server
enabled the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG option, possibly
forcing the client to use a weaker ciphersuite after resuming the session.
(CVE-2010-4180, CVE-2008-7270)

Note: With this update, setting the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG
option has no effect and this bug workaround can no longer be enabled.

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0978</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-7270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4180</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100978"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100979" severity="medium">
    <xccdf:title>RHSA-2010:0979: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A ciphersuite downgrade flaw was found in the OpenSSL SSL/TLS server code.
A remote attacker could possibly use this flaw to change the ciphersuite
associated with a cached session stored on the server, if the server
enabled the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG option, possibly
forcing the client to use a weaker ciphersuite after resuming the session.
(CVE-2010-4180)

Note: With this update, setting the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG
option has no effect and this bug workaround can no longer be enabled.

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. For the update to take effect, all
services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4180</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100979"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100981" severity="high">
    <xccdf:title>RHSA-2010:0981: HelixPlayer removal (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Helix Player is a media player.

Multiple security flaws were discovered in RealPlayer. Helix Player and
RealPlayer share a common source code base; therefore, some of the flaws
discovered in RealPlayer may also affect Helix Player. Some of these flaws
could, when opening, viewing, or playing a malicious media file or stream,
lead to arbitrary code execution with the privileges of the user running
Helix Player. (CVE-2010-2997, CVE-2010-4375, CVE-2010-4378, CVE-2010-4379,
CVE-2010-4382, CVE-2010-4383, CVE-2010-4384, CVE-2010-4385, CVE-2010-4386,
CVE-2010-4392)

The Red Hat Security Response Team is unable to properly determine the
impact or fix all of these issues in Helix Player, due to the source code
for RealPlayer being unavailable.

Due to the security concerns this update removes the HelixPlayer package
from Red Hat Enterprise Linux 4. Users wishing to continue to use Helix
Player should download it directly from https://player.helixcommunity.org/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4392</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100998" severity="low">
    <xccdf:title>RHSA-2010:0998: kvm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

It was found that some structure padding and reserved fields in certain
data structures in QEMU-KVM were not initialized properly before being
copied to user-space. A privileged host user with access to "/dev/kvm"
could use this flaw to leak kernel stack memory to user-space.
(CVE-2010-3881)

Red Hat would like to thank Vasiliy Kulikov for reporting this issue.

This update also fixes the following bugs:

* The 'kvm_amd' kernel module did not initialize the TSC (Time Stamp
Counter) offset in the VMCB (Virtual Machine Control Block) correctly.
After a vCPU (virtual CPU) has been created, the TSC offset in the VMCB
should have a negative value so that the virtual machine will see TSC
values starting at zero. However, the TSC offset was set to zero and
therefore the virtual machine saw the same TSC value as the host. With this
update, the TSC offset has been updated to show the correct values.
(BZ#656984)

* Setting the boot settings of a virtual machine to, firstly, boot from PXE
and, secondly, to boot from the hard drive would result in a PXE boot loop,
that is, the virtual machine would not continue to boot from the hard drive
if the PXE boot failed. This was caused by a flaw in the 'bochs-bios' (part
of KVM) code. With this update, after a virtual machine tries to boot from
PXE and fails, it continues to boot from a hard drive if there is one
present. (BZ#659850)

* If a 64-bit Red Hat Enterprise Linux 5.5 virtual machine was migrated to
another host with a different CPU clock speed, the clock of that virtual
machine would consistently lose or gain time (approximately half a second
for every second the host is running). On machines that do not use the kvm
clock, the network time protocol daemon (ntpd) could correct the time
drifts caused by migration. However, using the pvclock caused the time to
change consistently. This was due to flaws in the save/load functions of
pvclock. With this update, the issue has been fixed and migrating a virtual
machine no longer causes time drift. (BZ#660239)

All KVM users should upgrade to these updated packages, which contain
backported patches to correct these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3881</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100998"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20100999" severity="medium">
    <xccdf:title>RHSA-2010:0999: libvpx security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvpx packages provide the VP8 SDK, which allows the encoding and
decoding of the VP8 video codec, commonly used with the WebM multimedia
container file format.

An integer overflow flaw, leading to arbitrary memory writes, was found in
libvpx. An attacker could create a specially-crafted video encoded using
the VP8 codec that, when played by a victim with an application using
libvpx (such as Totem), would cause the application to crash or,
potentially, execute arbitrary code. (CVE-2010-4203)

All users of libvpx are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libvpx must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:0999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4203</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20100999"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20101000" severity="high">
    <xccdf:title>RHSA-2010:1000: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

It was discovered that named did not invalidate previously cached SIG
records when adding an NCACHE record for the same entry to the cache. A
remote attacker allowed to send recursive DNS queries to named could use
this flaw to crash named. (CVE-2010-3613)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:1000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3613</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20101000"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20101002" severity="medium">
    <xccdf:title>RHSA-2010:1002: mod_auth_mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_auth_mysql package includes an extension module for the Apache HTTP
Server, which can be used to implement web user authentication against a
MySQL database.

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a
multibyte character set that allowed a backslash ("\") as part of the
character encodings, a remote attacker could inject arbitrary SQL commands
into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where
AuthMySQLCharacterSet is configured to use one of the affected multibyte
character sets. Installations that did not use the AuthMySQLCharacterSet
configuration option were not vulnerable to this flaw.

All mod_auth_mysql users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue. After installing
the updated package, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:1002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2384</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20101002"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20101003" severity="medium">
    <xccdf:title>RHSA-2010:1003: git security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Git is a fast, scalable, distributed revision control system.

A cross-site scripting (XSS) flaw was found in gitweb, a simple web
interface for Git repositories. A remote attacker could perform an XSS
attack against victims by tricking them into visiting a specially-crafted
gitweb URL. (CVE-2010-3906)

All gitweb users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2010:1003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3906</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20101003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110004" severity="high">
    <xccdf:title>RHSA-2011:0004: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in sctp_packet_config() in the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation. A remote attacker
could use this flaw to cause a denial of service. (CVE-2010-3432,
Important)

* A missing integer overflow check was found in snd_ctl_new() in the Linux
kernel's sound subsystem. A local, unprivileged user on a 32-bit system
could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-3442, Important)

* A heap overflow flaw in the Linux kernel's Transparent Inter-Process
Communication protocol (TIPC) implementation could allow a local,
unprivileged user to escalate their privileges. (CVE-2010-3859, Important)

* An integer overflow flaw was found in the Linux kernel's Reliable
Datagram Sockets (RDS) protocol implementation. A local, unprivileged user
could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-3865, Important)

* A flaw was found in the Xenbus code for the unified block-device I/O
interface back end. A privileged guest user could use this flaw to cause a
denial of service on the host system running the Xen hypervisor.
(CVE-2010-3699, Moderate)

* Missing sanity checks were found in setup_arg_pages() in the Linux
kernel. When making the size of the argument and environment area on the
stack very large, it could trigger a BUG_ON(), resulting in a local denial
of service. (CVE-2010-3858, Moderate)

* A flaw was found in inet_csk_diag_dump() in the Linux kernel's module for
monitoring the sockets of INET transport protocols. By sending a netlink
message with certain bytecode, a local, unprivileged user could cause a
denial of service. (CVE-2010-3880, Moderate)

* Missing sanity checks were found in gdth_ioctl_alloc() in the gdth driver
in the Linux kernel. A local user with access to "/dev/gdth" on a 64-bit
system could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-4157, Moderate)

* The fix for Red Hat Bugzilla bug 484590 as provided in RHSA-2009:1243
introduced a regression. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2010-4161, Moderate)

* A NULL pointer dereference flaw was found in the Bluetooth HCI UART
driver in the Linux kernel. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4242, Moderate)

* It was found that a malicious guest running on the Xen hypervisor could
place invalid data in the memory that the guest shared with the blkback and
blktap back-end drivers, resulting in a denial of service on the host
system. (CVE-2010-4247, Moderate)

* A flaw was found in the Linux kernel's CPU time clocks implementation for
the POSIX clock interface. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4248, Moderate)

* Missing initialization flaws in the Linux kernel could lead to
information leaks. (CVE-2010-3876, CVE-2010-4083, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-3442,
CVE-2010-4161, and CVE-2010-4083; Thomas Pollet for reporting
CVE-2010-3865; Brad Spengler for reporting CVE-2010-3858; Nelson Elhage for
reporting CVE-2010-3880; Alan Cox for reporting CVE-2010-4242; and Vasiliy
Kulikov for reporting CVE-2010-3876.

This update also fixes several bugs and adds an enhancement. Documentation
for the bug fixes and the enhancement will be available shortly from the
Technical Notes document, linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3859</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3880</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4161</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110004"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110007" severity="high">
    <xccdf:title>RHSA-2011:0007: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>* Buffer overflow in eCryptfs. When /dev/ecryptfs has world writable
permissions (which it does not, by default, on Red Hat Enterprise Linux 6),
a local, unprivileged user could use this flaw to cause a denial of service
or possibly escalate their privileges. (CVE-2010-2492, Important)

* Integer overflow in the RDS protocol implementation could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-3865, Important)

* Missing boundary checks in the PPP over L2TP sockets implementation could
allow a local, unprivileged user to cause a denial of service or escalate
their privileges. (CVE-2010-4160, Important)

* NULL pointer dereference in the igb driver. If both Single Root I/O
Virtualization (SR-IOV) and promiscuous mode were enabled on an interface
using igb, it could result in a denial of service when a tagged VLAN packet
is received on that interface. (CVE-2010-4263, Important)

* Missing initialization flaw in the XFS file system implementation, and in
the network traffic policing implementation, could allow a local,
unprivileged user to cause an information leak. (CVE-2010-3078,
CVE-2010-3477, Moderate)

* NULL pointer dereference in the Open Sound System compatible sequencer
driver could allow a local, unprivileged user with access to /dev/sequencer
to cause a denial of service. /dev/sequencer is only accessible to root and
users in the audio group by default. (CVE-2010-3080, Moderate)

* Flaw in the ethtool IOCTL handler could allow a local user to cause an
information leak. (CVE-2010-3861, Moderate)

* Flaw in bcm_connect() in the Controller Area Network (CAN) Broadcast
Manager. On 64-bit systems, writing the socket address may overflow the
procname character array. (CVE-2010-3874, Moderate)

* Flaw in the module for monitoring the sockets of INET transport
protocols could allow a local, unprivileged user to cause a denial of
service. (CVE-2010-3880, Moderate)

* Missing boundary checks in the block layer implementation could allow a
local, unprivileged user to cause a denial of service. (CVE-2010-4162,
CVE-2010-4163, CVE-2010-4668, Moderate)

* NULL pointer dereference in the Bluetooth HCI UART driver could allow a
local, unprivileged user to cause a denial of service. (CVE-2010-4242,
Moderate)

* Flaw in the Linux kernel CPU time clocks implementation for the POSIX
clock interface could allow a local, unprivileged user to cause a denial of
service. (CVE-2010-4248, Moderate)

* Flaw in the garbage collector for AF_UNIX sockets could allow a local,
unprivileged user to trigger a denial of service. (CVE-2010-4249, Moderate)

* Missing upper bound integer check in the AIO implementation could allow a
local, unprivileged user to cause an information leak. (CVE-2010-3067, Low)

* Missing initialization flaws could lead to information leaks.
(CVE-2010-3298, CVE-2010-3876, CVE-2010-4072, CVE-2010-4073, CVE-2010-4074,
CVE-2010-4075, CVE-2010-4077, CVE-2010-4079, CVE-2010-4080, CVE-2010-4081,
CVE-2010-4082, CVE-2010-4083, CVE-2010-4158, Low)

* Missing initialization flaw in KVM could allow a privileged host user
with access to /dev/kvm to cause an information leak. (CVE-2010-4525, Low)

Red Hat would like to thank Andre Osterhues for reporting CVE-2010-2492;
Thomas Pollet for reporting CVE-2010-3865; Dan Rosenberg for reporting
CVE-2010-4160, CVE-2010-3078, CVE-2010-3874, CVE-2010-4162, CVE-2010-4163,
CVE-2010-3298, CVE-2010-4073, CVE-2010-4074, CVE-2010-4075, CVE-2010-4077,
CVE-2010-4079, CVE-2010-4080, CVE-2010-4081, CVE-2010-4082, CVE-2010-4083,
and CVE-2010-4158; Kosuke Tatsukawa for reporting CVE-2010-4263; Tavis
Ormandy for reporting CVE-2010-3080 and CVE-2010-3067; Kees Cook for
reporting CVE-2010-3861 and CVE-2010-4072; Nelson Elhage for reporting
CVE-2010-3880; Alan Cox for reporting CVE-2010-4242; Vegard Nossum for
reporting CVE-2010-4249; Vasiliy Kulikov for reporting CVE-2010-3876; and
Stephan Mueller of atsec information security for reporting CVE-2010-4525.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3874</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3880</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4668</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110007"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110009" severity="medium">
    <xccdf:title>RHSA-2011:0009: evince security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evince is a document viewer.

An array index error was found in the DeVice Independent (DVI) renderer's
PK and VF font file parsers. A DVI file that references a specially-crafted
font file could, when opened, cause Evince to crash or, potentially,
execute arbitrary code with the privileges of the user running Evince.
(CVE-2010-2640, CVE-2010-2641)

A heap-based buffer overflow flaw was found in the DVI renderer's AFM font
file parser. A DVI file that references a specially-crafted font file
could, when opened, cause Evince to crash or, potentially, execute
arbitrary code with the privileges of the user running Evince.
(CVE-2010-2642)

An integer overflow flaw was found in the DVI renderer's TFM font file
parser. A DVI file that references a specially-crafted font file could,
when opened, cause Evince to crash or, potentially, execute arbitrary code
with the privileges of the user running Evince. (CVE-2010-2643)

Note: The above issues are not exploitable unless an attacker can trick the
user into installing a malicious font file.

Red Hat would like to thank the Evince development team for reporting these
issues.  Upstream acknowledges Jon Larimer of IBM X-Force as the original
reporter of these issues.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2641</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110009"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110013" severity="medium">
    <xccdf:title>RHSA-2011:0013: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

An array index error, leading to a stack-based buffer overflow, was found
in the Wireshark ENTTEC dissector. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2010-4538)

Users of Wireshark should upgrade to these updated packages, which contain
a backported patch to correct this issue. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4538</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110013"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110017" severity="high">
    <xccdf:title>RHSA-2011:0017: Red Hat Enterprise Linux 5.6 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the igb driver in the Linux
kernel. If both the Single Root I/O Virtualization (SR-IOV) feature and
promiscuous mode were enabled on an interface using igb, it could result in
a denial of service when a tagged VLAN packet is received on that
interface. (CVE-2010-4263, Important)

* A missing sanity check was found in vbd_create() in the Xen hypervisor
implementation. As CD-ROM drives are not supported by the blkback back-end
driver, attempting to use a virtual CD-ROM drive with blkback could trigger
a denial of service (crash) on the host system running the Xen hypervisor.
(CVE-2010-4238, Moderate)

* A flaw was found in the Linux kernel execve() system call implementation.
A local, unprivileged user could cause large amounts of memory to be
allocated but not visible to the OOM (Out of Memory) killer, triggering a
denial of service. (CVE-2010-4243, Moderate)

* A flaw was found in fixup_page_fault() in the Xen hypervisor
implementation. If a 64-bit para-virtualized guest accessed a certain area
of memory, it could cause a denial of service on the host system running
the Xen hypervisor. (CVE-2010-4255, Moderate)

* A missing initialization flaw was found in the bfa driver used by Brocade
Fibre Channel Host Bus Adapters. A local, unprivileged user could use this
flaw to cause a denial of service by reading a file in the
"/sys/class/fc_host/host#/statistics/" directory. (CVE-2010-4343, Moderate)

* Missing initialization flaws in the Linux kernel could lead to
information leaks. (CVE-2010-3296, CVE-2010-3877, CVE-2010-4072,
CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4158,
Low)

Red Hat would like to thank Kosuke Tatsukawa for reporting CVE-2010-4263;
Vladymyr Denysov for reporting CVE-2010-4238; Brad Spengler for reporting
CVE-2010-4243; Dan Rosenberg for reporting CVE-2010-3296, CVE-2010-4073,
CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, and CVE-2010-4158; Vasiliy
Kulikov for reporting CVE-2010-3877; and Kees Cook for reporting
CVE-2010-4072.

These updated packages also include several hundred bug fixes for and
enhancements to the Linux kernel. Space precludes documenting each of these
changes in this advisory and users are directed to the Red Hat Enterprise
Linux 5.6 Release Notes for information on the most significant of these
changes:

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.6_Release_Notes/index.html

Refer to the kernel chapter in the Red Hat Enterprise Linux 5.6 Technical
Notes for further information:

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.6_Technical_Notes/kernel.html

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which address these vulnerabilities as well as fixing the bugs
and adding the enhancements noted in the Red Hat Enterprise Linux 5.6
Release Notes and Technical Notes. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3877</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4343</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110017"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110025" severity="low">
    <xccdf:title>RHSA-2011:0025: gcc security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gcc packages include C, C++, Java, Fortran, Objective C, and Ada 95 GNU
compilers, along with related support libraries. The libgcj package
provides fastjar, an archive tool for Java Archive (JAR) files.

Two directory traversal flaws were found in the way fastjar extracted JAR
archive files. If a local, unsuspecting user extracted a specially-crafted
JAR file, it could cause fastjar to overwrite arbitrary files writable by
the user running fastjar. (CVE-2010-0831, CVE-2010-2322)

This update also fixes the following bugs:

* The option -print-multi-os-directory in the gcc --help output is not in
the gcc(1) man page. This update applies an upstream patch to amend this.
(BZ#529659)

* An internal assertion in the compiler tried to check that a C++ static
data member is external which resulted in errors. This was because when the
compiler optimizes C++ anonymous namespaces the declarations were no longer
marked external as everything on anonymous namespaces is local to the
current translation. This update corrects the assertion to resolve this
issue. (BZ#503565, BZ#508735, BZ#582682)

* Attempting to compile certain .cpp files could have resulted in an
internal compiler error. This update resolves this issue. (BZ#527510)

* PrintServiceLookup.lookupPrintServices with an appropriate DocFlavor
failed to return a list of printers under gcj. This update includes a
backported patch to correct this bug in the printer lookup service.
(BZ#578382)

* GCC would not build against xulrunner-devel-1.9.2. This update removes
gcjwebplugin from the GCC RPM. (BZ#596097)

* When a SystemTap generated kernel module was compiled, gcc reported an
internal compiler error and gets a segmentation fault. This update applies
a patch that, instead of crashing, assumes it can point to anything.
(BZ#605803)

* There was a performance issue with libstdc++ regarding all objects
derived from or using std::streambuf because of lock contention between
threads. This patch ensures reload uses the same value from _S_global for
the comparison, _M_add_reference () and _M_impl member of the class.
(BZ#635708)

All gcc users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110025"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110027" severity="low">
    <xccdf:title>RHSA-2011:0027: python security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

It was found that many applications embedding the Python interpreter did
not specify a valid full path to the script or application when calling the
PySys_SetArgv API function, which could result in the addition of the
current working directory to the module search path (sys.path). A local
attacker able to trick a victim into running such an application in an
attacker-controlled directory could use this flaw to execute code with the
victim's privileges. This update adds the PySys_SetArgvEx API. Developers
can modify their applications to use this new API, which sets sys.argv
without modifying sys.path. (CVE-2008-5983)

Multiple flaws were found in the Python rgbimg module. If an application
written in Python was using the rgbimg module and loaded a
specially-crafted SGI image file, it could cause the application to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2009-4134, CVE-2010-1449, CVE-2010-1450)

Multiple flaws were found in the Python audioop module. Supplying certain
inputs could cause the audioop module to crash or, possibly, execute
arbitrary code. (CVE-2010-1634, CVE-2010-2089)

This update also fixes the following bugs:

* When starting a child process from the subprocess module in Python 2.4,
the parent process could leak file descriptors if an error occurred. This
update resolves the issue. (BZ#609017)

* Prior to Python 2.7, programs that used "ulimit -n" to enable
communication with large numbers of subprocesses could still monitor only
1024 file descriptors at a time, which caused an exception:

  ValueError: filedescriptor out of range in select()

This was due to the subprocess module using the "select" system call. The
module now uses the "poll" system call, removing this limitation.
(BZ#609020)

* Prior to Python 2.5, the tarfile module failed to unpack tar files if the
path was longer than 100 characters. This update backports the tarfile
module from Python 2.5 and the issue no longer occurs. (BZ#263401)

* The email module incorrectly implemented the logic for obtaining
attachment file names: the get_filename() fallback for using the deprecated
"name" parameter of the "Content-Type" header erroneously used the
"Content-Disposition" header. This update backports a fix from Python 2.6,
which resolves this issue. (BZ#644147)

* Prior to version 2.5, Python's optimized memory allocator never released
memory back to the system. The memory usage of a long-running Python
process would resemble a "high-water mark". This update backports a fix
from Python 2.5a1, which frees unused arenas, and adds a non-standard
sys._debugmallocstats() function, which prints diagnostic information to
stderr. Finally, when running under Valgrind, the optimized allocator is
deactivated, to allow more convenient debugging of Python memory usage
issues. (BZ#569093)

* The urllib and urllib2 modules ignored the no_proxy variable, which could
lead to programs such as "yum" erroneously accessing a proxy server for
URLs covered by a "no_proxy" exclusion. This update backports fixes of
urllib and urllib2, which respect the "no_proxy" variable, which fixes
these issues. (BZ#549372)

As well, this update adds the following enhancements:

* This update introduces a new python-libs package, subsuming the majority
of the content of the core python package. This makes both 32-bit and
64-bit Python libraries available on PowerPC systems. (BZ#625372)

* The python-libs.i386 package is now available for 64-bit Itanium with the
32-bit Itanium compatibility mode. (BZ#644761)

All Python users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2089</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110027"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110028" severity="low">
    <xccdf:title>RHSA-2011:0028: kvm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A data structure field in kvm_vcpu_ioctl_x86_get_vcpu_events() in QEMU-KVM
was not initialized properly before being copied to user-space. A
privileged host user with access to "/dev/kvm" could use this flaw to leak
kernel stack memory to user-space. (CVE-2010-4525)

Red Hat would like to thank Stephan Mueller of atsec information security
for reporting this issue.

These updated packages also fix several bugs. Documentation for these bug
fixes will be available shortly in the "kvm" section of the Red Hat
Enterprise Linux 5.6 Technical Notes, linked to in the References.

All KVM users should upgrade to these updated packages, which resolve this
issue as well as fixing the bugs noted in the Technical Notes. Note: The
procedure in the Solution section must be performed before this update will
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4525</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110028"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110153" severity="medium">
    <xccdf:title>RHSA-2011:0153: exim security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on UNIX systems connected to the Internet.

A privilege escalation flaw was discovered in Exim. If an attacker were
able to gain access to the "exim" user, they could cause Exim to execute
arbitrary commands as the root user. (CVE-2010-4345)

This update adds a new configuration file, "/etc/exim/trusted-configs". To
prevent Exim from running arbitrary commands as root, Exim will now drop
privileges when run with a configuration file not listed as trusted. This
could break backwards compatibility with some Exim configurations, as the
trusted-configs file only trusts "/etc/exim/exim.conf" and
"/etc/exim/exim4.conf" by default. If you are using a configuration file
not listed in the new trusted-configs file, you will need to add it
manually.

Additionally, Exim will no longer allow a user to execute exim as root with
the -D command line option to override macro definitions. All macro
definitions that require root permissions must now reside in a trusted
configuration file.

Users of Exim are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the exim daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4345</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110153"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110154" severity="medium">
    <xccdf:title>RHSA-2011:0154: hplip security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Hewlett-Packard Linux Imaging and Printing (HPLIP) provides drivers for
Hewlett-Packard printers and multifunction peripherals, and tools for
installing, using, and configuring them.

A flaw was found in the way certain HPLIP tools discovered devices using
the SNMP protocol. If a user ran certain HPLIP tools that search for
supported devices using SNMP, and a malicious user is able to send
specially-crafted SNMP responses, it could cause those HPLIP tools to crash
or, possibly, execute arbitrary code with the privileges of the user
running them. (CVE-2010-4267)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

Users of hplip should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4267</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110162" severity="high">
    <xccdf:title>RHSA-2011:0162: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A heap overflow flaw was found in the Linux kernel's Transparent
Inter-Process Communication protocol (TIPC) implementation. A local,
unprivileged user could use this flaw to escalate their privileges.
(CVE-2010-3859, Important)

* Missing sanity checks were found in gdth_ioctl_alloc() in the gdth driver
in the Linux kernel. A local user with access to "/dev/gdth" on a 64-bit
system could use these flaws to cause a denial of service or escalate their
privileges. (CVE-2010-4157, Moderate)

* A NULL pointer dereference flaw was found in the Bluetooth HCI UART
driver in the Linux kernel. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4242, Moderate)

* A flaw was found in the Linux kernel's garbage collector for AF_UNIX
sockets. A local, unprivileged user could use this flaw to trigger a
denial of service (out-of-memory condition). (CVE-2010-4249, Moderate)

* Missing initialization flaws were found in the Linux kernel. A local,
unprivileged user could use these flaws to cause information leaks.
(CVE-2010-3876, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080,
CVE-2010-4083, CVE-2010-4158, Low)

Red Hat would like to thank Alan Cox for reporting CVE-2010-4242; Vegard
Nossum for reporting CVE-2010-4249; Vasiliy Kulikov for reporting
CVE-2010-3876; Kees Cook for reporting CVE-2010-4072; and Dan Rosenberg for
reporting CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4083, and
CVE-2010-4158.

This update also fixes the following bugs:

* A flaw was found in the Linux kernel where, if used in conjunction with
another flaw that can result in a kernel Oops, could possibly lead to
privilege escalation. It does not affect Red Hat Enterprise Linux 4 as the
sysctl panic_on_oops variable is turned on by default. However, as a
preventive measure if the variable is turned off by an administrator, this
update addresses the issue. Red Hat would like to thank Nelson Elhage for
reporting this vulnerability. (BZ#659568)

* On Intel I/O Controller Hub 9 (ICH9) hardware, jumbo frame support is
achieved by using page-based sk_buff buffers without any packet split. The
entire frame data is copied to the page(s) rather than some to the
skb-&gt;data area and some to the page(s) when performing a typical
packet-split. This caused problems with the filtering code and frames were
getting dropped before they were received by listening applications. This
bug could eventually lead to the IP address being released and not being
able to be re-acquired from DHCP if the MTU (Maximum Transfer Unit) was
changed (for an affected interface using the e1000e driver). With this
update, frames are no longer dropped and an IP address is correctly
re-acquired after a previous release. (BZ#664667)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3859</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4249</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110162"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110163" severity="high">
    <xccdf:title>RHSA-2011:0163: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the sctp_icmp_proto_unreachable() function in the
Linux kernel's Stream Control Transmission Protocol (SCTP) implementation.
A remote attacker could use this flaw to cause a denial of service.
(CVE-2010-4526, Important)

This update also fixes the following bugs:

* Due to an off-by-one error, gfs2_grow failed to take the very last "rgrp"
parameter into account when adding up the new free space. With this update,
the GFS2 kernel properly counts all the new resource groups and fixes the
"statfs" file correctly. (BZ#666792)

* Prior to this update, a multi-threaded application, which invoked
popen(3) internally, could cause a thread stall by FILE lock corruption.
The application program waited for a FILE lock in glibc, but the lock
seemed to be corrupted, which was caused by a race condition in the COW (Copy On Write) logic. With this update, the race condition was corrected and FILE lock corruption no longer occurs. (BZ#667050)

* If an error occurred during I/O, the SCSI driver reset the "megaraid_sas"
controller to restore it to normal state. However, on Red Hat Enterprise
Linux 5, the waiting time to allow a full reset completion for the
"megaraid_sas" controller was too short. The driver incorrectly recognized
the controller as stalled, and, as a result, the system stalled as well.
With this update, more time is given to the controller to properly restart,
thus, the controller operates as expected after being reset. (BZ#667141)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4526</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110164" severity="medium">
    <xccdf:title>RHSA-2011:0164: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

The MySQL PolyFromWKB() function did not sanity check Well-Known Binary
(WKB) data, which could allow a remote, authenticated attacker to crash
mysqld. (CVE-2010-3840)

A flaw in the way MySQL processed certain JOIN queries could allow a
remote, authenticated attacker to cause excessive CPU use (up to 100%), if
a stored procedure contained JOIN queries, and that procedure was executed
twice in sequence. (CVE-2010-3839)

A flaw in the way MySQL processed queries that provide a mixture of numeric
and longblob data types to the LEAST or GREATEST function, could allow a
remote, authenticated attacker to crash mysqld. (CVE-2010-3838)

A flaw in the way MySQL processed PREPARE statements containing both
GROUP_CONCAT and the WITH ROLLUP modifier could allow a remote,
authenticated attacker to crash mysqld. (CVE-2010-3837)

MySQL did not properly pre-evaluate LIKE arguments in view prepare mode,
possibly allowing a remote, authenticated attacker to crash mysqld.
(CVE-2010-3836)

A flaw in the way MySQL processed statements that assign a value to a
user-defined variable and that also contain a logical value evaluation
could allow a remote, authenticated attacker to crash mysqld.
(CVE-2010-3835)

A flaw in the way MySQL evaluated the arguments of extreme-value functions,
such as LEAST and GREATEST, could allow a remote, authenticated attacker to
crash mysqld. (CVE-2010-3833)

A flaw in the way MySQL handled LOAD DATA INFILE requests allowed MySQL to
send OK packets even when there were errors. (CVE-2010-3683)

A flaw in the way MySQL processed EXPLAIN statements for some complex
SELECT queries could allow a remote, authenticated attacker to crash
mysqld. (CVE-2010-3682)

A flaw in the way MySQL processed certain alternating READ requests
provided by HANDLER statements could allow a remote, authenticated attacker
to crash mysqld. (CVE-2010-3681)

A flaw in the way MySQL processed CREATE TEMPORARY TABLE statements that
define NULL columns when using the InnoDB storage engine, could allow a
remote, authenticated attacker to crash mysqld. (CVE-2010-3680)

A flaw in the way MySQL processed certain values provided to the BINLOG
statement caused MySQL to read unassigned memory. A remote, authenticated
attacker could possibly use this flaw to crash mysqld. (CVE-2010-3679)

A flaw in the way MySQL processed SQL queries containing IN or CASE
statements, when a NULL argument was provided as one of the arguments to
the query, could allow a remote, authenticated attacker to crash mysqld.
(CVE-2010-3678)

A flaw in the way MySQL processed JOIN queries that attempt to retrieve
data from a unique SET column could allow a remote, authenticated attacker
to crash mysqld. (CVE-2010-3677)

Note: CVE-2010-3840, CVE-2010-3838, CVE-2010-3837, CVE-2010-3835,
CVE-2010-3833, CVE-2010-3682, CVE-2010-3681, CVE-2010-3680, CVE-2010-3678,
and CVE-2010-3677 only cause a temporary denial of service, as mysqld was
automatically restarted after each crash.

These updated packages upgrade MySQL to version 5.1.52. Refer to the MySQL
release notes for a full list of changes:

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-52.html

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3681</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3840</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110170" severity="medium">
    <xccdf:title>RHSA-2011:0170: libuser security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libuser library implements a standardized interface for manipulating
and administering user and group accounts. Sample applications that are
modeled after applications from the shadow password suite (shadow-utils)
are included in these packages.

It was discovered that libuser did not set the password entry correctly
when creating LDAP (Lightweight Directory Access Protocol) users. If an
administrator did not assign a password to an LDAP based user account,
either at account creation with luseradd, or with lpasswd after account
creation, an attacker could use this flaw to log into that account with a
default password string that should have been rejected. (CVE-2011-0002)

Note: LDAP administrators that have used libuser tools to add users should
check existing user accounts for plain text passwords, and reset them as
necessary.

Users of libuser should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0002</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110170"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110176" severity="medium">
    <xccdf:title>RHSA-2011:0176: java-1.6.0-openjdk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The javaws command can be used to
launch Java Web Start applications.

A public static field declaration allowed untrusted JNLP (Java Network
Launching Protocol) applications to read privileged data. A remote attacker
could directly or indirectly read the values of restricted system
properties, such as "user.name", "user.home", and "java.home", which
untrusted applications should not be allowed to read. (CVE-2010-3860)

It was found that JNLPSecurityManager could silently return without
throwing an exception when permission was denied. If the javaws command was
used to launch a Java Web Start application that relies on this exception
being thrown, it could result in that application being run with elevated
privileges, allowing it to bypass security manager restrictions and gain
access to privileged functionality. (CVE-2010-4351)

Note: The RHSA-2010:0339 java-1.6.0-openjdk update installed javaws by
mistake. As part of the fixes for CVE-2010-3860 and CVE-2010-4351, this
update removes javaws.

Red Hat would like to thank the TippingPoint Zero Day Initiative project
for reporting CVE-2010-4351. The original issue reporter wishes to stay
anonymous.

This erratum also upgrades the OpenJDK package to IcedTea6 1.7.7. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4351</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110176"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110177" severity="medium">
    <xccdf:title>RHSA-2011:0177: webkitgtk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>WebKitGTK+ is the port of the portable web rendering engine WebKit to the
GTK+ platform.

Multiple memory corruption flaws were found in WebKit. Malicious web
content could cause an application using WebKitGTK+ to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2010-1782, CVE-2010-1783, CVE-2010-1784,
CVE-2010-1785, CVE-2010-1787, CVE-2010-1788, CVE-2010-1790, CVE-2010-1792,
CVE-2010-1807, CVE-2010-1814, CVE-2010-3114, CVE-2010-3116, CVE-2010-3119,
CVE-2010-3255, CVE-2010-3812, CVE-2010-4198)

Multiple use-after-free flaws were found in WebKit. Malicious web content
could cause an application using WebKitGTK+ to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2010-1780, CVE-2010-1786, CVE-2010-1793, CVE-2010-1812,
CVE-2010-1815, CVE-2010-3113, CVE-2010-3257, CVE-2010-4197, CVE-2010-4204)

Two array index errors, leading to out-of-bounds memory reads, were found
in WebKit. Malicious web content could cause an application using
WebKitGTK+ to crash. (CVE-2010-4206, CVE-2010-4577)

A flaw in WebKit could allow malicious web content to trick a user into
thinking they are visiting the site reported by the location bar, when the
page is actually content controlled by an attacker. (CVE-2010-3115)

It was found that WebKit did not correctly restrict read access to images
created from the "canvas" element. Malicious web content could allow a
remote attacker to bypass the same-origin policy and potentially access
sensitive image data. (CVE-2010-3259)

A flaw was found in the way WebKit handled DNS prefetching. Even when it
was disabled, web content containing certain "link" elements could cause
WebKitGTK+ to perform DNS prefetching. (CVE-2010-3813)

Users of WebKitGTK+ should upgrade to these updated packages, which contain
WebKitGTK+ version 1.2.6, and resolve these issues. All running
applications that use WebKitGTK+ must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1785</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1792</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3119</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3259</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4577</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110177"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110180" severity="medium">
    <xccdf:title>RHSA-2011:0180: pango security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

An input sanitization flaw, leading to a heap-based buffer overflow, was
found in the way Pango displayed font files when using the FreeType font
engine back end. If a user loaded a malformed font file with an application
that uses Pango, it could cause the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0020)

Users of pango and evolution28-pango are advised to upgrade to these
updated packages, which contain a backported patch to resolve this issue.
After installing the updated packages, you must restart your system or
restart your X session for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0020</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110181" severity="high">
    <xccdf:title>RHSA-2011:0181: openoffice.org and openoffice.org2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled
the installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues.
Upstream acknowledges Dan Rosenberg of Virtual Security Research as the
original reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110181"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110182" severity="high">
    <xccdf:title>RHSA-2011:0182: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain Microsoft Office PowerPoint files. An attacker could use
this flaw to create a specially-crafted Microsoft Office PowerPoint file
that, when opened, would cause OpenOffice.org to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org. (CVE-2010-4253)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled the
installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

A flaw was found in the script that launches OpenOffice.org. In some
situations, a "." character could be included in the LD_LIBRARY_PATH
variable, allowing a local attacker to execute arbitrary code with the
privileges of the user running OpenOffice.org, if that user ran
OpenOffice.org from within an attacker-controlled directory.
(CVE-2010-3689)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues; and
Dmitri Gribenko for reporting the CVE-2010-3689 issue. Upstream
acknowledges Dan Rosenberg of Virtual Security Research as the original
reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4253</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110182"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110183" severity="high">
    <xccdf:title>RHSA-2011:0183: openoffice.org security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain Microsoft Office PowerPoint files. An attacker could use
this flaw to create a specially-crafted Microsoft Office PowerPoint file
that, when opened, would cause OpenOffice.org to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org. (CVE-2010-4253)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled the
installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

A flaw was found in the script that launches OpenOffice.org. In some
situations, a "." character could be included in the LD_LIBRARY_PATH
variable, allowing a local attacker to execute arbitrary code with the
privileges of the user running OpenOffice.org, if that user ran
OpenOffice.org from within an attacker-controlled directory.
(CVE-2010-3689)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues; and
Dmitri Gribenko for reporting the CVE-2010-3689 issue. Upstream
acknowledges Dan Rosenberg of Virtual Security Research as the original
reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

This update also fixes the following bug:

* OpenOffice.org did not create a lock file when opening a file that was on
a share mounted via SFTP. Additionally, if there was a lock file, it was
ignored. This could result in data loss if a file in this situation was
opened simultaneously by another user. (BZ#671087)

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4253</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110183"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110195" severity="medium">
    <xccdf:title>RHSA-2011:0195: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way PHP converted certain floating point values
from string representation to a number. If a PHP script evaluated an
attacker's input in a numeric context, the PHP interpreter could cause high
CPU usage until the script execution time limit is reached. This issue only
affected i386 systems. (CVE-2010-4645)

A numeric truncation error and an input validation flaw were found in the
way the PHP utf8_decode() function decoded partial multi-byte sequences
for some multi-byte encodings, sending them to output without them being
escaped. An attacker could use these flaws to perform a cross-site
scripting attack. (CVE-2009-5016, CVE-2010-3870)

A NULL pointer dereference flaw was found in the PHP
ZipArchive::getArchiveComment function. If a script used this function to
inspect a specially-crafted ZIP archive file, it could cause the PHP
interpreter to crash. (CVE-2010-3709)

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4645</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110195"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110196" severity="medium">
    <xccdf:title>RHSA-2011:0196: php53 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way PHP converted certain floating point values
from string representation to a number. If a PHP script evaluated an
attacker's input in a numeric context, the PHP interpreter could cause high
CPU usage until the script execution time limit is reached. This issue only
affected i386 systems. (CVE-2010-4645)

A stack memory exhaustion flaw was found in the way the PHP filter_var()
function validated email addresses. An attacker could use this flaw to
crash the PHP interpreter by providing excessively long input to be
validated as an email address. (CVE-2010-3710)

A memory disclosure flaw was found in the PHP multi-byte string extension.
If the mb_strcut() function was called with a length argument exceeding the
input string size, the function could disclose a portion of the PHP
interpreter's memory. (CVE-2010-4156)

All php53 users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4156</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4645</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110196"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110197" severity="medium">
    <xccdf:title>RHSA-2011:0197: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A stack-based buffer overflow flaw was found in the way PostgreSQL
processed certain tokens from an SQL query when the intarray module was
enabled on a particular database. An authenticated database user running a
specially-crafted SQL query could use this flaw to cause a temporary denial
of service (postgres daemon crash) or, potentially, execute arbitrary code
with the privileges of the database server. (CVE-2010-4015)

Red Hat would like to thank Geoff Keating of the Apple Product Security
team for reporting this issue.

For Red Hat Enterprise Linux 4, the updated postgresql packages contain a
backported patch for this issue; there are no other changes.

For Red Hat Enterprise Linux 5, the updated postgresql packages upgrade
PostgreSQL to version 8.1.23, and contain a backported patch for this
issue. Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.1/static/release.html

For Red Hat Enterprise Linux 6, the updated postgresql packages upgrade
PostgreSQL to version 8.4.7, which includes a fix for this issue. Refer to
the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110198" severity="medium">
    <xccdf:title>RHSA-2011:0198: postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A stack-based buffer overflow flaw was found in the way PostgreSQL
processed certain tokens from an SQL query when the intarray module was
enabled on a particular database. An authenticated database user running a
specially-crafted SQL query could use this flaw to cause a temporary denial
of service (postgres daemon crash) or, potentially, execute arbitrary code
with the privileges of the database server. (CVE-2010-4015)

Red Hat would like to thank Geoff Keating of the Apple Product Security
team for reporting this issue.

These updated postgresql84 packages upgrade PostgreSQL to version 8.4.7.
Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110198"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110199" severity="high">
    <xccdf:title>RHSA-2011:0199: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed principal names that were not null terminated, when the KDC was
configured to use an LDAP back end. A remote attacker could use this flaw
to crash the KDC via a specially-crafted request. (CVE-2011-0282)

A denial of service flaw was found in the way the MIT Kerberos KDC
processed certain principal names when the KDC was configured to use an
LDAP back end. A remote attacker could use this flaw to cause the KDC to
hang via a specially-crafted request. (CVE-2011-0281)

Red Hat would like to thank the MIT Kerberos Team for reporting these
issues. Upstream acknowledges Kevin Longfellow of Oracle Corporation as the
original reporter of the CVE-2011-0281 issue.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110199"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110200" severity="high">
    <xccdf:title>RHSA-2011:0200: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed principal names that were not null terminated, when the KDC was
configured to use an LDAP back end. A remote attacker could use this flaw
to crash the KDC via a specially-crafted request. (CVE-2011-0282)

A denial of service flaw was found in the way the MIT Kerberos KDC
processed certain principal names when the KDC was configured to use an
LDAP back end. A remote attacker could use this flaw to cause the KDC to
hang via a specially-crafted request. (CVE-2011-0281)

A denial of service flaw was found in the way the MIT Kerberos V5 slave KDC
update server (kpropd) processed certain update requests for KDC database
propagation. A remote attacker could use this flaw to terminate the kpropd
daemon via a specially-crafted update request. (CVE-2010-4022)

Red Hat would like to thank the MIT Kerberos Team for reporting the
CVE-2011-0282 and CVE-2011-0281 issues. Upstream acknowledges Kevin
Longfellow of Oracle Corporation as the original reporter of the
CVE-2011-0281 issue.

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0200</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110200"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110214" severity="medium">
    <xccdf:title>RHSA-2011:0214: java-1.6.0-openjdk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Java-based applications to hang, for instance if they parse Double values
in a specially-crafted HTTP request. (CVE-2010-4476)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve this issue. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4476</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110214"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110219" severity="low">
    <xccdf:title>RHSA-2011:0219: Red Hat Enterprise Linux 4 - 1-Year End Of Life Notice (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0219</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110219"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110256" severity="medium">
    <xccdf:title>RHSA-2011:0256: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. DHCPv6 is the DHCP protocol version for IPv6 networks.

A flaw was found in the way the dhcpd daemon processed certain DHCPv6
messages for addresses that had previously been declined and marked as
abandoned internally. If a remote attacker sent such messages to dhcpd, it
could cause dhcpd to crash due to an assertion failure if it was running as
a DHCPv6 server. (CVE-2011-0413)

Red Hat would like to thank Internet Systems Consortium for reporting this
issue.

Users running dhcpd as a DHCPv6 server should upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0256</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0413</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110256"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110257" severity="medium">
    <xccdf:title>RHSA-2011:0257: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.

A server-side memory leak was found in the Subversion server. If a
malicious, remote user performed "svn blame" or "svn log" operations on
certain repository files, it could cause the Subversion server to consume
a large amount of system memory. (CVE-2010-4644)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
(for use with the Apache HTTP Server) processed certain requests. If a
malicious, remote user issued a certain type of request to display a
collection of Subversion repositories on a host that has the
SVNListParentPath directive enabled, it could cause the httpd process
serving the request to crash. Note that SVNListParentPath is not enabled by
default. (CVE-2010-4539)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0257</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4539</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4644</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110257"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110258" severity="medium">
    <xccdf:title>RHSA-2011:0258: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

An access restriction bypass flaw was found in the mod_dav_svn module. If
the SVNPathAuthz directive was set to "short_circuit", certain access rules
were not enforced, possibly allowing sensitive repository data to be leaked
to remote users. Note that SVNPathAuthz is set to "On" by default.
(CVE-2010-3315)

A server-side memory leak was found in the Subversion server. If a
malicious, remote user performed "svn blame" or "svn log" operations on
certain repository files, it could cause the Subversion server to consume
a large amount of system memory. (CVE-2010-4644)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests. If a malicious, remote user issued a certain
type of request to display a collection of Subversion repositories on a
host that has the SVNListParentPath directive enabled, it could cause the
httpd process serving the request to crash. Note that SVNListParentPath is
not enabled by default. (CVE-2010-4539)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3315</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4539</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4644</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110258"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110260" severity="low">
    <xccdf:title>RHSA-2011:0260: python security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

Multiple flaws were found in the Python rgbimg module. If an application
written in Python was using the rgbimg module and loaded a
specially-crafted SGI image file, it could cause the application to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2009-4134, CVE-2010-1449, CVE-2010-1450)

This update also fixes the following bugs:

* Python 2.3.4's time.strptime() function did not correctly handle the "%W"
week number format string. This update backports the _strptime
implementation from Python 2.3.6, fixing this issue. (BZ#436001)

* Python 2.3.4's socket.htons() function returned partially-uninitialized
data on IBM System z, generally leading to incorrect results. (BZ#513341)

* Python 2.3.4's pwd.getpwuid() and grp.getgrgid() functions did not
support the full range of user and group IDs on 64-bit architectures,
leading to "OverflowError" exceptions for large input values. This update
adds support for the full range of user and group IDs on 64-bit
architectures. (BZ#497540)

Users of Python should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1450</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110260"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110261" severity="low">
    <xccdf:title>RHSA-2011:0261: bash security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Bash (Bourne-again shell) is the default shell for Red Hat Enterprise
Linux.

It was found that certain scripts bundled with the Bash documentation
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files accessible to the victim running the
scripts. (CVE-2008-5374)

This update also fixes the following bugs:

* If a child process's PID was the same as the PID of a previously ended
child process, Bash did not wait for that child process. In some cases this
caused "Resource temporarily unavailable" errors. With this update, Bash
recycles PIDs and waits for processes with recycled PIDs. (BZ#521134)

* Bash's built-in "read" command had a memory leak when "read" failed due
to no input (pipe for stdin). With this update, the memory is correctly
freed. (BZ#537029)

* Bash did not correctly check for a valid multi-byte string when setting
the IFS value, causing Bash to crash. With this update, Bash checks the
multi-byte string and no longer crashes. (BZ#539536)

* Bash incorrectly set locale settings when using the built-in "export"
command and setting the locale on the same line (for example, with
"LC_ALL=C export LC_ALL"). With this update, Bash correctly sets locale
settings. (BZ#539538)

All bash users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0261</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110261"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110262" severity="low">
    <xccdf:title>RHSA-2011:0262: sendmail security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sendmail is a Mail Transport Agent (MTA) used to send mail between
machines.

A flaw was found in the way sendmail handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick sendmail into accepting it by mistake, allowing the attacker to
perform a man-in-the-middle attack or bypass intended client certificate
authentication. (CVE-2009-4565) 

The CVE-2009-4565 issue only affected configurations using TLS with
certificate verification and CommonName checking enabled, which is not a
typical configuration.

This update also fixes the following bugs:

* Previously, sendmail did not correctly handle mail messages that had a
long first header line. A line with more than 2048 characters was split,
causing the part of the line exceeding the limit, as well as all of the
following mail headers, to be incorrectly handled as the message body.
(BZ#499450)

* When an SMTP-sender is sending mail data to sendmail, it may spool that
data to a file in the mail queue. It was found that, if the SMTP-sender
stopped sending data and a timeout occurred, the file may have been left
stalled in the mail queue, instead of being deleted. This update may not
correct this issue for every situation and configuration. Refer to the
Solution section for further information. (BZ#434645)

* Previously, the sendmail macro MAXHOSTNAMELEN used 64 characters as the
limit for the hostname length. However, in some cases, it was used against
an FQDN length, which has a maximum length of 255 characters. With this
update, the MAXHOSTNAMELEN limit has been changed to 255. (BZ#485380)

All sendmail users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
sendmail will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4565</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110262"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110263" severity="high">
    <xccdf:title>RHSA-2011:0263: Red Hat Enterprise Linux 4.9 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the load_mixer_volumes() function in
the Linux kernel's Open Sound System (OSS) sound driver. On 64-bit PowerPC
systems, a local, unprivileged user could use this flaw to cause a denial
of service or escalate their privileges. (CVE-2010-4527, Important)

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-4527, and
Kees Cook for reporting CVE-2010-4655.

These updated kernel packages also fix hundreds of bugs and add numerous
enhancements. For details on individual bug fixes and enhancements included
in this update, refer to the Red Hat Enterprise Linux 4.9 Release Notes,
linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add these enhancements. The system must
be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110263"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110281" severity="high">
    <xccdf:title>RHSA-2011:0281: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A flaw was found in the Swing library. Forged TimerEvents could be used to
bypass SecurityManager checks, allowing access to otherwise blocked files
and directories. (CVE-2010-4465)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), which could lead to heap corruption. (CVE-2010-4469)

A flaw was found in the way JAXP (Java API for XML Processing) components
were handled, allowing them to be manipulated by untrusted applets. This
could be used to elevate privileges and bypass secure XML processing
restrictions. (CVE-2010-4470)

It was found that untrusted applets could create and place cache entries in
the name resolution cache. This could allow an attacker targeted
manipulation over name resolution until the OpenJDK VM is restarted.
(CVE-2010-4448)

It was found that the Java launcher provided by OpenJDK did not check the
LD_LIBRARY_PATH environment variable for insecure empty path elements. A
local attacker able to trick a user into running the Java launcher while
working from an attacker-writable directory could use this flaw to load an
untrusted library, subverting the Java security model. (CVE-2010-4450)

A flaw was found in the XML Digital Signature component in OpenJDK.
Untrusted code could use this flaw to replace the Java Runtime Environment
(JRE) XML Digital Signature Transform or C14N algorithm implementations to
intercept digital signature operations. (CVE-2010-4472)

Note: All of the above flaws can only be remotely triggered in OpenJDK by
calling the "appletviewer" application.

This update also provides one defense in depth patch. (BZ#676019)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4472</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110281"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110283" severity="medium">
    <xccdf:title>RHSA-2011:0283: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A divide-by-zero flaw was found in the tcp_select_initial_window()
function in the Linux kernel's TCP/IP protocol suite implementation. A
local, unprivileged user could use this flaw to trigger a denial of service
by calling setsockopt() with certain options. (CVE-2010-4165, Moderate)

* A use-after-free flaw in the mprotect() system call in the Linux kernel
could allow a local, unprivileged user to cause a local denial of service.
(CVE-2010-4169, Moderate)

* A flaw was found in the Linux kernel execve() system call implementation.
A local, unprivileged user could cause large amounts of memory to be
allocated but not visible to the OOM (Out of Memory) killer, triggering a
denial of service. (CVE-2010-4243, Moderate)

Red Hat would like to thank Steve Chen for reporting CVE-2010-4165, and
Brad Spengler for reporting CVE-2010-4243.

This update also fixes several bugs and adds two enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document linked to in the References
section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancements
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4243</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110283"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110303" severity="medium">
    <xccdf:title>RHSA-2011:0303: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the Linux kernel's garbage collector for AF_UNIX
sockets. A local, unprivileged user could use this flaw to trigger a
denial of service (out-of-memory condition). (CVE-2010-4249, Moderate)

* A flaw was found in the Linux kernel's networking subsystem. If the
number of packets received exceeded the receiver's buffer limit, they were
queued in a backlog, consuming memory, instead of being discarded. A remote
attacker could abuse this flaw to cause a denial of service (out-of-memory
condition). (CVE-2010-4251, Moderate)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

Red Hat would like to thank Vegard Nossum for reporting CVE-2010-4249, and
Kees Cook for reporting CVE-2010-4655.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4251</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4805</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110303"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110305" severity="high">
    <xccdf:title>RHSA-2011:0305: samba security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A flaw was found in the way Samba handled file descriptors. If an attacker
were able to open a large number of file descriptors on the Samba server,
they could flip certain stack bits to "1" values, resulting in the Samba
server (smbd) crashing. (CVE-2011-0719)

Red Hat would like to thank the Samba team for reporting this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0719</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110305"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110306" severity="high">
    <xccdf:title>RHSA-2011:0306: samba3x security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A flaw was found in the way Samba handled file descriptors. If an attacker
were able to open a large number of file descriptors on the Samba server,
they could flip certain stack bits to "1" values, resulting in the Samba
server (smbd) crashing. (CVE-2011-0719)

Red Hat would like to thank the Samba team for reporting this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0719</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110306"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110307" severity="medium">
    <xccdf:title>RHSA-2011:0307: mailman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage email discussion lists.

Multiple input sanitization flaws were found in the way Mailman displayed
usernames of subscribed users on certain pages. If a user who is subscribed
to a mailing list were able to trick a victim into visiting one of those
pages, they could perform a cross-site scripting (XSS) attack against the
victim. (CVE-2011-0707)

Multiple input sanitization flaws were found in the way Mailman displayed
mailing list information. A mailing list administrator could use this flaw
to conduct a cross-site scripting (XSS) attack against victims viewing a
list's "listinfo" page. (CVE-2008-0564, CVE-2010-3089)

Red Hat would like to thank Mark Sapiro for reporting the CVE-2011-0707 and
CVE-2010-3089 issues.

Users of mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0707</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110308" severity="medium">
    <xccdf:title>RHSA-2011:0308: mailman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage email discussion lists.

Multiple input sanitization flaws were found in the way Mailman displayed
usernames of subscribed users on certain pages. If a user who is subscribed
to a mailing list were able to trick a victim into visiting one of those
pages, they could perform a cross-site scripting (XSS) attack against the
victim. (CVE-2011-0707)

Multiple input sanitization flaws were found in the way Mailman displayed
mailing list information. A mailing list administrator could use this flaw
to conduct a cross-site scripting (XSS) attack against victims viewing a
list's "listinfo" page. (CVE-2010-3089)

Red Hat would like to thank Mark Sapiro for reporting these issues.

Users of mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0707</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110308"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110309" severity="high">
    <xccdf:title>RHSA-2011:0309: pango security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

It was discovered that Pango did not check for memory reallocation failures
in the hb_buffer_ensure() function. An attacker able to trigger a
reallocation failure by passing sufficiently large input to an application
using Pango could use this flaw to crash the application or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0064)

Red Hat would like to thank the Mozilla Security Team for reporting this
issue.

All pango users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing this update, you
must restart your system or restart the X server for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0064</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110309"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110310" severity="high">
    <xccdf:title>RHSA-2011:0310: firefox security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox sanitized HTML content in extensions.
If an extension loaded or rendered malicious content using the
ParanoidFragmentSink class, it could fail to safely display the content,
causing Firefox to execute arbitrary JavaScript with the privileges of the
user running Firefox. (CVE-2010-1585)

A flaw was found in the way Firefox handled dialog boxes. An attacker could
use this flaw to create a malicious web page that would present a blank
dialog box that has non-functioning buttons. If a user closes the dialog
box window, it could unexpectedly grant the malicious web page elevated
privileges. (CVE-2011-0051)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-0053, CVE-2011-0055, CVE-2011-0058, CVE-2011-0062)

Several flaws were found in the way Firefox handled malformed JavaScript. A
website containing malicious JavaScript could cause Firefox to execute that
JavaScript with the privileges of the user running Firefox. (CVE-2011-0054,
CVE-2011-0056, CVE-2011-0057)

A flaw was found in the way Firefox handled malformed JPEG images. A
website containing a malicious JPEG image could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-0061)

A flaw was found in the way Firefox handled plug-ins that perform HTTP
requests. If a plug-in performed an HTTP request, and the server sent a 307
redirect response, the plug-in was not notified, and the HTTP request was
forwarded. The forwarded request could contain custom headers, which could
result in a Cross Site Request Forgery attack. (CVE-2011-0059)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.14. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bug:

* On Red Hat Enterprise Linux 4 and 5, running the "firefox
-setDefaultBrowser" command caused warnings such as the following:

libgnomevfs-WARNING **: Deprecated function.  User modifications to the
MIME database are no longer supported.

This update disables the "setDefaultBrowser" option. Red Hat Enterprise
Linux 4 users wishing to set a default web browser can use Applications -&gt;
Preferences -&gt; More Preferences -&gt; Preferred Applications. Red Hat
Enterprise Linux 5 users can use System -&gt; Preferences -&gt; Preferred
Applications. (BZ#463131, BZ#665031)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.14, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0062</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110310"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110311" severity="high">
    <xccdf:title>RHSA-2011:0311: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2010-1585, CVE-2011-0053, CVE-2011-0062)

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-0061)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0311</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0062</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110311"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110312" severity="medium">
    <xccdf:title>RHSA-2011:0312: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0051, CVE-2011-0053)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0053</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110312"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110313" severity="high">
    <xccdf:title>RHSA-2011:0313: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled dialog boxes. An attacker
could use this flaw to create a malicious web page that would present a
blank dialog box that has non-functioning buttons. If a user closes the
dialog box window, it could unexpectedly grant the malicious web page
elevated privileges. (CVE-2011-0051)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-0053)

A flaw was found in the way SeaMonkey handled plug-ins that perform HTTP
requests. If a plug-in performed an HTTP request, and the server sent a 307
redirect response, the plug-in was not notified, and the HTTP request was
forwarded. The forwarded request could contain custom headers, which could
result in a Cross Site Request Forgery attack. (CVE-2011-0059)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0059</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110313"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110318" severity="high">
    <xccdf:title>RHSA-2011:0318: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF Internet Fax image files, compressed with the CCITT Group 4
compression algorithm. An attacker could use this flaw to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2011-0192)

Red Hat would like to thank Apple Product Security for reporting this
issue.

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0318</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0192</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110318"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110320" severity="high">
    <xccdf:title>RHSA-2011:0320: libcgroup security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libcgroup packages provide tools and libraries to control and monitor
control groups.

A heap-based buffer overflow flaw was found in the way libcgroup converted
a list of user-provided controllers for a particular task into an array of
strings. A local attacker could use this flaw to escalate their privileges
via a specially-crafted list of controllers. (CVE-2011-1006)

It was discovered that libcgroup did not properly check the origin of
Netlink messages. A local attacker could use this flaw to send crafted
Netlink messages to the cgrulesengd daemon, causing it to put processes
into one or more existing control groups, based on the attacker's choosing,
possibly allowing the particular tasks to run with more resources (memory,
CPU, etc.) than originally intended. (CVE-2011-1022)

Red Hat would like to thank Nelson Elhage for reporting the CVE-2011-1006
issue.

All libcgroup users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0320</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110320"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110324" severity="high">
    <xccdf:title>RHSA-2011:0324: logwatch security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Logwatch is a customizable log analysis system. Logwatch parses through
your system's logs for a given period of time and creates a report
analyzing areas that you specify, in as much detail as you require.

A flaw was found in the way Logwatch processed log files. If an attacker
were able to create a log file with a malicious file name, it could result
in arbitrary code execution with the privileges of the root user when that
log file is analyzed by Logwatch. (CVE-2011-1018)

Users of logwatch should upgrade to this updated package, which contains a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1018</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110324"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110327" severity="medium">
    <xccdf:title>RHSA-2011:0327: subversion security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests to lock working copy paths in a repository. A
remote attacker could issue a lock request that could cause the httpd
process serving the request to crash. (CVE-2011-0715)

Red Hat would like to thank Hyrum Wright of the Apache Subversion project
for reporting this issue. Upstream acknowledges Philip Martin, WANdisco,
Inc. as the original reporter.

This update also fixes the following bug:

* A regression was found in the handling of repositories which do not have
a "db/fsfs.conf" file. The "svnadmin hotcopy" command would fail when
trying to produce a copy of such a repository. This command has been fixed
to ignore the absence of the "fsfs.conf" file. The "svnadmin hotcopy"
command will now succeed for this type of repository. (BZ#681522)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0715</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110328" severity="medium">
    <xccdf:title>RHSA-2011:0328: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests to lock working copy paths in a repository. A
remote attacker could issue a lock request that could cause the httpd
process serving the request to crash. (CVE-2011-0715)

Red Hat would like to thank Hyrum Wright of the Apache Subversion project
for reporting this issue. Upstream acknowledges Philip Martin, WANdisco,
Inc. as the original reporter.

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0328</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0715</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110328"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110329" severity="high">
    <xccdf:title>RHSA-2011:0329: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A use-after-free flaw was found in the Linux kernel's RPC server sockets
implementation. A remote attacker could use this flaw to trigger a denial
of service by sending a corrupted packet to a target system.
(CVE-2011-0714, Important)

Red Hat would like to thank Adam Prince for reporting this issue.

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0714</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110329"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110332" severity="high">
    <xccdf:title>RHSA-2011:0332: scsi-target-utils security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The scsi-target-utils package contains the daemon and tools to set up and
monitor SCSI targets. Currently, iSCSI software and iSER targets are
supported.

A double-free flaw was found in scsi-target-utils' tgtd daemon. A remote
attacker could trigger this flaw by sending carefully-crafted network
traffic, causing the tgtd daemon to crash. (CVE-2011-0001)

Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for
reporting this issue.

All scsi-target-utils users should upgrade to this updated package, which
contains a backported patch to correct this issue. All running
scsi-target-utils services must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0332</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0001</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110332"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110335" severity="high">
    <xccdf:title>RHSA-2011:0335: tomcat6 security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Tomcat to hang via a specially-crafted HTTP request. (CVE-2010-4476)

A flaw was found in the Tomcat NIO (Non-Blocking I/O) connector. A remote
attacker could use this flaw to cause a denial of service (out-of-memory
condition) via a specially-crafted request containing a large NIO buffer
size request value. (CVE-2011-0534)

This update also fixes the following bug:

* A bug in the "tomcat6" init script prevented additional Tomcat instances
from starting. As well, running "service tomcat6 start" caused
configuration options applied from "/etc/sysconfig/tomcat6" to be
overwritten with those from "/etc/tomcat6/tomcat6.conf". With this update,
multiple instances of Tomcat run as expected. (BZ#676922)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0335</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0534</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110335"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110336" severity="high">
    <xccdf:title>RHSA-2011:0336: tomcat5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Tomcat to hang via a specially-crafted HTTP request. (CVE-2010-4476)

Users of Tomcat should upgrade to these updated packages, which contain a
backported patch to correct this issue. Tomcat must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4476</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110336"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110337" severity="high">
    <xccdf:title>RHSA-2011:0337: vsftpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux, UNIX, and similar operating systems.

A flaw was discovered in the way vsftpd processed file name patterns. An
FTP user could use this flaw to cause the vsftpd process to use an
excessive amount of CPU time, when processing a request with a
specially-crafted file name pattern. (CVE-2011-0762)

All vsftpd users should upgrade to this updated package, which contains a
backported patch to correct this issue. The vsftpd daemon must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0762</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110337"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110345" severity="medium">
    <xccdf:title>RHSA-2011:0345: qemu-kvm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM. Virtual Network Computing (VNC) is
a remote display system.

A flaw was found in the way the VNC "password" option was handled. Clearing
a password disabled VNC authentication, allowing a remote user able to
connect to the virtual machines' VNC ports to open a VNC session without
authentication. (CVE-2011-0011)

All users of qemu-kvm should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0011</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110345"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110346" severity="medium">
    <xccdf:title>RHSA-2011:0346: openldap security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled authentication failures being
passed from an OpenLDAP slave to the master. If OpenLDAP was configured
with a chain overlay and it forwarded authentication failures, OpenLDAP
would bind to the directory as an anonymous user and return success, rather
than return failure on the authenticated bind. This could allow a user on a
system that uses LDAP for authentication to log into a directory-based
account without knowing the password. (CVE-2011-1024)

This update also fixes the following bug:

* Previously, multiple concurrent connections to an OpenLDAP server could
cause the slapd service to terminate unexpectedly with an assertion error.
This update adds mutexes to protect multiple threads from accessing a
structure with a connection, and the slapd service no longer crashes.
(BZ#677611)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0346</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1024</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110346"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110347" severity="medium">
    <xccdf:title>RHSA-2011:0347: openldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled authentication failures being
passed from an OpenLDAP slave to the master. If OpenLDAP was configured
with a chain overlay and it forwarded authentication failures, OpenLDAP
would bind to the directory as an anonymous user and return success, rather
than return failure on the authenticated bind. This could allow a user on a
system that uses LDAP for authentication to log into a directory-based
account without knowing the password. (CVE-2011-1024)

It was found that the OpenLDAP back-ndb back end allowed successful
authentication to the root distinguished name (DN) when any string was
provided as a password. A remote user could use this flaw to access an
OpenLDAP directory if they knew the value of the root DN. Note: This issue
only affected OpenLDAP installations using the NDB back-end, which is only
available for Red Hat Enterprise Linux 6 via third-party software.
(CVE-2011-1025)

A flaw was found in the way OpenLDAP handled modify relative distinguished
name (modrdn) requests. A remote, unauthenticated user could use this flaw
to crash an OpenLDAP server via a modrdn request containing an empty old
RDN value. (CVE-2011-1081)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1081</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110347"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110356" severity="high">
    <xccdf:title>RHSA-2011:0356: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC). The Public Key
Cryptography for Initial Authentication in Kerberos (PKINIT) capability
provides support for using public-key authentication with Kerberos.

A double-free flaw was found in the way the MIT Kerberos KDC handled
initial authentication requests (AS-REQ), when the KDC was configured to
provide the PKINIT capability. A remote attacker could use this flaw to
cause the KDC daemon to abort by using a specially-crafted AS-REQ request.
(CVE-2011-0284)

All krb5 users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0356</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0284</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110356"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110369" severity="medium">
    <xccdf:title>RHSA-2011:0369: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A heap-based buffer overflow flaw was found in the Wireshark MAC-LTE
dissector. If Wireshark read a malformed packet off a network or opened a
malicious dump file, it could crash or, possibly, execute arbitrary code as
the user running Wireshark. (CVE-2011-0444)

A heap-based buffer overflow flaw was found in the way Wireshark processed
signaling traces generated by the Gammu utility on Nokia DCT3 phones
running in Netmonitor mode. If Wireshark opened a specially-crafted capture
file, it could crash or, possibly, execute arbitrary code as the user
running Wireshark. (CVE-2011-0713)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2011-0538, CVE-2011-1139, CVE-2011-1140,
CVE-2011-1141)

Users of Wireshark should upgrade to these updated packages, which contain
Wireshark version 1.2.15, and resolve these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0369</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1141</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110369"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110370" severity="medium">
    <xccdf:title>RHSA-2011:0370: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A heap-based buffer overflow flaw was found in Wireshark. If Wireshark
opened a specially-crafted capture file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2011-0024)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2010-3445, CVE-2011-0538, CVE-2011-1139,
CVE-2011-1140, CVE-2011-1141, CVE-2011-1143)

Users of Wireshark should upgrade to these updated packages, which contain
backported patches to correct these issues. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1143</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110370"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110376" severity="medium">
    <xccdf:title>RHSA-2011:0376: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial of service flaw was discovered in the system for sending messages
between applications. A local user could send a message with an excessive
number of nested variants to the system-wide message bus, causing the
message bus (and, consequently, any process using libdbus to receive
messages) to abort. (CVE-2010-4352)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4352</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110390" severity="medium">
    <xccdf:title>RHSA-2011:0390: rsync security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>rsync is a program for synchronizing files over a network.

A memory corruption flaw was found in the way the rsync client processed
malformed file list data. If an rsync client used the "--recursive" and
"--delete" options without the "--owner" option when connecting to a
malicious rsync server, the malicious server could cause rsync on the
client system to crash or, possibly, execute arbitrary code with the
privileges of the user running rsync. (CVE-2011-1097)

Red Hat would like to thank Wayne Davison and Matt McCutchen for reporting
this issue.

Users of rsync should upgrade to this updated package, which contains a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0390</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1097</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110390"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110391" severity="high">
    <xccdf:title>RHSA-2011:0391: libvirt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

It was found that several libvirt API calls did not honor the read-only
permission for connections. A local attacker able to establish a read-only
connection to libvirtd on a server could use this flaw to execute commands
that should be restricted to read-write connections, possibly leading to a
denial of service or privilege escalation. (CVE-2011-1146)

Note: Previously, using rpmbuild without the '--define "rhel 5"' option to
build the libvirt source RPM on Red Hat Enterprise Linux 5 failed with a
"Failed build dependencies" error for the device-mapper-devel package, as
this -devel sub-package is not available on Red Hat Enterprise Linux 5.
With this update, the -devel sub-package is no longer checked by default as
a dependency when building on Red Hat Enterprise Linux 5, allowing the
libvirt source RPM to build as expected.

All libvirt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1146</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110391"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110392" severity="high">
    <xccdf:title>RHSA-2011:0392: libtiff security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF files encoded with a 4-bit run-length encoding scheme from
ThunderScan. An attacker could use this flaw to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2011-1167)

This update also fixes the following bug:

* The RHSA-2011:0318 libtiff update introduced a regression that prevented
certain TIFF Internet Fax image files, compressed with the CCITT Group 4
compression algorithm, from being read. (BZ#688825)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1167</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110392"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110394" severity="high">
    <xccdf:title>RHSA-2011:0394: conga security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The conga packages provide a web-based administration tool for remote
cluster and storage management.

A privilege escalation flaw was found in luci, the Conga web-based
administration application. A remote attacker could possibly use this flaw
to obtain administrative access, allowing them to read, create, or modify
the content of the luci application. (CVE-2011-0720)

Users of Conga are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, luci must be restarted ("service luci restart") for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0394</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110394"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110395" severity="medium">
    <xccdf:title>RHSA-2011:0395: gdm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNOME Display Manager (GDM) provides the graphical login screen, shown
shortly after boot up, log out, and when user-switching.

A race condition flaw was found in the way GDM handled the cache
directories used to store users' dmrc and face icon files. A local attacker
could use this flaw to trick GDM into changing the ownership of an
arbitrary file via a symbolic link attack, allowing them to escalate their
privileges. (CVE-2011-0727)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

All users should upgrade to these updated packages, which contain a
backported patch to correct this issue. GDM must be restarted for this
update to take effect. Rebooting achieves this, but changing the runlevel
from 5 to 3 and back to 5 also restarts GDM.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0727</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110395"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110406" severity="medium">
    <xccdf:title>RHSA-2011:0406: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol.

A denial of service flaw was found in the way the Quagga bgpd daemon
processed certain route metrics information. A BGP message with a
specially-crafted path limit attribute would cause the bgpd daemon to reset
its session with the peer through which this message was received.
(CVE-2010-1675)

A NULL pointer dereference flaw was found in the way the Quagga bgpd daemon
processed malformed route extended communities attributes. A configured BGP
peer could crash bgpd on a target system via a specially-crafted BGP
message. (CVE-2010-1674)

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1675</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110406"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110407" severity="medium">
    <xccdf:title>RHSA-2011:0407: logrotate security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The logrotate utility simplifies the administration of multiple log files,
allowing the automatic rotation, compression, removal, and mailing of log
files.

A shell command injection flaw was found in the way logrotate handled the
shred directive. A specially-crafted log file could cause logrotate to
execute arbitrary commands with the privileges of the user running
logrotate (root, by default). Note: The shred directive is not enabled by
default. (CVE-2011-1154)

A race condition flaw was found in the way logrotate applied permissions
when creating new log files. In some specific configurations, a local
attacker could use this flaw to open new log files before logrotate applies
the final permissions, possibly leading to the disclosure of sensitive
information. (CVE-2011-1098)

An input sanitization flaw was found in logrotate. A log file with a
specially-crafted file name could cause logrotate to abort when attempting
to process that file a subsequent time. (CVE-2011-1155)

All logrotate users should upgrade to this updated package, which contains
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1155</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110407"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110412" severity="high">
    <xccdf:title>RHSA-2011:0412: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

The fix for CVE-2010-3847 introduced a regression in the way the dynamic
loader expanded the $ORIGIN dynamic string token specified in the RPATH and
RUNPATH entries in the ELF library header. A local attacker could use this
flaw to escalate their privileges via a setuid or setgid program using
such a library. (CVE-2011-0536)

It was discovered that the glibc addmntent() function did not sanitize its
input properly. A local attacker could possibly use this flaw to inject
malformed lines into /etc/mtab via certain setuid mount helpers, if the
attacker were allowed to mount to an arbitrary directory under their
control. (CVE-2010-0296)

It was discovered that the glibc fnmatch() function did not properly
restrict the use of alloca(). If the function was called on sufficiently
large inputs, it could cause an application using fnmatch() to crash or,
possibly, execute arbitrary code with the privileges of the application.
(CVE-2011-1071)

It was discovered that the locale command did not produce properly escaped
output as required by the POSIX specification. If an attacker were able to
set the locale environment variables in the environment of a script that
performed shell evaluation on the output of the locale command, and that
script were run with different privileges than the attacker's, it could
execute arbitrary code with the privileges of the script. (CVE-2011-1095)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1659</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110412"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110413" severity="high">
    <xccdf:title>RHSA-2011:0413: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

The fix for CVE-2010-3847 introduced a regression in the way the dynamic
loader expanded the $ORIGIN dynamic string token specified in the RPATH and
RUNPATH entries in the ELF library header. A local attacker could use this
flaw to escalate their privileges via a setuid or setgid program using
such a library. (CVE-2011-0536)

It was discovered that the glibc fnmatch() function did not properly
restrict the use of alloca(). If the function was called on sufficiently
large inputs, it could cause an application using fnmatch() to crash or,
possibly, execute arbitrary code with the privileges of the application.
(CVE-2011-1071)

It was discovered that the locale command did not produce properly escaped
output as required by the POSIX specification. If an attacker were able to
set the locale environment variables in the environment of a script that
performed shell evaluation on the output of the locale command, and that
script were run with different privileges than the attacker's, it could
execute arbitrary code with the privileges of the script. (CVE-2011-1095)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1659</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110413"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110414" severity="high">
    <xccdf:title>RHSA-2011:0414: policycoreutils security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The policycoreutils packages contain the core utilities that are
required for the basic operation of a Security-Enhanced Linux (SELinux)
system and its policies.

It was discovered that the seunshare utility did not enforce proper file
permissions on the directory used as an alternate temporary directory
mounted as /tmp/. A local user could use this flaw to overwrite files or,
possibly, execute arbitrary code with the privileges of a setuid or
setgid application that relies on proper /tmp/ permissions, by running that
application via seunshare. (CVE-2011-1011)

Red Hat would like to thank Tavis Ormandy for reporting this issue.

This update also introduces the following changes:

* The seunshare utility was moved from the main policycoreutils subpackage
to the policycoreutils-sandbox subpackage. This utility is only required
by the sandbox feature and does not need to be installed by default.

* Updated selinux-policy packages that add the SELinux policy changes
required by the seunshare fixes.

All policycoreutils users should upgrade to these updated packages, which
correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1011</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110414"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110421" severity="high">
    <xccdf:title>RHSA-2011:0421: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the sctp_icmp_proto_unreachable() function in the
Linux kernel's Stream Control Transmission Protocol (SCTP) implementation.
A remote attacker could use this flaw to cause a denial of service.
(CVE-2010-4526, Important)

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* A race condition was found in the way the Linux kernel's InfiniBand
implementation set up new connections. This could allow a remote user to
cause a denial of service. (CVE-2011-0695, Important)

* A heap overflow flaw in the iowarrior_write() function could allow a
user with access to an IO-Warrior USB device, that supports more than 8
bytes per report, to cause a denial of service or escalate their
privileges. (CVE-2010-4656, Moderate)

* A flaw was found in the way the Linux Ethernet bridge implementation
handled certain IGMP (Internet Group Management Protocol) packets. A local,
unprivileged user on a system that has a network interface in an Ethernet
bridge could use this flaw to crash that system. (CVE-2011-0716, Moderate)

* A NULL pointer dereference flaw was found in the Generic Receive Offload
(GRO) functionality in the Linux kernel's networking implementation. If
both GRO and promiscuous mode were enabled on an interface in a virtual LAN
(VLAN), it could result in a denial of service when a malformed VLAN frame
is received on that interface. (CVE-2011-1478, Moderate)

* A missing initialization flaw in the Linux kernel could lead to an
information leak. (CVE-2010-3296, Low)

* A missing security check in the Linux kernel's implementation of the
install_special_mapping() function could allow a local, unprivileged user
to bypass the mmap_min_addr protection mechanism. (CVE-2010-4346, Low)

* A logic error in the orinoco_ioctl_set_auth() function in the Linux
kernel's ORiNOCO wireless extensions support implementation could render
TKIP countermeasures ineffective when it is enabled, as it enabled the card
instead of shutting it down. (CVE-2010-4648, Low)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

* An information leak was found in the Linux kernel's task_show_regs()
implementation. On IBM S/390 systems, a local, unprivileged user could use
this flaw to read /proc/[PID]/status files, allowing them to discover
the CPU register values of processes. (CVE-2011-0710, Low)

Red Hat would like to thank Jens Kuehnel for reporting CVE-2011-0695; Kees
Cook for reporting CVE-2010-4656 and CVE-2010-4655; Dan Rosenberg for
reporting CVE-2010-3296; and Tavis Ormandy for reporting CVE-2010-4346.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4346</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1478</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110421"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110422" severity="medium">
    <xccdf:title>RHSA-2011:0422: postfix security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

It was discovered that Postfix did not flush the received SMTP commands
buffer after switching to TLS encryption for an SMTP session. A
man-in-the-middle attacker could use this flaw to inject SMTP commands into
a victim's session during the plain text phase. This would lead to those
commands being processed by Postfix after TLS encryption is enabled,
possibly allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-0411)

It was discovered that Postfix did not properly check the permissions of
users' mailbox files. A local attacker able to create files in the mail
spool directory could use this flaw to create mailbox files for other local
users, and be able to read mail delivered to those users. (CVE-2008-2937)

Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411, and
Sebastian Krahmer of the SuSE Security Team for reporting CVE-2008-2937.
The CERT/CC acknowledges Wietse Venema as the original reporter of
CVE-2011-0411.

Users of Postfix are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the postfix service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-2937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110422"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110423" severity="medium">
    <xccdf:title>RHSA-2011:0423: postfix security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

It was discovered that Postfix did not flush the received SMTP commands
buffer after switching to TLS encryption for an SMTP session. A
man-in-the-middle attacker could use this flaw to inject SMTP commands into
a victim's session during the plain text phase. This would lead to those
commands being processed by Postfix after TLS encryption is enabled,
possibly allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-0411)

Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411. The
CERT/CC acknowledges Wietse Venema as the original reporter.

Users of Postfix are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the postfix service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110423"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110426" severity="medium">
    <xccdf:title>RHSA-2011:0426: spice-xpi security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

An uninitialized pointer use flaw was found in the SPICE Firefox plug-in.
If a user were tricked into visiting a malicious web page with Firefox
while the SPICE plug-in was enabled, it could cause Firefox to crash or,
possibly, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-1179)

It was found that the SPICE Firefox plug-in used a predictable name for one
of its log files. A local attacker could use this flaw to conduct a
symbolic link attack, allowing them to overwrite arbitrary files accessible
to the user running Firefox. (CVE-2011-0012)

Users of spice-xpi should upgrade to this updated package, which contains
backported patches to correct these issues. After installing the update,
Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1179</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110426"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110427" severity="medium">
    <xccdf:title>RHSA-2011:0427: spice-xpi security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

An uninitialized pointer use flaw was found in the SPICE Firefox plug-in.
If a user were tricked into visiting a malicious web page with Firefox
while the SPICE plug-in was enabled, it could cause Firefox to crash or,
possibly, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-1179)

Users of spice-xpi should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing the update,
Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1179</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110427"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110428" severity="high">
    <xccdf:title>RHSA-2011:0428: dhcp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

It was discovered that the DHCP client daemon, dhclient, did not
sufficiently sanitize certain options provided in DHCP server replies, such
as the client hostname. A malicious DHCP server could send such an option
with a specially-crafted value to a DHCP client. If this option's value was
saved on the client system, and then later insecurely evaluated by a
process that assumes the option is trusted, it could lead to arbitrary code
execution with the privileges of that process. (CVE-2011-0997)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

All dhclient users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0997</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110428"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110429" severity="high">
    <xccdf:title>RHSA-2011:0429: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* An inconsistency was found in the interaction between the Linux kernel's
method for allocating NFSv4 (Network File System version 4) ACL data and
the method by which it was freed. This inconsistency led to a kernel panic
which could be triggered by a local, unprivileged user with files owned by
said user on an NFSv4 share. (CVE-2011-1090, Moderate)

* A NULL pointer dereference flaw was found in the Generic Receive Offload
(GRO) functionality in the Linux kernel's networking implementation. If
both GRO and promiscuous mode were enabled on an interface in a virtual LAN
(VLAN), it could result in a denial of service when a malformed VLAN frame
is received on that interface. (CVE-2011-1478, Moderate)

* A missing security check in the Linux kernel's implementation of the
install_special_mapping() function could allow a local, unprivileged user
to bypass the mmap_min_addr protection mechanism. (CVE-2010-4346, Low)

* An information leak was found in the Linux kernel's task_show_regs()
implementation. On IBM S/390 systems, a local, unprivileged user could use
this flaw to read /proc/[PID]/status files, allowing them to discover the
CPU register values of processes. (CVE-2011-0710, Low)

* A missing validation check was found in the Linux kernel's
mac_partition() implementation, used for supporting file systems created
on Mac OS operating systems. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partitions. (CVE-2011-1010, Low)

Red Hat would like to thank Ryan Sweat for reporting CVE-2011-1478; Tavis
Ormandy for reporting CVE-2010-4346; and Timo Warns for reporting
CVE-2011-1010.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4346</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1478</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110429"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110432" severity="medium">
    <xccdf:title>RHSA-2011:0432: xorg-x11 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the X.Org X server resource database utility, xrdb.
Certain variables were not properly sanitized during the launch of a user's
graphical session, which could possibly allow a remote attacker to execute
arbitrary code with root privileges, if they were able to make the display
manager execute xrdb with a specially-crafted X client hostname. For
example, by configuring the hostname on the target system via a crafted
DHCP reply, or by using the X Display Manager Control Protocol (XDMCP) to
connect to that system from a host that has a special DNS name.
(CVE-2011-0465)

Red Hat would like to thank Matthieu Herrb for reporting this issue.
Upstream acknowledges Sebastian Krahmer of the SuSE Security Team as the
original reporter.

Users of xorg-x11 should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0465</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110432"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110433" severity="medium">
    <xccdf:title>RHSA-2011:0433: xorg-x11-server-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xorg-x11-server-utils package contains a collection of utilities used
to modify and query the runtime configuration of the X.Org server. X.Org is
an open source implementation of the X Window System.

A flaw was found in the X.Org X server resource database utility, xrdb.
Certain variables were not properly sanitized during the launch of a user's
graphical session, which could possibly allow a remote attacker to execute
arbitrary code with root privileges, if they were able to make the display
manager execute xrdb with a specially-crafted X client hostname. For
example, by configuring the hostname on the target system via a crafted
DHCP reply, or by using the X Display Manager Control Protocol (XDMCP) to
connect to that system from a host that has a special DNS name.
(CVE-2011-0465)

Red Hat would like to thank Matthieu Herrb for reporting this issue.
Upstream acknowledges Sebastian Krahmer of the SuSE Security Team as the
original reporter.

Users of xorg-x11-server-utils should upgrade to this updated package,
which contains a backported patch to resolve this issue. All running X.Org
server instances must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0465</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110433"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110436" severity="medium">
    <xccdf:title>RHSA-2011:0436: avahi security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zero Configuration Networking. It facilitates service
discovery on a local network. Avahi and Avahi-aware applications allow you
to plug your computer into a network and, with no configuration, view other
people to chat with, view printers to print to, and find shared files on
other computers.

A flaw was found in the way the Avahi daemon (avahi-daemon) processed
Multicast DNS (mDNS) packets with an empty payload. An attacker on the
local network could use this flaw to cause avahi-daemon on a target system
to enter an infinite loop via an empty mDNS UDP packet. (CVE-2011-1002)

All users are advised to upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update,
avahi-daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1002</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110436"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110447" severity="medium">
    <xccdf:title>RHSA-2011:0447: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

An invalid free flaw was found in the password-changing capability of the
MIT Kerberos administration daemon, kadmind. A remote, unauthenticated
attacker could use this flaw to cause kadmind to abort via a
specially-crafted request. (CVE-2011-0285)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the kadmind daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0285</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110447"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110452" severity="high">
    <xccdf:title>RHSA-2011:0452: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF image files that were compressed with the JPEG compression
algorithm. An attacker could use this flaw to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2009-5022)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110452"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110455" severity="high">
    <xccdf:title>RHSA-2011:0455: polkit security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PolicyKit is a toolkit for defining and handling authorizations.

A race condition flaw was found in the PolicyKit pkexec utility and polkitd
daemon. A local user could use this flaw to appear as a privileged user to
pkexec, allowing them to execute arbitrary commands as root by running
those commands with pkexec. (CVE-2011-1485)

Red Hat would like to thank Neel Mehta of Google for reporting this issue.

All polkit users should upgrade to these updated packages, which contain
backported patches to correct this issue. The system must be rebooted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1485</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110464" severity="medium">
    <xccdf:title>RHSA-2011:0464: kdelibs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A cross-site scripting (XSS) flaw was found in the way KHTML, the HTML
layout engine used by KDE applications such as the Konqueror web browser,
displayed certain error pages. A remote attacker could use this flaw to
perform a cross-site scripting attack against victims by tricking them into
visiting a specially-crafted URL. (CVE-2011-1168)

A flaw was found in the way kdelibs checked the user specified hostname
against the name in the server's SSL certificate. A man-in-the-middle
attacker could use this flaw to trick an application using kdelibs into
mistakenly accepting a certificate as if it was valid for the host, if that
certificate was issued for an IP address to which the user specified
hostname was resolved to. (CVE-2011-1094)

Note: As part of the fix for CVE-2011-1094, this update also introduces
stricter handling for wildcards used in servers' SSL certificates.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1168</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110464"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110465" severity="high">
    <xccdf:title>RHSA-2011:0465: kdenetwork security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdenetwork packages contain networking applications for the K Desktop
Environment (KDE).

A directory traversal flaw was found in the way KGet, a download manager,
handled the "file" element in Metalink files. An attacker could use this
flaw to create a specially-crafted Metalink file that, when opened, would
cause KGet to overwrite arbitrary files accessible to the user running
KGet. (CVE-2011-1586)

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch to resolve this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1586</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110465"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110471" severity="high">
    <xccdf:title>RHSA-2011:0471: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could possibly lead to arbitrary code
execution with the privileges of the user running Firefox. (CVE-2011-0080,
CVE-2011-0081)

An arbitrary memory write flaw was found in the way Firefox handled
out-of-memory conditions. If all memory was consumed when a user visited a
malicious web page, it could possibly lead to arbitrary code execution
with the privileges of the user running Firefox. (CVE-2011-0078)

An integer overflow flaw was found in the way Firefox handled the HTML
frameset tag. A web page with a frameset tag containing large values for
the "rows" and "cols" attributes could trigger this flaw, possibly leading
to arbitrary code execution with the privileges of the user running
Firefox. (CVE-2011-0077)

A flaw was found in the way Firefox handled the HTML iframe tag. A web page
with an iframe tag containing a specially-crafted source address could
trigger this flaw, possibly leading to arbitrary code execution with the
privileges of the user running Firefox. (CVE-2011-0075)

A flaw was found in the way Firefox displayed multiple marquee elements. A
malformed HTML document could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0074)

A flaw was found in the way Firefox handled the nsTreeSelection element.
Malformed content could cause Firefox to execute arbitrary code with the
privileges of the user running Firefox. (CVE-2011-0073)

A use-after-free flaw was found in the way Firefox appended frame and
iframe elements to a DOM tree when the NoScript add-on was enabled.
Malicious HTML content could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0072)

A directory traversal flaw was found in the Firefox resource:// protocol
handler. Malicious content could cause Firefox to access arbitrary files
accessible to the user running Firefox. (CVE-2011-0071)

A double free flaw was found in the way Firefox handled
"application/http-index-format" documents. A malformed HTTP response could
cause Firefox to execute arbitrary code with the privileges of the user
running Firefox. (CVE-2011-0070)

A flaw was found in the way Firefox handled certain JavaScript cross-domain
requests. If malicious content generated a large number of cross-domain
JavaScript requests, it could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0069)

A flaw was found in the way Firefox displayed the autocomplete pop-up.
Malicious content could use this flaw to steal form history information.
(CVE-2011-0067)

Two use-after-free flaws were found in the Firefox mObserverList and
mChannel objects. Malicious content could use these flaws to execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2011-0066, CVE-2011-0065)

A flaw was found in the Firefox XSLT generate-id() function. This function
returned the memory address of an object in memory, which could possibly be
used by attackers to bypass address randomization protections.
(CVE-2011-1202)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.17. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.17, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1202</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110471"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110473" severity="high">
    <xccdf:title>RHSA-2011:0473: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could possibly lead to arbitrary code
execution with the privileges of the user running SeaMonkey.
(CVE-2011-0080)

An arbitrary memory write flaw was found in the way SeaMonkey handled
out-of-memory conditions. If all memory was consumed when a user visited a
malicious web page, it could possibly lead to arbitrary code execution
with the privileges of the user running SeaMonkey. (CVE-2011-0078)

An integer overflow flaw was found in the way SeaMonkey handled the HTML
frameset tag. A web page with a frameset tag containing large values for
the "rows" and "cols" attributes could trigger this flaw, possibly leading
to arbitrary code execution with the privileges of the user running
SeaMonkey. (CVE-2011-0077)

A flaw was found in the way SeaMonkey handled the HTML iframe tag. A web
page with an iframe tag containing a specially-crafted source address could
trigger this flaw, possibly leading to arbitrary code execution with the
privileges of the user running SeaMonkey. (CVE-2011-0075)

A flaw was found in the way SeaMonkey displayed multiple marquee elements.
A malformed HTML document could cause SeaMonkey to execute arbitrary code
with the privileges of the user running SeaMonkey. (CVE-2011-0074)

A flaw was found in the way SeaMonkey handled the nsTreeSelection element.
Malformed content could cause SeaMonkey to execute arbitrary code with the
privileges of the user running SeaMonkey. (CVE-2011-0073)

A use-after-free flaw was found in the way SeaMonkey appended frame and
iframe elements to a DOM tree when the NoScript add-on was enabled.
Malicious HTML content could cause SeaMonkey to execute arbitrary code with
the privileges of the user running SeaMonkey. (CVE-2011-0072)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0080</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110473"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110474" severity="high">
    <xccdf:title>RHSA-2011:0474: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could possibly lead to
arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-0080)

An arbitrary memory write flaw was found in the way Thunderbird handled
out-of-memory conditions. If all memory was consumed when a user viewed a
malicious HTML mail message, it could possibly lead to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0078)

An integer overflow flaw was found in the way Thunderbird handled the HTML
frameset tag. An HTML mail message with a frameset tag containing large
values for the "rows" and "cols" attributes could trigger this flaw,
possibly leading to arbitrary code execution with the privileges of the
user running Thunderbird. (CVE-2011-0077)

A flaw was found in the way Thunderbird handled the HTML iframe tag. An
HTML mail message with an iframe tag containing a specially-crafted source
address could trigger this flaw, possibly leading to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0075)

A flaw was found in the way Thunderbird displayed multiple marquee
elements. A malformed HTML mail message could cause Thunderbird to execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0074)

A flaw was found in the way Thunderbird handled the nsTreeSelection
element. Malformed content could cause Thunderbird to execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0073)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0080</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110475" severity="high">
    <xccdf:title>RHSA-2011:0475: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could possibly lead to
arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-0080, CVE-2011-0081)

An arbitrary memory write flaw was found in the way Thunderbird handled
out-of-memory conditions. If all memory was consumed when a user viewed a
malicious HTML mail message, it could possibly lead to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0078)

An integer overflow flaw was found in the way Thunderbird handled the HTML
frameset tag. An HTML mail message with a frameset tag containing large
values for the "rows" and "cols" attributes could trigger this flaw,
possibly leading to arbitrary code execution with the privileges of the
user running Thunderbird. (CVE-2011-0077)

A flaw was found in the way Thunderbird handled the HTML iframe tag. An
HTML mail message with an iframe tag containing a specially-crafted source
address could trigger this flaw, possibly leading to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0075)

A flaw was found in the way Thunderbird displayed multiple marquee
elements. A malformed HTML mail message could cause Thunderbird to execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0074)

A flaw was found in the way Thunderbird handled the nsTreeSelection
element. Malformed content could cause Thunderbird to execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0073)

A directory traversal flaw was found in the Thunderbird resource://
protocol handler. Malicious content could cause Thunderbird to access
arbitrary files accessible to the user running Thunderbird. (CVE-2011-0071)

A double free flaw was found in the way Thunderbird handled
"application/http-index-format" documents. A malformed HTTP response could
cause Thunderbird to execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2011-0070)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0081</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110475"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110477" severity="high">
    <xccdf:title>RHSA-2011:0477: gstreamer-plugins security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gstreamer-plugins packages contain plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media formats.

An integer overflow flaw, leading to a heap-based buffer overflow, and a
stack-based buffer overflow flaw were found in various ModPlug music file
format library (libmodplug) modules, embedded in GStreamer. An attacker
could create specially-crafted music files that, when played by a victim,
would cause applications using GStreamer to crash or, potentially, execute
arbitrary code. (CVE-2006-4192, CVE-2011-1574)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as Rhythmbox)
must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-4192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1574</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110477"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110478" severity="medium">
    <xccdf:title>RHSA-2011:0478: libvirt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

A flaw was found in the way libvirtd handled error reporting for concurrent
connections. A remote attacker able to establish read-only connections to
libvirtd on a server could use this flaw to crash libvirtd. (CVE-2011-1486)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110478"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110479" severity="medium">
    <xccdf:title>RHSA-2011:0479: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

A flaw was found in the way libvirtd handled error reporting for concurrent
connections. A remote attacker able to establish read-only connections to
libvirtd on a server could use this flaw to crash libvirtd. (CVE-2011-1486)

This update also fixes the following bug:

* Previously, running qemu under a different UID prevented it from
accessing files with mode 0660 permissions that were owned by a different
user, but by a group that qemu was a member of. (BZ#668692)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110479"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110486" severity="medium">
    <xccdf:title>RHSA-2011:0486: xmlsec1 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The XML Security Library is a C library based on libxml2 and OpenSSL that
implements the XML Digital Signature and XML Encryption standards.

A flaw was found in the way xmlsec1 handled XML files that contain an XSLT
transformation specification. A specially-crafted XML file could cause
xmlsec1 to create or overwrite an arbitrary file while performing the
verification of a file's digital signature. (CVE-2011-1425)

Red Hat would like to thank Nicolas Grégoire and Aleksey Sanin for
reporting this issue.

This update also fixes the following bug:

* xmlsec1 previously used an incorrect search path when searching for
crypto plug-in libraries, possibly trying to access such libraries using a
relative path. (BZ#558480, BZ#700467)

Users of xmlsec1 should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the update,
all running applications that use the xmlsec1 library must be restarted for
the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1425</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110486"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110491" severity="medium">
    <xccdf:title>RHSA-2011:0491: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

Multiple flaws were found in the Python audioop module. Supplying certain
inputs could cause the audioop module to crash or, possibly, execute
arbitrary code. (CVE-2010-1634, CVE-2010-2089)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

A buffer over-read flaw was found in the way the Python Expat parser
handled malformed UTF-8 sequences when processing XML files. A
specially-crafted XML file could cause Python applications using the Python
Expat parser to crash while parsing the file. (CVE-2009-3720)

This update makes Python use the system Expat library rather than its own
internal copy; therefore, users must have the version of Expat shipped with
RHSA-2009:1625 installed, or a later version, to resolve the CVE-2009-3720
issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110491"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110492" severity="medium">
    <xccdf:title>RHSA-2011:0492: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

A buffer over-read flaw was found in the way the Python Expat parser
handled malformed UTF-8 sequences when processing XML files. A
specially-crafted XML file could cause Python applications using the Python
Expat parser to crash while parsing the file. (CVE-2009-3720)

This update makes Python use the system Expat library rather than its own
internal copy; therefore, users must have the version of Expat shipped with
RHSA-2009:1625 installed, or a later version, to resolve the CVE-2009-3720
issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3720</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110492"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110496" severity="high">
    <xccdf:title>RHSA-2011:0496: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

It was found that the xc_try_bzip2_decode() and xc_try_lzma_decode() decode
routines did not correctly check for a possible buffer size overflow in the
decoding loop. As well, several integer overflow flaws and missing
error/range checking were found that could lead to an infinite loop. A
privileged guest user could use these flaws to crash the guest or,
possibly, execute arbitrary code in the privileged management domain
(Dom0). (CVE-2011-1583)

All xen users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1583</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3262</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110496"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110498" severity="high">
    <xccdf:title>RHSA-2011:0498: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* An integer overflow flaw in ib_uverbs_poll_cq() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-4649, Important)

* An integer signedness flaw in drm_modeset_ctl() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2011-1013, Important)

* The Radeon GPU drivers in the Linux kernel were missing sanity checks for
the Anti Aliasing (AA) resolve register values which could allow a local,
unprivileged user to cause a denial of service or escalate their privileges
on systems using a graphics card from the ATI Radeon R300, R400, or R500
family of cards. (CVE-2011-1016, Important)

* A flaw in dccp_rcv_state_process() could allow a remote attacker to
cause a denial of service, even when the socket was already closed.
(CVE-2011-1093, Important)

* A flaw in the Linux kernel's Stream Control Transmission Protocol (SCTP)
implementation could allow a remote attacker to cause a denial of service
if the sysctl "net.sctp.addip_enable" and "auth_enable" variables were
turned on (they are off by default). (CVE-2011-1573, Important)

* A memory leak in the inotify_init() system call. In some cases, it could
leak a group, which could allow a local, unprivileged user to eventually
cause a denial of service. (CVE-2010-4250, Moderate)

* A missing validation of a null-terminated string data structure element
in bnep_sock_ioctl() could allow a local user to cause an information leak
or a denial of service. (CVE-2011-1079, Moderate)

* An information leak in bcm_connect() in the Controller Area Network (CAN)
Broadcast Manager implementation could allow a local, unprivileged user to
leak kernel mode addresses in "/proc/net/can-bcm". (CVE-2010-4565, Low)

* A flaw was found in the Linux kernel's Integrity Measurement Architecture
(IMA) implementation. When SELinux was disabled, adding an IMA rule which
was supposed to be processed by SELinux would cause ima_match_rules() to
always succeed, ignoring any remaining rules. (CVE-2011-0006, Low)

* A missing initialization flaw in the XFS file system implementation could
lead to an information leak. (CVE-2011-0711, Low)

* Buffer overflow flaws in snd_usb_caiaq_audio_init() and
snd_usb_caiaq_midi_init() could allow a local, unprivileged user with
access to a Native Instruments USB audio device to cause a denial of
service or escalate their privileges. (CVE-2011-0712, Low)

* The start_code and end_code values in "/proc/[pid]/stat" were not
protected. In certain scenarios, this flaw could be used to defeat Address
Space Layout Randomization (ASLR). (CVE-2011-0726, Low)

* A flaw in dev_load() could allow a local user who has the CAP_NET_ADMIN
capability to load arbitrary modules from "/lib/modules/", instead of only
netdev modules. (CVE-2011-1019, Low)

* A flaw in ib_uverbs_poll_cq() could allow a local, unprivileged user to
cause an information leak. (CVE-2011-1044, Low)

* A missing validation of a null-terminated string data structure element
in do_replace() could allow a local user who has the CAP_NET_ADMIN
capability to cause an information leak. (CVE-2011-1080, Low)

Red Hat would like to thank Vegard Nossum for reporting CVE-2010-4250;
Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1019, and
CVE-2011-1080; Dan Rosenberg for reporting CVE-2010-4565 and CVE-2011-0711;
Rafael Dominguez Vega for reporting CVE-2011-0712; and Kees Cook for
reporting CVE-2011-0726.

This update also fixes various bugs and adds an enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4250</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4649</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0726</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1573</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110498"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110506" severity="medium">
    <xccdf:title>RHSA-2011:0506: rdesktop security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>rdesktop is a client for the Remote Desktop Server (previously, Terminal
Server) in Microsoft Windows. It uses the Remote Desktop Protocol (RDP) to
remotely present a user's desktop.

A directory traversal flaw was found in the way rdesktop shared a local
path with a remote server. If a user connects to a malicious server with
rdesktop, the server could use this flaw to cause rdesktop to read and
write to arbitrary, local files accessible to the user running rdesktop.
(CVE-2011-1595)

Red Hat would like to thank Cendio AB for reporting this issue. Cendio AB
acknowledges an anonymous contributor working with the SecuriTeam Secure
Disclosure program as the original reporter.

Users of rdesktop should upgrade to this updated package, which contains a
backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1595</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110506"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110507" severity="medium">
    <xccdf:title>RHSA-2011:0507: apr security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It provides a free library of C data
structures and routines.

It was discovered that the apr_fnmatch() function used an unconstrained
recursion when processing patterns with the '*' wildcard. An attacker could
use this flaw to cause an application using this function, which also
accepted untrusted input as a pattern for matching (such as an httpd server
using the mod_autoindex module), to exhaust all stack memory or use an
excessive amount of CPU time when performing matching. (CVE-2011-0419)

Red Hat would like to thank Maksymilian Arciemowicz for reporting this
issue.

All apr users should upgrade to these updated packages, which contain a
backported patch to correct this issue. Applications using the apr library,
such as httpd, must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0419</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110507"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110534" severity="high">
    <xccdf:title>RHSA-2011:0534: qemu-kvm security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that the virtio-blk driver in qemu-kvm did not properly
validate read and write requests from guests. A privileged guest user could
use this flaw to crash the guest or, possibly, execute arbitrary code on
the host. (CVE-2011-1750)

It was found that the PIIX4 Power Management emulation layer in qemu-kvm
did not properly check for hot plug eligibility during device removals. A
privileged guest user could use this flaw to crash the guest or, possibly,
execute arbitrary code on the host. (CVE-2011-1751)

Red Hat would like to thank Nelson Elhage for reporting CVE-2011-1751.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues, and fix the bugs and
add the enhancements noted in the Technical Notes. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1751</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110534"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110542" severity="high">
    <xccdf:title>RHSA-2011:0542: Red Hat Enterprise Linux 6.1 kernel security, bug fix and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Multiple buffer overflow flaws were found in the Linux kernel's
Management Module Support for Message Passing Technology (MPT) based
controllers. A local, unprivileged user could use these flaws to cause a
denial of service, an information leak, or escalate their privileges.
(CVE-2011-1494, CVE-2011-1495, Important)

* A flaw was found in the Linux kernel's Ethernet bonding driver
implementation. Packets coming in from network devices that have more
than 16 receive queues to a bonding interface could cause a denial of
service. (CVE-2011-1581, Important)

* A flaw was found in the Linux kernel's networking subsystem. If the
number of packets received exceeded the receiver's buffer limit, they were
queued in a backlog, consuming memory, instead of being discarded. A remote
attacker could abuse this flaw to cause a denial of service (out-of-memory
condition). (CVE-2010-4251, Moderate)

* A flaw was found in the Linux kernel's Transparent Huge Pages (THP)
implementation. A local, unprivileged user could abuse this flaw to allow
the user stack (when it is using huge pages) to grow and cause a denial of
service. (CVE-2011-0999, Moderate)

* A flaw was found in the transmit methods (xmit) for the loopback and
InfiniBand transports in the Linux kernel's Reliable Datagram Sockets (RDS)
implementation. A local, unprivileged user could use this flaw to cause a
denial of service. (CVE-2011-1023, Moderate)

* A flaw in the Linux kernel's Event Poll (epoll) implementation could
allow a local, unprivileged user to cause a denial of service.
(CVE-2011-1082, Moderate)

* An inconsistency was found in the interaction between the Linux kernel's
method for allocating NFSv4 (Network File System version 4) ACL data and
the method by which it was freed. This inconsistency led to a kernel panic
which could be triggered by a local, unprivileged user with files owned by
said user on an NFSv4 share. (CVE-2011-1090, Moderate)

* A missing validation check was found in the Linux kernel's
mac_partition() implementation, used for supporting file systems created
on Mac OS operating systems. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partitions. (CVE-2011-1010, Low)

* A buffer overflow flaw in the DEC Alpha OSF partition implementation in
the Linux kernel could allow a local attacker to cause an information leak
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1163, Low)

* Missing validations of null-terminated string data structure elements in
the do_replace(), compat_do_replace(), do_ipt_get_ctl(), do_ip6t_get_ctl(),
and do_arpt_get_ctl() functions could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1170,
CVE-2011-1171, CVE-2011-1172, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1494 and
CVE-2011-1495; Nelson Elhage for reporting CVE-2011-1082; Timo Warns for
reporting CVE-2011-1010 and CVE-2011-1163; and Vasiliy Kulikov for
reporting CVE-2011-1170, CVE-2011-1171, and CVE-2011-1172.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.1 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.1 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4251</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1495</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1581</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110542"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110545" severity="low">
    <xccdf:title>RHSA-2011:0545: squid security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

It was found that string comparison functions in Squid did not properly
handle the comparisons of NULL and empty strings. A remote, trusted web
client could use this flaw to cause the squid daemon to crash via a
specially-crafted request. (CVE-2010-3072)

This update also fixes the following bugs:

* A small memory leak in Squid caused multiple "ctx: enter level" messages
to be logged to "/var/log/squid/cache.log". This update resolves the memory
leak. (BZ#666533)

* This erratum upgrades Squid to upstream version 3.1.10. This upgraded
version supports the Google Instant service and introduces various code
improvements. (BZ#639365)

Users of squid should upgrade to this updated package, which resolves these
issues. After installing this update, the squid service will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3072</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110545"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110554" severity="medium">
    <xccdf:title>RHSA-2011:0554: python security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

This erratum also upgrades Python to upstream version 2.6.6, and includes a
number of bug fixes and enhancements. Documentation for these bug fixes
and enhancements is available from the Technical Notes document, linked to
in the References section.

All users of Python are advised to upgrade to these updated packages, which
correct these issues, and fix the bugs and add the enhancements noted in
the Technical Notes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110554"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110558" severity="medium">
    <xccdf:title>RHSA-2011:0558: perl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming. The Perl CGI module provides
resources for preparing and processing Common Gateway Interface (CGI) based
HTTP requests and responses.

It was found that the Perl CGI module used a hard-coded value for the MIME
boundary string in multipart/x-mixed-replace content. A remote attacker
could possibly use this flaw to conduct an HTTP response splitting attack
via a specially-crafted HTTP request. (CVE-2010-2761)

A CRLF injection flaw was found in the way the Perl CGI module processed a
sequence of non-whitespace preceded by newline characters in the header. A
remote attacker could use this flaw to conduct an HTTP response splitting
attack via a specially-crafted sequence of characters provided to the CGI
module. (CVE-2010-4410)

It was found that certain Perl string manipulation functions (such as uc()
and lc()) failed to preserve the taint bit. A remote attacker could use
this flaw to bypass the Perl taint mode protection mechanism in scripts
that use the affected functions to process tainted input. (CVE-2011-1487)

These packages upgrade the CGI module to version 3.51. Refer to the CGI
module's Changes file, linked to in the References, for a full list of
changes.

This update also fixes the following bugs:

* When using the "threads" module, an attempt to send a signal to a thread
that did not have a signal handler specified caused the perl interpreter to
terminate unexpectedly with a segmentation fault. With this update, the
"threads" module has been updated to upstream version 1.82, which fixes
this bug. As a result, sending a signal to a thread that does not have the
signal handler specified no longer causes perl to crash. (BZ#626330)

* Prior to this update, the perl packages did not require the Digest::SHA
module as a dependency. Consequent to this, when a user started the cpan
command line interface and attempted to download a distribution from CPAN,
they may have been presented with the following message:

CPAN: checksum security checks disabled because Digest::SHA not installed.
Please consider installing the Digest::SHA module.

This update corrects the spec file for the perl package to require the
perl-Digest-SHA package as a dependency, and cpan no longer displays the
above message. (BZ#640716)

* When using the "threads" module, continual creation and destruction of
threads could cause the Perl program to consume an increasing amount of
memory. With this update, the underlying source code has been corrected to
free the allocated memory when a thread is destroyed, and the continual
creation and destruction of threads in Perl programs no longer leads to
memory leaks. (BZ#640720)

* Due to a packaging error, the perl packages did not include the
"NDBM_File" module. This update corrects this error, and "NDBM_File" is now
included as expected. (BZ#640729)

* Prior to this update, the prove(1) manual page and the "prove --help"
command listed "--fork" as a valid command line option. However, version
3.17 of the Test::Harness distribution removed the support for the
fork-based parallel testing, and the prove utility thus no longer supports
this option. This update corrects both the manual page and the output of
the "prove --help" command, so that "--fork" is no longer included in the
list of available command line options. (BZ#609492)

Users of Perl, especially those of Perl threads, are advised to upgrade to
these updated packages, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2761</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1487</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110558"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110560" severity="low">
    <xccdf:title>RHSA-2011:0560: sssd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.

A flaw was found in the SSSD PAM responder that could allow a local
attacker to crash SSSD via a carefully-crafted packet. With SSSD
unresponsive, legitimate users could be denied the ability to log in to the
system. (CVE-2010-4341)

Red Hat would like to thank Sebastian Krahmer for reporting this issue.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

Users of SSSD should upgrade to these updated packages, which upgrade SSSD
to upstream version 1.5.1 to correct this issue, and fix the bugs and add
the enhancements noted in the Technical Notes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0560</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4341</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110560"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110568" severity="low">
    <xccdf:title>RHSA-2011:0568: eclipse security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Eclipse software development environment provides a set of tools for
C/C++ and Java development.

A cross-site scripting (XSS) flaw was found in the Eclipse Help Contents
web application. An attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted Eclipse Help URL. (CVE-2010-4647)

The following Eclipse packages have been upgraded to the versions found in
the official upstream Eclipse Helios SR1 release, providing a number of
bug fixes and enhancements over the previous versions:

* eclipse to 3.6.1. (BZ#656329)
* eclipse-cdt to 7.0.1. (BZ#656333)
* eclipse-birt to 2.6.0. (BZ#656391)
* eclipse-emf to 2.6.0. (BZ#656344)
* eclipse-gef to 3.6.1. (BZ#656347)
* eclipse-mylyn to 3.4.2. (BZ#656337)
* eclipse-rse to 3.2. (BZ#656338)
* eclipse-dtp to 1.8.1. (BZ#656397)
* eclipse-changelog to 2.7.0. (BZ#669499)
* eclipse-valgrind to 0.6.1. (BZ#669460)
* eclipse-callgraph to 0.6.1. (BZ#669462)
* eclipse-oprofile to 0.6.1. (BZ#670228)
* eclipse-linuxprofilingframework to 0.6.1. (BZ#669461)

In addition, the following updates were made to the dependencies of the
Eclipse packages above:

* icu4j to 4.2.1. (BZ#656342)
* sat4j to 2.2.0. (BZ#661842)
* objectweb-asm to 3.2. (BZ#664019)
* jetty-eclipse to 6.1.24. (BZ#661845)

This update includes numerous upstream bug fixes and enhancements, such as:

* The Eclipse IDE and Java Development Tools (JDT):

- projects and folders can filter out resources in the workspace.
- new virtual folder and linked files support.
- the full set of UNIX file permissions is now supported.
- addition of the stop button to cancel long-running wizard tasks.
- Java editor now shows multiple quick-fixes via problem hover.
- new support for running JUnit version 4 tests.
- over 200 upstream bug fixes.

* The Eclipse C/C++ Development Tooling (CDT):

- new Codan framework has been added for static code analysis.
- refactoring improvements such as stored refactoring history.
- compile and build errors now highlighted in the build console.
- switch to the new DSF debugger framework.
- new template view support.
- over 600 upstream bug fixes.

This update also fixes the following bugs:

* Incorrect URIs for GNU Tools in the "Help Contents" window have been
fixed. (BZ#622713)

* The profiling of binaries did not work if an Eclipse project was not in
an Eclipse workspace. This update adds an automated test for external
project profiling, which corrects this issue. (BZ#622867)

* Running a C/C++ application in Eclipse successfully terminated, but
returned an I/O exception not related to the application itself in the
Error Log window. With this update, the exception is no longer returned.
(BZ#668890)

* The eclipse-mylyn package showed a "20100916-0100-e3x" qualifier. The
qualifier has been modified to "v20100902-0100-e3x" to match the upstream
version of eclipse-mylyn. (BZ#669819)

* Installing the eclipse-mylyn package failed and returned a "Resource
temporarily unavailable" error message due to a bug in the packaging. This
update fixes this bug and installation now works as expected. (BZ#673174)

* Building the eclipse-cdt package could fail due to an incorrect
interaction with the local file system. Interaction with the local file
system is now prevented and the build no longer fails. (BZ#678364)

* The libhover plug-in, provided by the eclipse-cdt package, used binary
data to search for hover topics. The data location was specified externally
as a URL which could cause an exception to occur on a system with no
Internet access. This update modifies the plug-in so that it pulls the
needed data from a local location. (BZ#679543)

Users of eclipse should upgrade to these updated packages, which correct
these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4647</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110568"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110586" severity="low">
    <xccdf:title>RHSA-2011:0586: libguestfs security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libguestfs is a library for accessing and modifying guest disk images.

libguestfs relied on the format auto-detection in QEMU rather than
allowing the guest image file format to be specified. A privileged guest
user could potentially use this flaw to read arbitrary files on the host
that were accessible to a user on that host who was running a program that
utilized the libguestfs library. (CVE-2010-3851)

This erratum upgrades libguestfs to upstream version 1.7.17, which includes
a number of bug fixes and one enhancement. Documentation for these bug
fixes and this enhancement is provided in the Technical Notes document,
linked to in the References section.

All libguestfs users are advised to upgrade to these updated packages,
which correct this issue, and fix the bugs and add the enhancement noted
in the Technical Notes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0586</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3851</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110586"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110599" severity="low">
    <xccdf:title>RHSA-2011:0599: sudo security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the sudo password checking logic. In configurations
where the sudoers settings allowed a user to run a command using sudo with
only the group ID changed, sudo failed to prompt for the user's password
before running the specified command with the elevated group privileges.
(CVE-2011-0010)

This update also fixes the following bugs:

* When the "/etc/sudoers" file contained entries with multiple hosts,
running the "sudo -l" command incorrectly reported that a certain user does
not have permissions to use sudo on the system. With this update, running
the "sudo -l" command now produces the correct output. (BZ#603823)

* Prior to this update, the manual page for sudoers.ldap was not installed,
even though it contains important information on how to set up an LDAP
(Lightweight Directory Access Protocol) sudoers source, and other documents
refer to it. With this update, the manual page is now properly included in
the package. Additionally, various POD files have been removed from the
package, as they are required for build purposes only. (BZ#634159)

* The previous version of sudo did not use the same location for the LDAP
configuration files as the nss_ldap package. This has been fixed and sudo
now looks for these files in the same location as the nss_ldap package.
(BZ#652726)

* When a file was edited using the "sudo -e file" or the "sudoedit file"
command, the editor being executed for this task was logged only as
"sudoedit". With this update, the full path to the executable being used as
an editor is now logged (instead of "sudoedit"). (BZ#665131)

* A comment regarding the "visiblepw" option of the "Defaults" directive
has been added to the default "/etc/sudoers" file to clarify its usage.
(BZ#688640)

* This erratum upgrades sudo to upstream version 1.7.4p5, which provides a
number of bug fixes and enhancements over the previous version. (BZ#615087)

All users of sudo are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0010</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110599"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110600" severity="medium">
    <xccdf:title>RHSA-2011:0600: dovecot security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server for Linux, UNIX, and similar operating systems,
primarily written with security in mind.

A flaw was found in the way Dovecot handled SIGCHLD signals. If a large
amount of IMAP or POP3 session disconnects caused the Dovecot master
process to receive these signals rapidly, it could cause the master process
to crash. (CVE-2010-3780)

A flaw was found in the way Dovecot processed multiple Access Control Lists
(ACL) defined for a mailbox. In some cases, Dovecot could fail to apply the
more specific ACL entry, possibly resulting in more access being granted to
the user than intended. (CVE-2010-3707)

This update also adds the following enhancement:

* This erratum upgrades Dovecot to upstream version 2.0.9, providing
multiple fixes for the "dsync" utility and improving overall performance.
Refer to the "/usr/share/doc/dovecot-2.0.9/ChangeLog" file after installing
this update for further information about the changes. (BZ#637056)

Users of dovecot are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement. After installing the updated
packages, the dovecot service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3780</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110600"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110616" severity="low">
    <xccdf:title>RHSA-2011:0616: pidgin security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Marius Wachtler as the original reporter.

This update also fixes the following bugs:

* Previous versions of the pidgin package did not properly clear certain
data structures used in libpurple/cipher.c when attempting to free them.
Partial information could potentially be extracted from the incorrectly
cleared regions of the previously freed memory. With this update, data
structures are properly cleared when freed. (BZ#684685)

* This erratum upgrades Pidgin to upstream version 2.7.9. For a list of all
changes addressed in this upgrade, refer to
http://developer.pidgin.im/wiki/ChangeLog (BZ#616917)

* Some incomplete translations for the kn_IN and ta_IN locales have been
corrected. (BZ#633860, BZ#640170)

Users of pidgin should upgrade to these updated packages, which resolve
these issues. Pidgin must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4922</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110616"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110677" severity="medium">
    <xccdf:title>RHSA-2011:0677: openssl security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A buffer over-read flaw was discovered in the way OpenSSL parsed the
Certificate Status Request TLS extensions in ClientHello TLS handshake
messages. A remote attacker could possibly use this flaw to crash an SSL
server using the affected OpenSSL functionality. (CVE-2011-0014)

This update fixes the following bugs:

* The "openssl speed" command (which provides algorithm speed measurement)
failed when openssl was running in FIPS (Federal Information Processing
Standards) mode, even if testing of FIPS approved algorithms was requested.
FIPS mode disables ciphers and cryptographic hash algorithms that are not
approved by the NIST (National Institute of Standards and Technology)
standards. With this update, the "openssl speed" command no longer fails.
(BZ#619762)

* The "openssl pkcs12 -export" command failed to export a PKCS#12 file in
FIPS mode. The default algorithm for encrypting a certificate in the
PKCS#12 file was not FIPS approved and thus did not work. The command now
uses a FIPS approved algorithm by default in FIPS mode. (BZ#673453)

This update also adds the following enhancements:

* The "openssl s_server" command, which previously accepted connections
only over IPv4, now accepts connections over IPv6. (BZ#601612)

* For the purpose of allowing certain maintenance commands to be run (such
as "rsync"), an "OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW" environment variable
has been added. When a system is configured for FIPS mode and is in a
maintenance state, this newly added environment variable can be set to
allow software that requires the use of an MD5 cryptographic hash algorithm
to be run, even though the hash algorithm is not approved by the FIPS-140-2
standard. (BZ#673071)

Users of OpenSSL are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add these
enhancements. For the update to take effect, all services linked to the
OpenSSL library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0014</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110677"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110779" severity="medium">
    <xccdf:title>RHSA-2011:0779: avahi security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zero Configuration Networking. It facilitates service
discovery on a local network. Avahi and Avahi-aware applications allow you
to plug your computer into a network and, with no configuration, view other
people to chat with, view printers to print to, and find shared files on
other computers.

A flaw was found in the way the Avahi daemon (avahi-daemon) processed
Multicast DNS (mDNS) packets with an empty payload. An attacker on the
local network could use this flaw to cause avahi-daemon on a target system
to enter an infinite loop via an empty mDNS UDP packet. (CVE-2011-1002)

This update also fixes the following bug:

* Previously, the avahi packages in Red Hat Enterprise Linux 6 were not
compiled with standard RPM CFLAGS; therefore, the Stack Protector and
Fortify Source protections were not enabled, and the debuginfo packages did
not contain the information required for debugging. This update corrects
this issue by using proper CFLAGS when compiling the packages. (BZ#629954,
BZ#684276)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the update,
avahi-daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1002</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110779"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110791" severity="medium">
    <xccdf:title>RHSA-2011:0791: tomcat6 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that web applications could modify the location of the Tomcat
host's work directory. As web applications deployed on Tomcat have read and
write access to this directory, a malicious web application could use this
flaw to trick Tomcat into giving it read and write access to an arbitrary
directory on the file system. (CVE-2010-3718)

A cross-site scripting (XSS) flaw was found in the Manager application,
used for managing web applications on Tomcat. If a remote attacker could
trick a user who is logged into the Manager application into visiting a
specially-crafted URL, the attacker could perform Manager application tasks
with the privileges of the logged in user. (CVE-2010-4172)

A second cross-site scripting (XSS) flaw was found in the Manager
application. A malicious web application could use this flaw to conduct an
XSS attack, leading to arbitrary web script execution with the privileges
of victims who are logged into and viewing Manager application web pages.
(CVE-2011-0013)

This update also fixes the following bugs:

* A bug in the "tomcat6" init script prevented additional Tomcat instances
from starting. As well, running "service tomcat6 start" caused
configuration options applied from "/etc/sysconfig/tomcat6" to be
overwritten with those from "/etc/tomcat6/tomcat6.conf". With this update,
multiple instances of Tomcat run as expected. (BZ#636997)

* The "/usr/share/java/" directory was missing a symbolic link to the
"/usr/share/tomcat6/bin/tomcat-juli.jar" library. Because this library was
mandatory for certain operations (such as running the Jasper JSP
precompiler), the "build-jar-repository" command was unable to compose a
valid classpath. With this update, the missing symbolic link has been
added. (BZ#661244)

* Previously, the "tomcat6" init script failed to start Tomcat with a "This
account is currently not available." message when Tomcat was configured to
run under a user that did not have a valid shell configured as a login
shell. This update modifies the init script to work correctly regardless of
the daemon user's login shell. Additionally, these new tomcat6 packages now
set "/sbin/nologin" as the login shell for the "tomcat" user upon
installation, as recommended by deployment best practices. (BZ#678671)

* Some standard Tomcat directories were missing write permissions for the
"tomcat" group, which could cause certain applications to fail with errors
such as "No output folder". This update adds write permissions for the
"tomcat" group to the affected directories. (BZ#643809)

* The "/usr/sbin/tomcat6" wrapper script used a hard-coded path to the
"catalina.out" file, which may have caused problems (such as for logging
init script output) if Tomcat was being run with a user other than "tomcat"
and with CATALINA_BASE set to a directory other than the default.
(BZ#695284, BZ#697504)

* Stopping Tomcat could have resulted in traceback errors being logged to
"catalina.out" when certain web applications were deployed. (BZ#698624)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0013</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110791"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110833" severity="high">
    <xccdf:title>RHSA-2011:0833: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw in the dccp_rcv_state_process() function could allow a remote
attacker to cause a denial of service, even when the socket was already
closed. (CVE-2011-1093, Important)

* Multiple buffer overflow flaws were found in the Linux kernel's
Management Module Support for Message Passing Technology (MPT) based
controllers. A local, unprivileged user could use these flaws to cause a
denial of service, an information leak, or escalate their privileges.
(CVE-2011-1494, CVE-2011-1495, Important)

* A missing validation of a null-terminated string data structure element
in the bnep_sock_ioctl() function could allow a local user to cause an
information leak or a denial of service. (CVE-2011-1079, Moderate)

* Missing error checking in the way page tables were handled in the Xen
hypervisor implementation could allow a privileged guest user to cause the
host, and the guests, to lock up. (CVE-2011-1166, Moderate)

* A flaw was found in the way the Xen hypervisor implementation checked for
the upper boundary when getting a new event channel port. A privileged
guest user could use this flaw to cause a denial of service or escalate
their privileges. (CVE-2011-1763, Moderate)

* The start_code and end_code values in "/proc/[pid]/stat" were not
protected. In certain scenarios, this flaw could be used to defeat Address
Space Layout Randomization (ASLR). (CVE-2011-0726, Low)

* A missing initialization flaw in the sco_sock_getsockopt() function could
allow a local, unprivileged user to cause an information leak.
(CVE-2011-1078, Low)

* A missing validation of a null-terminated string data structure element
in the do_replace() function could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1080, Low)

* A buffer overflow flaw in the DEC Alpha OSF partition implementation in
the Linux kernel could allow a local attacker to cause an information leak
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1163, Low)

* Missing validations of null-terminated string data structure elements in
the do_replace(), compat_do_replace(), do_ipt_get_ctl(), do_ip6t_get_ctl(),
and do_arpt_get_ctl() functions could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1170,
CVE-2011-1171, CVE-2011-1172, Low)

* A heap overflow flaw in the Linux kernel's EFI GUID Partition Table (GPT)
implementation could allow a local attacker to cause a denial of service
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1577, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1494 and
CVE-2011-1495; Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1078,
CVE-2011-1080, CVE-2011-1170, CVE-2011-1171, and CVE-2011-1172; Kees Cook
for reporting CVE-2011-0726; and Timo Warns for reporting CVE-2011-1163
and CVE-2011-1577.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0726</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1495</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1763</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110833"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110836" severity="high">
    <xccdf:title>RHSA-2011:0836: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer underflow flaw, leading to a buffer overflow, was found in the
Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
This could allow a remote attacker to cause a denial of service.
(CVE-2011-1770, Important)

* Missing sanity checks were found in setup_arg_pages() in the Linux
kernel. When making the size of the argument and environment area on the
stack very large, it could trigger a BUG_ON(), resulting in a local denial
of service. (CVE-2010-3858, Moderate)

* A missing validation check was found in the bcm_release() and
raw_release() functions in the Linux kernel's Controller Area Network (CAN)
implementation. This could allow a local, unprivileged user to cause a
denial of service. (CVE-2011-1598, CVE-2011-1748, Moderate)

* The fix for Red Hat Bugzilla bug 656461, as provided in RHSA-2011:0542,
introduced a regression in the cifs_close() function in the Linux kernel's
Common Internet File System (CIFS) implementation. A local, unprivileged
user with write access to a CIFS file system could use this flaw to cause a
denial of service. (CVE-2011-1771, Moderate)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1770; Brad
Spengler for reporting CVE-2010-3858; and Oliver Hartkopp for reporting
CVE-2011-1748.

This update also fixes various bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1770</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1771</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110836"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110837" severity="medium">
    <xccdf:title>RHSA-2011:0837: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's Microsoft Windows Bitmap (BMP) and Personal Computer
eXchange (PCX) image file plug-ins. An attacker could create a
specially-crafted BMP or PCX image file that, when opened, could cause the
relevant plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2009-1570, CVE-2011-1178)

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Sphere Designer
image filter. An attacker could create a specially-crafted Sphere Designer
filter configuration file that, when opened, could cause the Sphere
Designer plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2010-4541)

Red Hat would like to thank Stefan Cornelius of Secunia Research for
responsibly reporting the CVE-2009-1570 flaw.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1570</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1178</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110837"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110838" severity="medium">
    <xccdf:title>RHSA-2011:0838: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's Microsoft Windows Bitmap (BMP) and Personal Computer
eXchange (PCX) image file plug-ins. An attacker could create a
specially-crafted BMP or PCX image file that, when opened, could cause the
relevant plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2009-1570, CVE-2011-1178)

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Lightning,
Sphere Designer, and Gfig image filters. An attacker could create a
specially-crafted Lightning, Sphere Designer, or Gfig filter configuration
file that, when opened, could cause the relevant plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)

Red Hat would like to thank Stefan Cornelius of Secunia Research for
responsibly reporting the CVE-2009-1570 flaw.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-1570</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1178</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110838"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110839" severity="medium">
    <xccdf:title>RHSA-2011:0839: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Lightning,
Sphere Designer, and Gfig image filters. An attacker could create a
specially-crafted Lightning, Sphere Designer, or Gfig filter configuration
file that, when opened, could cause the relevant plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4543</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110839"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110841" severity="medium">
    <xccdf:title>RHSA-2011:0841: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

A divide-by-zero flaw was found in the way SystemTap handled malformed
debugging information in DWARF format. When SystemTap unprivileged mode was
enabled, an unprivileged user in the stapusr group could use this flaw to
crash the system. Additionally, a privileged user (root, or a member of the
stapdev group) could trigger this flaw when tricked into instrumenting a
specially-crafted ELF binary, even when unprivileged mode was not enabled.
(CVE-2011-1769)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0841</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1769</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110841"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110842" severity="medium">
    <xccdf:title>RHSA-2011:0842: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

Two divide-by-zero flaws were found in the way SystemTap handled malformed
debugging information in DWARF format. When SystemTap unprivileged mode was
enabled, an unprivileged user in the stapusr group could use these flaws to
crash the system. Additionally, a privileged user (root, or a member of the
stapdev group) could trigger these flaws when tricked into instrumenting a
specially-crafted ELF binary, even when unprivileged mode was not enabled.
(CVE-2011-1769, CVE-2011-1781)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1769</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1781</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110842"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110843" severity="medium">
    <xccdf:title>RHSA-2011:0843: postfix security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A heap-based buffer over-read flaw was found in the way Postfix performed
SASL handlers management for SMTP sessions, when Cyrus SASL authentication
was enabled. A remote attacker could use this flaw to cause the Postfix
smtpd server to crash via a specially-crafted SASL authentication request.
The smtpd process was automatically restarted by the postfix master process
after the time configured with service_throttle_time elapsed.
(CVE-2011-1720)

Note: Cyrus SASL authentication for Postfix is not enabled by default.

Red Hat would like to thank the CERT/CC for reporting this issue. Upstream
acknowledges Thomas Jarosch of Intra2net AG as the original reporter.

Users of Postfix are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the postfix service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1720</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110843"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110844" severity="low">
    <xccdf:title>RHSA-2011:0844: apr security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It provides a free library of C data
structures and routines.

The fix for CVE-2011-0419 (released via RHSA-2011:0507) introduced an
infinite loop flaw in the apr_fnmatch() function when the APR_FNM_PATHNAME
matching flag was used. A remote attacker could possibly use this flaw to
cause a denial of service on an application using the apr_fnmatch()
function. (CVE-2011-1928)

Note: This problem affected httpd configurations using the "Location"
directive with wildcard URLs. The denial of service could have been
triggered during normal operation; it did not specifically require a
malicious HTTP request.

This update also addresses additional problems introduced by the rewrite of
the apr_fnmatch() function, which was necessary to address the
CVE-2011-0419 flaw.

All apr users should upgrade to these updated packages, which contain a
backported patch to correct this issue. Applications using the apr library,
such as httpd, must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1928</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110844"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110845" severity="high">
    <xccdf:title>RHSA-2011:0845: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

An off-by-one flaw was found in the way BIND processed negative responses
with large resource record sets (RRSets). An attacker able to send
recursive queries to a BIND server that is configured as a caching
resolver could use this flaw to cause named to exit with an assertion
failure. (CVE-2011-1910)

All BIND users are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1910</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110845"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110856" severity="high">
    <xccdf:title>RHSA-2011:0856: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Integer overflow flaws were found in the way Java2D parsed JPEG images and
user-supplied fonts. An attacker could use these flaws to execute arbitrary
code with the privileges of the user running an untrusted applet or
application. (CVE-2011-0862)

It was found that the MediaTracker implementation created Component
instances with unnecessary access privileges. A remote attacker could use
this flaw to elevate their privileges by utilizing an untrusted applet or
application that uses Swing. (CVE-2011-0871)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), resulting in an applet or application crashing. (CVE-2011-0864)

An information leak flaw was found in the NetworkInterface class. An
untrusted applet or application could use this flaw to access information
about available network interfaces that should only be available to
privileged code. (CVE-2011-0867)

An incorrect float-to-long conversion, leading to an overflow, was found
in the way certain objects (such as images and text) were transformed in
Java2D. A remote attacker could use this flaw to crash an untrusted applet
or application that uses Java2D. (CVE-2011-0868)

It was found that untrusted applets and applications could misuse a SOAP
connection to incorrectly set global HTTP proxy settings instead of
setting them in a local scope. This flaw could be used to intercept HTTP
requests. (CVE-2011-0869)

A flaw was found in the way signed objects were deserialized. If trusted
and untrusted code were running in the same Java Virtual Machine (JVM), and
both were deserializing the same signed object, the untrusted code could
modify said object by using this flaw to bypass the validation checks on
signed objects. (CVE-2011-0865)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0856</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110856"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110857" severity="high">
    <xccdf:title>RHSA-2011:0857: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Integer overflow flaws were found in the way Java2D parsed JPEG images and
user-supplied fonts. An attacker could use these flaws to execute arbitrary
code with the privileges of the user running an untrusted applet or
application. (CVE-2011-0862)

It was found that the MediaTracker implementation created Component
instances with unnecessary access privileges. A remote attacker could use
this flaw to elevate their privileges by utilizing an untrusted applet or
application that uses Swing. (CVE-2011-0871)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), resulting in an applet or application crashing. (CVE-2011-0864)

An information leak flaw was found in the NetworkInterface class. An
untrusted applet or application could use this flaw to access information
about available network interfaces that should only be available to
privileged code. (CVE-2011-0867)

An incorrect float-to-long conversion, leading to an overflow, was found
in the way certain objects (such as images and text) were transformed in
Java2D. A remote attacker could use this flaw to crash an untrusted applet
or application that uses Java2D. (CVE-2011-0868)

It was found that untrusted applets and applications could misuse a SOAP
connection to incorrectly set global HTTP proxy settings instead of
setting them in a local scope. This flaw could be used to intercept HTTP
requests. (CVE-2011-0869)

A flaw was found in the way signed objects were deserialized. If trusted
and untrusted code were running in the same Java Virtual Machine (JVM), and
both were deserializing the same signed object, the untrusted code could
modify said object by using this flaw to bypass the validation checks on
signed objects. (CVE-2011-0865)

Note: All of the above flaws can only be remotely triggered in OpenJDK by
calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which provide OpenJDK 6 b20 / IcedTea 1.9.8 and resolve these
issues. All running instances of OpenJDK Java must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0857</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110857"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110858" severity="medium">
    <xccdf:title>RHSA-2011:0858: xerces-j2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.

A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. Applications using the Apache Xerces2 Java
Parser must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2625</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110858"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110859" severity="medium">
    <xccdf:title>RHSA-2011:0859: cyrus-imapd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

It was discovered that cyrus-imapd did not flush the received commands
buffer after switching to TLS encryption for IMAP, LMTP, NNTP, and POP3
sessions. A man-in-the-middle attacker could use this flaw to inject
protocol commands into a victim's TLS session initialization messages. This
could lead to those commands being processed by cyrus-imapd, potentially
allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-1926)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the update, cyrus-imapd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0859</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1926</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110859"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110861" severity="medium">
    <xccdf:title>RHSA-2011:0861: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed requests submitted against the URL of a baselined resource. A
malicious, remote user could use this flaw to cause the httpd process
serving the request to crash. (CVE-2011-1752)

Red Hat would like to thank the Apache Subversion project for reporting
this issue. Upstream acknowledges Joe Schaefer of the Apache Software
Foundation as the original reporter.

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1752</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110861"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110862" severity="medium">
    <xccdf:title>RHSA-2011:0862: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

An infinite loop flaw was found in the way the mod_dav_svn module processed
certain data sets. If the SVNPathAuthz directive was set to
"short_circuit", and path-based access control for files and directories
was enabled, a malicious, remote user could use this flaw to cause the
httpd process serving the request to consume an excessive amount of system
memory. (CVE-2011-1783)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed requests submitted against the URL of a baselined resource. A
malicious, remote user could use this flaw to cause the httpd process
serving the request to crash. (CVE-2011-1752)

An information disclosure flaw was found in the way the mod_dav_svn
module processed certain URLs when path-based access control for files and
directories was enabled. A malicious, remote user could possibly use this
flaw to access certain files in a repository that would otherwise not be
accessible to them. Note: This vulnerability cannot be triggered if the
SVNPathAuthz directive is set to "short_circuit". (CVE-2011-1921)

Red Hat would like to thank the Apache Subversion project for reporting
these issues. Upstream acknowledges Joe Schaefer of the Apache Software
Foundation as the original reporter of CVE-2011-1752; Ivan Zhakov of
VisualSVN as the original reporter of CVE-2011-1783; and Kamesh
Jayachandran of CollabNet, Inc. as the original reporter of CVE-2011-1921.

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1921</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110862"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110871" severity="medium">
    <xccdf:title>RHSA-2011:0871: tigervnc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Virtual Network Computing (VNC) is a remote display system which allows you
to view a computer's desktop environment not only on the machine where it
is running, but from anywhere on the Internet and from a wide variety of
machine architectures. TigerVNC is a suite of VNC servers and clients.

It was discovered that vncviewer could prompt for and send authentication
credentials to a remote server without first properly validating the
server's X.509 certificate. As vncviewer did not indicate that the
certificate was bad or missing, a man-in-the-middle attacker could use this
flaw to trick a vncviewer client into connecting to a spoofed VNC server,
allowing the attacker to obtain the client's credentials. (CVE-2011-1775)

All tigervnc users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1775</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110871"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110885" severity="high">
    <xccdf:title>RHSA-2011:0885: firefox security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox handled malformed JPEG images. A
website containing a malicious JPEG image could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Firefox. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2011-0083, CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375,
CVE-2011-2376)

An integer overflow flaw was found in the way Firefox handled JavaScript
Array objects. A website containing malicious JavaScript could cause
Firefox to execute that JavaScript with the privileges of the user running
Firefox. (CVE-2011-2371)

A use-after-free flaw was found in the way Firefox handled malformed
JavaScript. A website containing malicious JavaScript could cause Firefox
to execute that JavaScript with the privileges of the user running Firefox.
(CVE-2011-2373)

It was found that Firefox could treat two separate cookies as
interchangeable if both were for the same domain name but one of those
domain names had a trailing "." character. This violates the same-origin
policy and could possibly lead to data being leaked to the wrong domain.
(CVE-2011-2362)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.18. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bug:

* With previous versions of Firefox on Red Hat Enterprise Linux 5, the
"background-repeat" CSS (Cascading Style Sheets) property did not work
(such images were not displayed and repeated as expected). (BZ#698313)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.18, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2371</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2605</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110885"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110886" severity="high">
    <xccdf:title>RHSA-2011:0886: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Thunderbird. Malicious HTML
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0083,
CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375, CVE-2011-2376)

It was found that Thunderbird could treat two separate cookies (for web
content) as interchangeable if both were for the same domain name but one
of those domain names had a trailing "." character. This violates the
same-origin policy and could possibly lead to data being leaked to the
wrong domain. (CVE-2011-2362)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0886</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2605</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110886"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110887" severity="high">
    <xccdf:title>RHSA-2011:0887: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Thunderbird. Malicious HTML
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0083,
CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375, CVE-2011-2376)

An integer overflow flaw was found in the way Thunderbird handled
JavaScript Array objects. Malicious content could cause Thunderbird to
execute JavaScript with the privileges of the user running Thunderbird.
(CVE-2011-2371)

A use-after-free flaw was found in the way Thunderbird handled malformed
JavaScript. Malicious content could cause Thunderbird to execute JavaScript
with the privileges of the user running Thunderbird. (CVE-2011-2373)

It was found that Thunderbird could treat two separate cookies (for web
content) as interchangeable if both were for the same domain name but one
of those domain names had a trailing "." character. This violates the
same-origin policy and could possibly lead to data being leaked to the
wrong domain. (CVE-2011-2362)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0887</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2371</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2605</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110887"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110888" severity="high">
    <xccdf:title>RHSA-2011:0888: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled malformed JPEG images. A
website containing a malicious JPEG image could cause SeaMonkey to crash
or, potentially, execute arbitrary code with the privileges of the user
running SeaMonkey. (CVE-2011-2377)

Multiple dangling pointer flaws were found in SeaMonkey. A web page
containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-0083, CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375,
CVE-2011-2376)

An integer overflow flaw was found in the way SeaMonkey handled JavaScript
Array objects. A website containing malicious JavaScript could cause
SeaMonkey to execute that JavaScript with the privileges of the user
running SeaMonkey. (CVE-2011-2371)

A use-after-free flaw was found in the way SeaMonkey handled malformed
JavaScript. A website containing malicious JavaScript could cause SeaMonkey
to execute that JavaScript with the privileges of the user running
SeaMonkey. (CVE-2011-2373)

It was found that SeaMonkey could treat two separate cookies as
interchangeable if both were for the same domain name but one of those
domain names had a trailing "." character. This violates the same-origin
policy and could possibly lead to data being leaked to the wrong domain.
(CVE-2011-2362)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0888</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2365</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2371</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2605</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110888"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110908" severity="medium">
    <xccdf:title>RHSA-2011:0908: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

It was found that WEBrick (the Ruby HTTP server toolkit) did not filter
terminal escape sequences from its log files. A remote attacker could use
specially-crafted HTTP requests to inject terminal escape sequences into
the WEBrick log files. If a victim viewed the log files with a terminal
emulator, it could result in control characters being executed with the
privileges of that user. (CVE-2009-4492)

A cross-site scripting (XSS) flaw was found in the way WEBrick displayed
error pages. A remote attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted URL. (CVE-2010-0541)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 and CVE-2010-0541 issues.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1005</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110908"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110909" severity="medium">
    <xccdf:title>RHSA-2011:0909: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

A race condition flaw was found in the remove system entries method in the
FileUtils module. If a local user ran a Ruby script that uses this method,
a local attacker could use this flaw to delete arbitrary files and
directories accessible to that user via a symbolic link attack.
(CVE-2011-1004)

It was found that WEBrick (the Ruby HTTP server toolkit) did not filter
terminal escape sequences from its log files. A remote attacker could use
specially-crafted HTTP requests to inject terminal escape sequences into
the WEBrick log files. If a victim viewed the log files with a terminal
emulator, it could result in control characters being executed with the
privileges of that user. (CVE-2009-4492)

A cross-site scripting (XSS) flaw was found in the way WEBrick displayed
error pages. A remote attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted URL. (CVE-2010-0541)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 and CVE-2010-0541 issues.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0909</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1005</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110909"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110910" severity="medium">
    <xccdf:title>RHSA-2011:0910: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

A race condition flaw was found in the remove system entries method in the
FileUtils module. If a local user ran a Ruby script that uses this method,
a local attacker could use this flaw to delete arbitrary files and
directories accessible to that user via a symbolic link attack.
(CVE-2011-1004)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 issue.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1005</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110910"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110918" severity="medium">
    <xccdf:title>RHSA-2011:0918: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

It was found that cURL always performed credential delegation when
authenticating with GSSAPI. A rogue server could use this flaw to obtain
the client's credentials and impersonate that client to other servers that
are using GSSAPI. (CVE-2011-2192)

Users of curl should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0918</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2192</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110918"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110919" severity="high">
    <xccdf:title>RHSA-2011:0919: qemu-kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that the virtio subsystem in qemu-kvm did not properly
validate virtqueue in and out requests from the guest. A privileged guest
user could use this flaw to trigger a buffer overflow, allowing them to
crash the guest (denial of service) or, possibly, escalate their privileges
on the host. (CVE-2011-2212)

It was found that the virtio_queue_notify() function in qemu-kvm did not
perform sufficient input validation on the value later used as an index
into the array of virtqueues. An unprivileged guest user could use this
flaw to crash the guest (denial of service) or, possibly, escalate their
privileges on the host. (CVE-2011-2512)

Red Hat would like to thank Nelson Elhage for reporting CVE-2011-2212.

This update also fixes the following bug:

* A bug was found in the way vhost (in qemu-kvm) set up mappings with the
host kernel's vhost module. This could result in the host kernel's vhost
module not having a complete view of a guest system's memory, if that guest
had more than 4 GB of memory. Consequently, hot plugging a vhost-net
network device and restarting the guest may have resulted in that device no
longer working. (BZ#701771)

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2512</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110919"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110920" severity="high">
    <xccdf:title>RHSA-2011:0920: krb5-appl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The krb5-appl packages provide Kerberos-aware telnet, ftp, rcp, rsh, and
rlogin clients and servers. While these have been replaced by tools such as
OpenSSH in most environments, they remain in use in others.

It was found that gssftp, a Kerberos-aware FTP server, did not properly
drop privileges. A remote FTP user could use this flaw to gain unauthorized
read or write access to files that are owned by the root group.
(CVE-2011-1526)

Red Hat would like to thank the MIT Kerberos project for reporting this
issue. Upstream acknowledges Tim Zingelman as the original reporter.

All krb5-appl users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0920</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1526</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110920"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110926" severity="high">
    <xccdf:title>RHSA-2011:0926: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS requests. A
remote attacker could use this flaw to send a specially-crafted DNS request
packet to BIND, causing it to exit unexpectedly due to a failed assertion.
(CVE-2011-2464)

Users of bind97 on Red Hat Enterprise Linux 5, and bind on Red Hat
Enterprise Linux 6, are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2464</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110926"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110927" severity="high">
    <xccdf:title>RHSA-2011:0927: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer overflow flaw in ib_uverbs_poll_cq() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-4649, Important)

* A race condition in the way new InfiniBand connections were set up could
allow a remote user to cause a denial of service. (CVE-2011-0695,
Important)

* A flaw in the Stream Control Transmission Protocol (SCTP) implementation
could allow a remote attacker to cause a denial of service if the sysctl
"net.sctp.addip_enable" variable was turned on (it is off by default).
(CVE-2011-1573, Important)

* Flaws in the AGPGART driver implementation when handling certain IOCTL
commands could allow a local, unprivileged user to cause a denial of
service or escalate their privileges. (CVE-2011-1745, CVE-2011-2022,
Important)

* An integer overflow flaw in agp_allocate_memory() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2011-1746, Important)

* A flaw allowed napi_reuse_skb() to be called on VLAN (virtual LAN)
packets. An attacker on the local network could trigger this flaw by
sending specially-crafted packets to a target system, possibly causing a
denial of service. (CVE-2011-1576, Moderate)

* An integer signedness error in next_pidmap() could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-1593, Moderate)

* A flaw in the way the Xen hypervisor implementation handled CPUID
instruction emulation during virtual machine exits could allow an
unprivileged guest user to crash a guest. This only affects systems that
have an Intel x86 processor with the Intel VT-x extension enabled.
(CVE-2011-1936, Moderate)

* A flaw in inet_diag_bc_audit() could allow a local, unprivileged user to
cause a denial of service (infinite loop). (CVE-2011-2213, Moderate)

* A missing initialization flaw in the XFS file system implementation
could lead to an information leak. (CVE-2011-0711, Low)

* A flaw in ib_uverbs_poll_cq() could allow a local, unprivileged user to
cause an information leak. (CVE-2011-1044, Low)

* A missing validation check was found in the signals implementation. A
local, unprivileged user could use this flaw to send signals via the
sigqueueinfo system call, with the si_code set to SI_TKILL and with spoofed
process and user IDs, to other processes. Note: This flaw does not allow
existing permission checks to be bypassed; signals can only be sent if your
privileges allow you to already do so. (CVE-2011-1182, Low)

* A heap overflow flaw in the EFI GUID Partition Table (GPT) implementation
could allow a local attacker to cause a denial of service by mounting a
disk containing specially-crafted partition tables. (CVE-2011-1776, Low)

* Structure padding in two structures in the Bluetooth implementation
was not initialized properly before being copied to user-space, possibly
allowing local, unprivileged users to leak kernel stack memory to
user-space. (CVE-2011-2492, Low)

Red Hat would like to thank Jens Kuehnel for reporting CVE-2011-0695;
Vasiliy Kulikov for reporting CVE-2011-1745, CVE-2011-2022, and
CVE-2011-1746; Ryan Sweat for reporting CVE-2011-1576; Robert Swiecki for
reporting CVE-2011-1593; Dan Rosenberg for reporting CVE-2011-2213 and
CVE-2011-0711; Julien Tinnes of the Google Security Team for reporting
CVE-2011-1182; Timo Warns for reporting CVE-2011-1776; and Marek Kroemeke
and Filip Palian for reporting CVE-2011-2492.

Bug fix documentation will be available shortly from the Technical Notes
document linked to in the References.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0927</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4649</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1745</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1936</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110927"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110928" severity="medium">
    <xccdf:title>RHSA-2011:0928: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the receive hook in the ipip_init() function in the
ipip module, and in the ipgre_init() function in the ip_gre module, could
be called before network namespaces setup is complete. If packets were
received at the time the ipip or ip_gre module was still being loaded into
the kernel, it could cause a denial of service. (CVE-2011-1767,
CVE-2011-1768, Moderate)

* It was found that an mmap() call with the MAP_PRIVATE flag on "/dev/zero"
would create transparent hugepages and trigger a certain robustness check.
A local, unprivileged user could use this flaw to cause a denial of
service. (CVE-2011-2479, Moderate)

This update also fixes various bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0928</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2479</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110928"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110930" severity="medium">
    <xccdf:title>RHSA-2011:0930: NetworkManager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

It was found that NetworkManager did not properly enforce PolicyKit
settings controlling the permissions to configure wireless network sharing.
A local, unprivileged user could use this flaw to bypass intended PolicyKit
restrictions, allowing them to enable wireless network sharing.
(CVE-2011-2176)

Users of NetworkManager should upgrade to these updated packages, which
contain a backported patch to correct this issue. Running instances of
NetworkManager must be restarted ("service NetworkManager restart") for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0930</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2176</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110930"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110953" severity="medium">
    <xccdf:title>RHSA-2011:0953: system-config-firewall security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>system-config-firewall is a graphical user interface for basic firewall
setup.

It was found that system-config-firewall used the Python pickle module in
an insecure way when sending data (via D-Bus) to the privileged back-end
mechanism. A local user authorized to configure firewall rules using
system-config-firewall could use this flaw to execute arbitrary code with
root privileges, by sending a specially-crafted serialized object.
(CVE-2011-2520)

Red Hat would like to thank Marco Slaviero of SensePost for reporting this
issue.

This erratum updates system-config-firewall to use JSON (JavaScript Object
Notation) for data exchange, instead of pickle. Therefore, an updated
version of system-config-printer that uses this new communication data
format is also provided in this erratum.

Users of system-config-firewall are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. Running
instances of system-config-firewall must be restarted before the utility
will be able to communicate with its updated back-end.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0953</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2520</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110953"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110959" severity="medium">
    <xccdf:title>RHSA-2011:0959: mutt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt verified SSL certificates. When a server
presented an SSL certificate chain, Mutt could ignore a server hostname
check failure. A remote attacker able to get a certificate from a trusted
Certificate Authority could use this flaw to trick Mutt into accepting a
certificate issued for a different hostname, and perform man-in-the-middle
attacks against Mutt's SSL connections. (CVE-2011-1429)

All Mutt users should upgrade to this updated package, which contains a
backported patch to correct this issue. All running instances of Mutt must
be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1429</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110959"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110975" severity="low">
    <xccdf:title>RHSA-2011:0975: sssd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.

A flaw was found in the SSSD PAM responder that could allow a local
attacker to force SSSD to enter an infinite loop via a carefully-crafted
packet. With SSSD unresponsive, legitimate users could be denied the
ability to log in to the system. (CVE-2010-4341)

Red Hat would like to thank Sebastian Krahmer for reporting this issue.

These updated sssd packages include a number of bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Refer to
the Red Hat Enterprise Linux 5.7 Technical Notes for information about
these changes:

https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.7_Technical_Notes/sssd.html#RHSA-2011-0975

All sssd users are advised to upgrade to these updated sssd packages, which
upgrade SSSD to upstream version 1.5.1 to correct this issue, and fix the
bugs and add the enhancements noted in the Technical Notes.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4341</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110975"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20110999" severity="medium">
    <xccdf:title>RHSA-2011:0999: rsync security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>rsync is a program for synchronizing files over a network.

A flaw was found in the way the rsync daemon handled the "filter",
"exclude", and "exclude from" options, used for hiding files and preventing
access to them from rsync clients. A remote attacker could use this flaw to
bypass those restrictions by using certain command line options and
symbolic links, allowing the attacker to overwrite those files if they knew
their file names and had write access to them. (CVE-2007-6200)

Note: This issue only affected users running rsync as a writable daemon:
"read only" set to "false" in the rsync configuration file (for example,
"/etc/rsyncd.conf"). By default, this option is set to "true".

This update also fixes the following bugs:

* The rsync package has been upgraded to upstream version 3.0.6, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#339971)

* When running an rsync daemon that was receiving files, a deferred info,
error or log message could have been sent directly to the sender instead of
being handled by the "rwrite()" function in the generator. Also, under
certain circumstances, a deferred info or error message from the receiver
could have bypassed the log file and could have been sent only to the
client process. As a result, an "unexpected tag 3" fatal error could have
been displayed. These problems have been fixed in this update so that an
rsync daemon receiving files now works as expected. (BZ#471182)

* Prior to this update, the rsync daemon called a number of timezone-using
functions after doing a chroot. As a result, certain C libraries were
unable to generate proper timestamps from inside a chrooted daemon. This
bug has been fixed in this update so that the rsync daemon now calls the
respective timezone-using functions prior to doing a chroot, and proper
timestamps are now generated as expected. (BZ#575022)

* When running rsync under a non-root user with the "-A" ("--acls") option
and without using the "--numeric-ids" option, if there was an Access
Control List (ACL) that included a group entry for a group that the
respective user was not a member of on the receiving side, the
"acl_set_file()" function returned an invalid argument value ("EINVAL").
This was caused by rsync mistakenly mapping the group name to the Group ID
"GID_NONE" ("-1"), which failed. The bug has been fixed in this update so
that no invalid argument is returned and rsync works as expected.
(BZ#616093)

* When creating a sparse file that was zero blocks long, the "rsync
--sparse" command did not properly truncate the sparse file at the end of
the copy transaction. As a result, the file size was bigger than expected.
This bug has been fixed in this update by properly truncating the file so
that rsync now copies such files as expected. (BZ#530866)

* Under certain circumstances, when using rsync in daemon mode, rsync
generator instances could have entered an infinitive loop, trying to write
an error message for the receiver to an invalid socket. This problem has
been fixed in this update by adding a new sibling message: when the
receiver is reporting a socket-read error, the generator will notice this
fact and avoid writing an error message down the socket, allowing it to
close down gracefully when the pipe from the receiver closes. (BZ#690148)

* Prior to this update, there were missing deallocations found in the
"start_client()" function. This bug has been fixed in this update and no
longer occurs. (BZ#700450)

All users of rsync are advised to upgrade to this updated package, which
resolves these issues and adds enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:0999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20110999"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111000" severity="low">
    <xccdf:title>RHSA-2011:1000: rgmanager security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rgmanager package contains the Red Hat Resource Group Manager, which
provides the ability to create and manage high-availability server
applications in the event of system downtime.

It was discovered that certain resource agent scripts set the
LD_LIBRARY_PATH environment variable to an insecure value containing empty
path elements. A local user able to trick a user running those scripts to
run them while working from an attacker-writable directory could use this
flaw to escalate their privileges via a specially-crafted dynamic library.
(CVE-2010-3389)

Red Hat would like to thank Raphael Geissert for reporting this issue.

This update also fixes the following bugs:

* The failover domain "nofailback" option was not honored if a service was
in the "starting" state. This bug has been fixed. (BZ#669440)

* PID files with white spaces in the file name are now handled correctly.
(BZ#632704)

* The /usr/sbin/rhev-check.sh script can now be used from within Cron.
(BZ#634225)

* The clustat utility now reports the correct version. (BZ#654160)

* The oracledb.sh agent now attempts to try the "shutdown immediate"
command instead of using the "shutdown abort" command. (BZ#633992)

* The SAPInstance and SAPDatabase scripts now use proper directory name
quoting so they no longer collide with directory names like "/u".
(BZ#637154)

* The clufindhostname utility now returns the correct value in all cases.
(BZ#592613)

* The nfsclient resource agent now handles paths with trailing slashes
correctly. (BZ#592624)

* The last owner of a service is now reported correctly after a failover.
(BZ#610483)

* The /usr/share/cluster/fs.sh script no longer runs the "quotaoff" command
if quotas were not configured. (BZ#637678)

* The "listen" line in the /etc/httpd/conf/httpd.conf file generated by the
Apache resource agent is now correct. (BZ#675739)

* The tomcat-5 resource agent no longer generates incorrect configurations.
(BZ#637802)

* The time required to stop an NFS resource when the server is unavailable
has been reduced. (BZ#678494)

* When using exclusive prioritization, a higher priority service now
preempts a lower priority service after status check failures. (BZ#680256)

* The postgres-8 resource agent now correctly detects failed start
operations. (BZ#663827)

* The handling of reference counts passed by rgmanager to resource agents
now works properly, as expected. (BZ#692771)

As well, this update adds the following enhancements:

* It is now possible to disable updates to static routes by the IP resource
agent. (BZ#620700)

* It is now possible to use XFS as a file system within a cluster service.
(BZ#661893)

* It is now possible to use the "clustat" command as a non-root user, so
long as that user is in the "root" group. (BZ#510300)

* It is now possible to migrate virtual machines when central processing is
enabled. (BZ#525271)

* The rgmanager init script will now delay after stopping services in order
to allow time for other nodes to restart them. (BZ#619468)

* The handling of failed independent subtrees has been corrected.
(BZ#711521)

All users of Red Hat Resource Group Manager are advised to upgrade to this
updated package, which contains backported patches to correct these issues
and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3389</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111000"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111005" severity="low">
    <xccdf:title>RHSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sysstat package contains a set of utilities which enable system
monitoring of disks, network, and other I/O activity.

It was found that the sysstat initscript created a temporary file in an
insecure way. A local attacker could use this flaw to create arbitrary
files via a symbolic link attack. (CVE-2007-3852)

This update fixes the following bugs:

* On systems under heavy load, the sadc utility would sometimes output the
following error message if a write() call was unable to write all of the
requested input:

"Cannot write data to system activity file: Success."

In this updated package, the sadc utility tries to write the remaining
input, resolving this issue. (BZ#454617)

* On the Itanium architecture, the "sar -I" command provided incorrect
information about the interrupt statistics of the system. With this update,
the "sar -I" command has been disabled for this architecture, preventing
this bug. (BZ#468340)

* Previously, the "iostat -n" command used invalid data to create
statistics for read and write operations. With this update, the data source
for these statistics has been fixed, and the iostat utility now returns
correct information. (BZ#484439)

* The "sar -d" command used to output invalid data about block devices.
With this update, the sar utility recognizes disk registration and disk
overflow statistics properly, and only correct and relevant data is now
displayed. (BZ#517490)

* Previously, the sar utility set the maximum number of days to be logged
in one month too high. Consequently, data from a month was appended to
data from the preceding month. With this update, the maximum number of days
has been set to 25, and data from a month now correctly replaces data from
the preceding month. (BZ#578929)

* In previous versions of the iostat utility, the number of NFS mount
points was hard-coded. Consequently, various issues occurred while iostat
was running and NFS mount points were mounted or unmounted; certain values
in iostat reports overflowed and some mount points were not reported at
all. With this update, iostat properly recognizes when an NFS mount point
mounts or unmounts, fixing these issues. (BZ#675058, BZ#706095, BZ#694767)

* When a device name was longer than 13 characters, the iostat utility
printed a redundant new line character, making its output less readable.
This bug has been fixed and now, no extra characters are printed if a long
device name occurs in iostat output. (BZ#604637)

* Previously, if kernel interrupt counters overflowed, the sar utility
provided confusing output. This bug has been fixed and the sum of
interrupts is now reported correctly. (BZ#622557)

* When some processors were disabled on a multi-processor system, the sar
utility sometimes failed to provide information about the CPU activity.
With this update, the uptime of a single processor is used to compute the
statistics, rather than the total uptime of all processors, and this bug no
longer occurs. (BZ#630559)

* Previously, the mpstat utility wrongly interpreted data about processors
in the system. Consequently, it reported a processor that did not exist.
This bug has been fixed and non-existent CPUs are no longer reported by
mpstat. (BZ#579409)

* Previously, there was no easy way to enable the collection of statistics
about disks and interrupts. Now, the SADC_OPTIONS variable can be used to
set parameters for the sadc utility, fixing this bug. (BZ#598794)

* The read_uptime() function failed to close its open file upon exit. A
patch has been provided to fix this bug. (BZ#696672)

This update also adds the following enhancement:

* With this update, the cifsiostat utility has been added to the sysstat
package to provide CIFS (Common Internet File System) mount point I/O
statistics. (BZ#591530)

All sysstat users are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-3852</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111005"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111019" severity="medium">
    <xccdf:title>RHSA-2011:1019: libvirt security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.

An integer overflow flaw was found in libvirtd's RPC call handling. An
attacker able to establish read-only connections to libvirtd could trigger
this flaw by calling virDomainGetVcpus() with specially-crafted parameters,
causing libvirtd to crash. (CVE-2011-2511)

This update fixes the following bugs:

* libvirt was rebased from version 0.6.3 to version 0.8.2 in Red Hat
Enterprise Linux 5.6. A code audit found a minor API change that effected
error messages seen by libvirt 0.8.2 clients talking to libvirt 0.7.1 –
0.7.7 (0.7.x) servers. A libvirt 0.7.x server could send
VIR_ERR_BUILD_FIREWALL errors where a libvirt 0.8.2 client expected
VIR_ERR_CONFIG_UNSUPPORTED errors. In other circumstances, a libvirt 0.8.2
client saw a "Timed out during operation" message where it should see an
"Invalid network filter" error. This update adds a backported patch that
allows libvirt 0.8.2 clients to interoperate with the API as used by
libvirt 0.7.x servers, ensuring correct error messages are sent.
(BZ#665075)

* libvirt could crash if the maximum number of open file descriptors
(_SC_OPEN_MAX) grew larger than the FD_SETSIZE value because it accessed
file descriptors outside the bounds of the set. With this update the
maximum number of open file descriptors can no longer grow larger than the
FD_SETSIZE value. (BZ#665549)

* A libvirt race condition was found. An array in the libvirt event
handlers was accessed with a lock temporarily released. In rare cases, if
one thread attempted to access this array but a second thread reallocated
the array before the first thread reacquired a lock, it could lead to the
first thread attempting to access freed memory, potentially causing libvirt
to crash. With this update libvirt no longer refers to the old array and,
consequently, behaves as expected. (BZ#671569)

* Guests connected to a passthrough NIC would kernel panic if a
system_reset signal was sent through the QEMU monitor. With this update you
can reset such guests as expected. (BZ#689880)

* When using the Xen kernel, the rpmbuild command failed on the xencapstest
test. With this update you can run rpmbuild successfully when using the Xen
kernel. (BZ#690459)

* When a disk was hot unplugged, "ret &gt;= 0" was passed to the qemuAuditDisk
calls in disk hotunplug operations before ret was, in fact, set to 0. As
well, the error path jumped to the "cleanup" label prematurely. As a
consequence, hotunplug failures were not audited and hotunplug successes
were audited as failures. This was corrected and hot unplugging checks now
behave as expected. (BZ#710151)

* A conflict existed between filter update locking sequences and virtual
machine startup locking sequences. When a filter update occurred on one or
more virtual machines, a deadlock could consequently occur if a virtual
machine referencing a filter was started. This update changes and makes
more flexible several qemu locking sequences ensuring this deadlock no
longer occurs. (BZ#697749)

* qemudDomainSaveImageStartVM closed some incoming file descriptor (fd)
arguments without informing the caller. The consequent double-closes could
cause Domain restoration failure. This update alters the
qemudDomainSaveImageStartVM signature to prevent the double-closes.
(BZ#681623)

This update also adds the following enhancements:

* The libvirt Xen driver now supports more than one serial port.
(BZ#670789)

* Enabling and disabling the High Precision Event Timer (HPET) in Xen
domains is now possible. (BZ#703193)

All libvirt users should install this update which addresses this
vulnerability, fixes these bugs and adds these enhancements. After
installing the updated packages, libvirtd must be restarted ("service
libvirtd restart") for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2511</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111019"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111065" severity="high">
    <xccdf:title>RHSA-2011:1065: Red Hat Enterprise Linux 5.7 kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Xen hypervisor implementation handled
instruction emulation during virtual machine exits. A malicious user-space
process running in an SMP guest could trick the emulator into reading a
different instruction than the one that caused the virtual machine to exit.
An unprivileged guest user could trigger this flaw to crash the host. This
only affects systems with both an AMD x86 processor and the AMD
Virtualization (AMD-V) extensions enabled. (CVE-2011-1780, Important)

* A flaw allowed the tc_fill_qdisc() function in the Linux kernel's packet
scheduler API implementation to be called on built-in qdisc structures. A
local, unprivileged user could use this flaw to trigger a NULL pointer
dereference, resulting in a denial of service. (CVE-2011-2525, Moderate)

* A flaw was found in the way space was allocated in the Linux kernel's
Global File System 2 (GFS2) implementation. If the file system was almost
full, and a local, unprivileged user made an fallocate() request, it could
result in a denial of service. Note: Setting quotas to prevent users from
using all available disk space would prevent exploitation of this flaw.
(CVE-2011-2689, Moderate)

These updated kernel packages include a number of bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Refer to the Red Hat Enterprise Linux 5.7 Technical Notes for
information about the most significant bug fixes and enhancements included
in this update:

https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.7_Technical_Notes/kernel.html#RHSA-2011-1065

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2689</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111065"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111073" severity="low">
    <xccdf:title>RHSA-2011:1073: bash security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Bash is the default shell for Red Hat Enterprise Linux.

It was found that certain scripts bundled with the Bash documentation
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files accessible to the victim running the
scripts. (CVE-2008-5374)

This update fixes the following bugs:

* When using the source builtin at location ".", occasionally, bash
opted to preserve internal consistency and abort scripts. This caused
bash to abort scripts that assigned values to read-only variables.
This is now fixed to ensure that such scripts are now executed as
written and not aborted. (BZ#448508)

* When the tab key was pressed for auto-completion options for the typed
text, the cursor moved to an unexpected position on a previous line if
the prompt contained characters that cannot be viewed and a "\]". This
is now fixed to retain the cursor at the expected position at the end of
the target line after autocomplete options correctly display. (BZ#463880)

* Bash attempted to interpret the NOBITS .dynamic section of the ELF
header. This resulted in a "^D: bad ELF interpreter: No such
file or directory" message. This is fixed to ensure that the invalid
"^D" does not appear in the error message. (BZ#484809)

* The $RANDOM variable in Bash carried over values from a previous
execution for later jobs. This is fixed and the $RANDOM variable
generates a new random number for each use. (BZ#492908)

* When Bash ran a shell script with an embedded null character, bash's
source builtin parsed the script incorrectly. This is fixed and
bash's source builtin correctly parses shell script null characters.
(BZ#503701)

* The bash manual page for "trap" did not mention that signals ignored upon
entry cannot be listed later. The manual page was updated for this update
and now specifically notes that "Signals ignored upon entry to the shell
cannot be trapped, reset or listed". (BZ#504904)

* Bash's readline incorrectly displayed additional text when resizing
the terminal window when text spanned more than one line, which caused
incorrect display output. This is now fixed to ensure that text in more
than one line in a resized window displays as expected. (BZ#525474)

* Previously, bash incorrectly displayed "Broken pipe" messages for
builtins like "echo" and "printf" when output did not succeed due to
EPIPE. This is fixed to ensure that the unnecessary "Broken pipe"
messages no longer display. (BZ#546529)

* Inserts with the repeat function were not possible after a deletion in
vi-mode. This has been corrected and, with this update, the repeat function
works as expected after a deletion. (BZ#575076)

* In some situations, bash incorrectly appended "/" to files instead of
just directories during tab-completion, causing incorrect
auto-completions. This is fixed and auto-complete appends "/" only to
directories. (BZ#583919)

* Bash had a memory leak in the "read" builtin when the number of fields
being read was not equal to the number of variables passed as arguments,
causing a shell script crash. This is fixed to prevent a memory leak and
shell script crash. (BZ#618393)

* /usr/share/doc/bash-3.2/loadables in the bash package contained source
files which would not build due to missing C header files. With this
update, the unusable (and unbuildable) source files were removed from the
package. (BZ#663656)

This update also adds the following enhancement:

* The system-wide "/etc/bash.bash_logout" bash logout file is now enabled.
This allows administrators to write system-wide logout actions for all
users. (BZ#592979)

Users of bash are advised to upgrade to this updated package, which
contains backported patches to resolve these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-5374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111073"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111083" severity="medium">
    <xccdf:title>RHSA-2011:1083: fuse security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FUSE (Filesystem in Userspace) can implement a fully functional file system
in a user-space program. These packages provide the mount utility,
fusermount, the tool used to mount FUSE file systems.

Multiple flaws were found in the way fusermount handled the mounting and
unmounting of directories when symbolic links were present. A local user in
the fuse group could use these flaws to unmount file systems, which they
would otherwise not be able to unmount and that were not mounted using
FUSE, via a symbolic link attack. (CVE-2010-3879, CVE-2011-0541,
CVE-2011-0542, CVE-2011-0543)

Note: The util-linux-ng RHBA-2011:0699 update must also be installed to
fully correct the above flaws.

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3879</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0543</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111083"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111084" severity="medium">
    <xccdf:title>RHSA-2011:1084: libsndfile security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libsndfile packages provide a library for reading and writing sound
files.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the libsndfile library processed certain Ensoniq PARIS
Audio Format (PAF) audio files. An attacker could create a
specially-crafted PAF file that, when opened, could cause an application
using libsndfile to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-2696)

Users of libsndfile are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using libsndfile must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111084"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111085" severity="high">
    <xccdf:title>RHSA-2011:1085: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

A flaw was found in the way the FreeType font rendering engine processed
certain PostScript Type 1 fonts. If a user loaded a specially-crafted font
file with an application linked against FreeType, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-0226)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0226</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111085"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111088" severity="medium">
    <xccdf:title>RHSA-2011:1088: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

It was found that SystemTap did not perform proper module path sanity
checking if a user specified a custom path to the uprobes module, used
when performing user-space probing ("staprun -u"). A local user who is a
member of the stapusr group could use this flaw to bypass intended
module-loading restrictions, allowing them to escalate their privileges by
loading an arbitrary, unsigned module. (CVE-2011-2502)

A race condition flaw was found in the way the staprun utility performed
module loading. A local user who is a member of the stapusr group could
use this flaw to modify a signed module while it is being loaded,
allowing them to escalate their privileges. (CVE-2011-2503)

SystemTap users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2503</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111088"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111089" severity="medium">
    <xccdf:title>RHSA-2011:1089: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

A race condition flaw was found in the way the staprun utility performed
module loading. A local user who is a member of the stapusr group could use
this flaw to modify a signed module while it is being loaded, allowing them
to escalate their privileges. (CVE-2011-2503)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2503</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111089"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111100" severity="medium">
    <xccdf:title>RHSA-2011:1100: icedtea-web security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

A flaw was discovered in the JNLP (Java Network Launching Protocol)
implementation in IcedTea-Web. An unsigned Java Web Start application
could use this flaw to manipulate the content of a Security Warning
dialog box, to trick a user into granting the application unintended access
permissions to local files. (CVE-2011-2514)

An information disclosure flaw was discovered in the JNLP implementation in
IcedTea-Web. An unsigned Java Web Start application or Java applet could
use this flaw to determine the path to the cache directory used to store
downloaded Java class and archive files, and therefore determine the user's
login name. (CVE-2011-2513)

All icedtea-web users should upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2514</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111100"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111102" severity="medium">
    <xccdf:title>RHSA-2011:1102: libsoup security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libsoup is an HTTP client/library implementation for GNOME.

A directory traversal flaw was found in libsoup's SoupServer. If an
application used SoupServer to implement an HTTP service, a remote attacker
who is able to connect to that service could use this flaw to access any
local files accessible to that application via a specially-crafted request.
(CVE-2011-2524)

All users of libsoup should upgrade to these updated packages, which
contain a backported patch to resolve this issue. All running applications
using libsoup's SoupServer must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2524</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111102"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111103" severity="medium">
    <xccdf:title>RHSA-2011:1103: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain a backported patch to correct this issue. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1103</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2692</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111103"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111104" severity="medium">
    <xccdf:title>RHSA-2011:1104: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A buffer overflow flaw was found in the way libpng processed certain PNG
image files. An attacker could create a specially-crafted PNG image that,
when opened, could cause an application using libpng to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-2690)

Note: The application behavior required to exploit CVE-2011-2690 is rarely
used. No application shipped with Red Hat Enterprise Linux behaves this
way, for example.

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
libpng must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1104</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2692</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111104"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111105" severity="medium">
    <xccdf:title>RHSA-2011:1105: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A buffer overflow flaw was found in the way libpng processed certain PNG
image files. An attacker could create a specially-crafted PNG image that,
when opened, could cause an application using libpng to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-2690)

Note: The application behavior required to exploit CVE-2011-2690 is rarely
used. No application shipped with Red Hat Enterprise Linux behaves this
way, for example.

An out-of-bounds memory read flaw was found in the way libpng processed
certain PNG image files. An attacker could create a specially-crafted PNG
image that, when opened, could cause an application using libpng to crash.
(CVE-2011-2501)

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng should upgrade to these updated packages, which upgrade
libpng to version 1.2.46 to correct these issues. All running applications
using libpng must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2692</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111105"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111109" severity="medium">
    <xccdf:title>RHSA-2011:1109: foomatic security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Foomatic is a comprehensive, spooler-independent database of printers,
printer drivers, and driver descriptions. The package also includes
spooler-independent command line interfaces to manipulate queues and to
print files and manipulate print jobs. foomatic-rip is a print filter
written in Perl.

An input sanitization flaw was found in the foomatic-rip print filter. An
attacker could submit a print job with the username, title, or job options
set to appear as a command line option that caused the filter to use a
specified PostScript printer description (PPD) file, rather than the
administrator-set one. This could lead to arbitrary code execution with the
privileges of the "lp" user. (CVE-2011-2697)

All foomatic users should upgrade to this updated package, which contains
a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1109</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2697</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111109"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111110" severity="medium">
    <xccdf:title>RHSA-2011:1110: foomatic security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Foomatic is a comprehensive, spooler-independent database of printers,
printer drivers, and driver descriptions. The package also includes
spooler-independent command line interfaces to manipulate queues and to
print files and manipulate print jobs. foomatic-rip is a print filter
written in C.

An input sanitization flaw was found in the foomatic-rip print filter. An
attacker could submit a print job with the username, title, or job options
set to appear as a command line option that caused the filter to use a
specified PostScript printer description (PPD) file, rather than the
administrator-set one. This could lead to arbitrary code execution with the
privileges of the "lp" user. (CVE-2011-2964)

All foomatic users should upgrade to this updated package, which contains
a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1110</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111110"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111132" severity="medium">
    <xccdf:title>RHSA-2011:1132: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial of service flaw was found in the way the D-Bus library handled
endianness conversion when receiving messages. A local user could use this
flaw to send a specially-crafted message to dbus-daemon or to a service
using the bus, such as Avahi or NetworkManager, possibly causing the
daemon to exit or the service to disconnect from the bus. (CVE-2011-2200)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111154" severity="high">
    <xccdf:title>RHSA-2011:1154: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A buffer overflow flaw was found in the way the libXfont library, used by
the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to potentially
execute arbitrary code with the privileges of the X.Org server.
(CVE-2011-2895)

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2895</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111155" severity="high">
    <xccdf:title>RHSA-2011:1155: xorg-x11 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon. These xorg-x11 packages also provide the
X.Org libXfont runtime library.

A buffer overflow flaw was found in the way the libXfont library, used by
the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to potentially
execute arbitrary code with the privileges of the X.Org server.
(CVE-2011-2895)

Users of xorg-x11 should upgrade to these updated packages, which contain
a backported patch to resolve this issue. All running X.Org server
instances must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2895</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111155"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111160" severity="medium">
    <xccdf:title>RHSA-2011:1160: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

Two denial of service flaws were found in the way the dhcpd daemon handled
certain incomplete request packets. A remote attacker could use these flaws
to crash dhcpd via a specially-crafted request. (CVE-2011-2748,
CVE-2011-2749)

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing this update, all
DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2749</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111160"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111161" severity="medium">
    <xccdf:title>RHSA-2011:1161: freetype security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2 font
engines.

A buffer overflow flaw was found in the way the FreeType library handled
malformed font files compressed using UNIX compress. If a user loaded a
specially-crafted compressed font file with an application linked against
FreeType, it could cause the application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2011-2895)

Note: This issue only affects the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1161</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2895</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111161"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111163" severity="high">
    <xccdf:title>RHSA-2011:1163: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update includes backported fixes for two security issues. These issues
only affected users of Red Hat Enterprise Linux 5.6 Extended Update
Support, as they have already been addressed for users of Red Hat
Enterprise Linux 5 in the 5.7 update, RHSA-2011:1065.

This update fixes the following security issues:

* A flaw was found in the way the Xen hypervisor implementation handled
instruction emulation during virtual machine exits. A malicious user-space
process running in an SMP guest could trick the emulator into reading a
different instruction than the one that caused the virtual machine to exit.
An unprivileged guest user could trigger this flaw to crash the host. This
only affects systems with both an AMD x86 processor and the AMD
Virtualization (AMD-V) extensions enabled. (CVE-2011-1780, Important)

* A flaw allowed the tc_fill_qdisc() function in the Linux kernel's packet
scheduler API implementation to be called on built-in qdisc structures. A
local, unprivileged user could use this flaw to trigger a NULL pointer
dereference, resulting in a denial of service. (CVE-2011-2525, Moderate)

This update also fixes the following bugs:

* A bug was found in the way the x86_emulate() function handled the IMUL
instruction in the Xen hypervisor. On systems without support for hardware
assisted paging (HAP), such as those running CPUs that do not have support
for (or those that have it disabled) Intel Extended Page Tables (EPT) or
AMD Virtualization (AMD-V) Rapid Virtualization Indexing (RVI), this bug
could cause fully-virtualized guests to crash or lead to silent memory
corruption. In reported cases, this issue occurred when booting
fully-virtualized Red Hat Enterprise Linux 6.1 guests with memory cgroups
enabled. (BZ#712884)

* A bug in the way the ibmvscsi driver handled interrupts may have
prevented automatic path recovery for multipath devices. This bug only
affected 64-bit PowerPC systems. (BZ#720929)

* The RHSA-2009:1243 update introduced a regression in the way file locking
on NFS (Network File System) was handled. This caused applications to hang
if they made a lock request on a file on an NFS version 2 or 3 file system
that was mounted with the "sec=krb5" option. With this update, the original
behavior of using mixed RPC authentication flavors for NFS and locking
requests has been restored. (BZ#722854)

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2525</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111164" severity="high">
    <xccdf:title>RHSA-2011:1164: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2982)

A dangling pointer flaw was found in the Firefox Scalable Vector Graphics
(SVG) text manipulation routine. A web page containing a malicious SVG
image could cause Firefox to crash or, potentially, execute arbitrary code
with the privileges of the user running Firefox. (CVE-2011-0084)

A dangling pointer flaw was found in the way Firefox handled a certain
Document Object Model (DOM) element. A web page containing malicious
content could cause Firefox to crash or, potentially, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2011-2378)

A flaw was found in the event management code in Firefox. A website
containing malicious JavaScript could cause Firefox to execute that
JavaScript with the privileges of the user running Firefox. (CVE-2011-2981)

A flaw was found in the way Firefox handled malformed JavaScript. A web
page containing malicious JavaScript could cause Firefox to access already
freed memory, causing Firefox to crash or, potentially, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2011-2983)

It was found that a malicious web page could execute arbitrary code with
the privileges of the user running Firefox if the user dropped a tab onto
the malicious web page. (CVE-2011-2984)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.20. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.20, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2984</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111165" severity="high">
    <xccdf:title>RHSA-2011:1165: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2011-2982)

A flaw was found in the way Thunderbird handled malformed JavaScript.
Malicious content could cause Thunderbird to access already freed memory,
causing Thunderbird to crash or, potentially, execute arbitrary code with
the privileges of the user running Thunderbird. (CVE-2011-2983)

Note: This update disables support for Scalable Vector Graphics (SVG)
images in Thunderbird on Red Hat Enterprise Linux 5.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2983</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111165"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111166" severity="high">
    <xccdf:title>RHSA-2011:1166: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2982)

A dangling pointer flaw was found in the Thunderbird Scalable Vector
Graphics (SVG) text manipulation routine. An HTML mail message containing a
malicious SVG image could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0084)

A dangling pointer flaw was found in the way Thunderbird handled a certain
Document Object Model (DOM) element. An HTML mail message containing
malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2378)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2982</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111167" severity="high">
    <xccdf:title>RHSA-2011:1167: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-2982)

A flaw was found in the way SeaMonkey handled malformed JavaScript. A web
page containing malicious JavaScript could cause SeaMonkey to access
already freed memory, causing SeaMonkey to crash or, potentially, execute
arbitrary code with the privileges of the user running SeaMonkey.
(CVE-2011-2983)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2983</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111167"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111187" severity="medium">
    <xccdf:title>RHSA-2011:1187: dovecot security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server for Linux, UNIX, and similar operating systems,
primarily written with security in mind.

A denial of service flaw was found in the way Dovecot handled NULL
characters in certain header names. A mail message with specially-crafted
headers could cause the Dovecot child process handling the target user's
connection to crash, blocking them from downloading the message
successfully and possibly leading to the corruption of their mailbox.
(CVE-2011-1929)

Users of dovecot are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, the dovecot service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1187</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1929</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111187"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111189" severity="high">
    <xccdf:title>RHSA-2011:1189: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Security issues:

* Using PCI passthrough without interrupt remapping support allowed KVM
guests to generate MSI interrupts and thus potentially inject traps. A
privileged guest user could use this flaw to crash the host or possibly
escalate their privileges on the host. The fix for this issue can prevent
PCI passthrough working and guests starting. Refer to Red Hat Bugzilla bug
715555 for details. (CVE-2011-1898, Important)

* Flaw in the client-side NLM implementation could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-2491, Important)

* Integer underflow in the Bluetooth implementation could allow a remote
attacker to cause a denial of service or escalate their privileges by
sending a specially-crafted request to a target system via Bluetooth.
(CVE-2011-2497, Important)

* Buffer overflows in the netlink-based wireless configuration interface
implementation could allow a local user, who has the CAP_NET_ADMIN
capability, to cause a denial of service or escalate their privileges on
systems that have an active wireless interface. (CVE-2011-2517, Important)

* Flaw in the way the maximum file offset was handled for ext4 file systems
could allow a local, unprivileged user to cause a denial of service.
(CVE-2011-2695, Important)

* Flaw allowed napi_reuse_skb() to be called on VLAN packets. An attacker
on the local network could use this flaw to send crafted packets to a
target, possibly causing a denial of service. (CVE-2011-1576, Moderate)

* Integer signedness error in next_pidmap() could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-1593, Moderate)

* Race condition in the memory merging support (KSM) could allow a local,
unprivileged user to cause a denial of service. KSM is off by default, but
on systems running VDSM, or on KVM hosts, it is likely turned on by the
ksm/ksmtuned services. (CVE-2011-2183, Moderate)

* Flaw in inet_diag_bc_audit() could allow a local, unprivileged user to
cause a denial of service. (CVE-2011-2213, Moderate)

* Flaw in the way space was allocated in the Global File System 2 (GFS2)
implementation. If the file system was almost full, and a local,
unprivileged user made an fallocate() request, it could result in a denial
of service. Setting quotas to prevent users from using all available disk
space would prevent exploitation of this flaw. (CVE-2011-2689, Moderate)

* Local, unprivileged users could send signals via the sigqueueinfo system
call, with si_code set to SI_TKILL and with spoofed process and user IDs,
to other processes. This flaw does not allow existing permission checks to
be bypassed; signals can only be sent if your privileges allow you to
already do so. (CVE-2011-1182, Low)

* Heap overflow in the EFI GUID Partition Table (GPT) implementation could
allow a local attacker to cause a denial of service by mounting a disk
containing crafted partition tables. (CVE-2011-1776, Low)

* Structure padding in two structures in the Bluetooth implementation was
not initialized properly before being copied to user-space, possibly
allowing local, unprivileged users to leak kernel stack memory to
user-space. (CVE-2011-2492, Low)

* /proc/[PID]/io is world-readable by default. Previously, these files
could be read without any further restrictions. A local, unprivileged user
could read these files, belonging to other, possibly privileged processes
to gather confidential information, such as the length of a password used
in a process. (CVE-2011-2495, Low)

Red Hat would like to thank Vasily Averin for reporting CVE-2011-2491; Dan
Rosenberg for reporting CVE-2011-2497 and CVE-2011-2213; Ryan Sweat for
reporting CVE-2011-1576; Robert Swiecki for reporting CVE-2011-1593; Andrea
Righi for reporting CVE-2011-2183; Julien Tinnes of the Google Security
Team for reporting CVE-2011-1182; Timo Warns for reporting CVE-2011-1776;
Marek Kroemeke and Filip Palian for reporting CVE-2011-2492; and Vasiliy
Kulikov of Openwall for reporting CVE-2011-2495.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2495</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2695</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111189"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111196" severity="medium">
    <xccdf:title>RHSA-2011:1196: system-config-printer security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>system-config-printer is a print queue configuration tool with a graphical
user interface.

It was found that system-config-printer did not properly sanitize NetBIOS
and workgroup names when searching for network printers. A remote attacker
could use this flaw to execute arbitrary code with the privileges of the
user running system-config-printer. (CVE-2011-2899)

All users of system-config-printer are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. Running
instances of system-config-printer must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2899</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111196"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111197" severity="medium">
    <xccdf:title>RHSA-2011:1197: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

An integer overflow flaw was found in libvirtd's RPC call handling. An
attacker able to establish read-only connections to libvirtd could trigger
this flaw by calling virDomainGetVcpus() with specially-crafted parameters,
causing libvirtd to crash. (CVE-2011-2511)

This update also fixes the following bugs:

* Previously, when the "virsh vol-create-from" command was run on an LVM
(Logical Volume Manager) storage pool, performance of the command was very
low and the operation consumed an excessive amount of time. This bug has
been fixed in the virStorageVolCreateXMLFrom() function, and the
performance problem of the command no longer occurs.

* Due to a regression, libvirt used undocumented command line options,
instead of the recommended ones. Consequently, the qemu-img utility used an
invalid argument while creating an encrypted volume, and the process
eventually failed. With this update, the bug in the backing format of the
storage back end has been fixed, and encrypted volumes can now be created
as expected. (BZ#726617)

* Due to a bug in the qemuAuditDisk() function, hot unplug failures were
never audited, and a hot unplug success was audited as a failure. This bug
has been fixed, and auditing of disk hot unplug operations now works as
expected. (BZ#728516)

* Previously, when a debug process was being activated, the act of
preparing a debug message ended up with dereferencing a UUID (universally
unique identifier) prior to the NULL argument check. Consequently, an API
running the debug process sometimes terminated with a segmentation fault.
With this update, a patch has been provided to address this issue, and the
crashes no longer occur in the described scenario. (BZ#728546)

* The libvirt library uses the "boot=on" option to mark which disk is
bootable but it only uses that option if Qemu advertises its support. The
qemu-kvm utility in Red Hat Enterprise Linux 6.1 removed support for that
option and libvirt could not use it. As a consequence, when an IDE disk was
added as the second storage with a virtio disk being set up as the first
one by default, the operating system tried to boot from the IDE disk rather
than the virtio disk and either failed to boot with the "No bootable disk"
error message returned, or the system booted whatever operating system was
on the IDE disk. With this update, the boot configuration is translated
into bootindex, which provides control over which device is used for
booting a guest operating system, thus fixing this bug.

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd must be restarted ("service libvirtd
restart") for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2511</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111212" severity="high">
    <xccdf:title>RHSA-2011:1212: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation. A remote attacker
could send a specially-crafted SCTP packet to a target system, resulting in
a denial of service. (CVE-2011-2482, Important)

* A flaw in the Linux kernel's client-side NFS Lock Manager (NLM)
implementation could allow a local, unprivileged user to cause a denial of
service. (CVE-2011-2491, Important)

* Buffer overflow flaws in the Linux kernel's netlink-based wireless
configuration interface implementation could allow a local user, who has
the CAP_NET_ADMIN capability, to cause a denial of service or escalate
their privileges on systems that have an active wireless interface.
(CVE-2011-2517, Important)

* A flaw was found in the way the Linux kernel's Xen hypervisor
implementation emulated the SAHF instruction. When using a
fully-virtualized guest on a host that does not use hardware assisted
paging (HAP), such as those running CPUs that do not have support for (or
those that have it disabled) Intel Extended Page Tables (EPT) or AMD
Virtualization (AMD-V) Rapid Virtualization Indexing (RVI), a privileged
guest user could trigger this flaw to cause the hypervisor to crash.
(CVE-2011-2519, Moderate)

* An off-by-one flaw was found in the __addr_ok() macro in the Linux
kernel's Xen hypervisor implementation when running on 64-bit systems. A
privileged guest user could trigger this flaw to cause the hypervisor to
crash. (CVE-2011-2901, Moderate)

* /proc/[PID]/io is world-readable by default. Previously, these files
could be read without any further restrictions. A local, unprivileged user
could read these files, belonging to other, possibly privileged processes
to gather confidential information, such as the length of a password used
in a process. (CVE-2011-2495, Low)

Red Hat would like to thank Vasily Averin for reporting CVE-2011-2491, and
Vasiliy Kulikov of Openwall for reporting CVE-2011-2495.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2495</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2901</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111212"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111219" severity="medium">
    <xccdf:title>RHSA-2011:1219: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

A race condition flaw was found in the way the mount.cifs tool mounted CIFS
(Common Internet File System) shares. If mount.cifs had the setuid bit set,
a local attacker could conduct a symbolic link attack to trick mount.cifs
into mounting a share over an arbitrary directory they were otherwise not
allowed to mount to, possibly allowing them to escalate their privileges.
(CVE-2010-0787)

It was found that the mount.cifs tool did not properly handle share or
directory names containing a newline character. If mount.cifs had the
setuid bit set, a local attacker could corrupt the mtab (mounted file
systems table) file via a specially-crafted CIFS share mount request.
(CVE-2010-0547)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the samba packages distributed by Red Hat does not
have the setuid bit set. We recommend that administrators do not manually
set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522; the Debian Security Team for reporting CVE-2010-0787;
and Dan Rosenberg for reporting CVE-2011-1678. Upstream acknowledges
Nobuhiro Tsuji of NTT DATA Security Corporation as the original reporter of
CVE-2011-2694; Yoshihiro Ishikawa of LAC Co., Ltd. as the original reporter
of CVE-2011-2522; and the Debian Security Team acknowledges Ronald Volgers
as the original reporter of CVE-2010-0787.

Users of Samba are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3585</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111219"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111220" severity="medium">
    <xccdf:title>RHSA-2011:1220: samba3x security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

It was found that the fix for CVE-2010-0547, provided by the Samba rebase
in RHBA-2011:0054, was incomplete. The mount.cifs tool did not properly
handle share or directory names containing a newline character, allowing a
local attacker to corrupt the mtab (mounted file systems table) file via a
specially-crafted CIFS (Common Internet File System) share mount request,
if mount.cifs had the setuid bit set. (CVE-2011-2724)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the samba3x packages distributed by Red Hat does not
have the setuid bit set. We recommend that administrators do not manually
set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522, and Dan Rosenberg for reporting CVE-2011-1678. Upstream
acknowledges Nobuhiro Tsuji of NTT DATA Security Corporation as the
original reporter of CVE-2011-2694, and Yoshihiro Ishikawa of LAC Co., Ltd.
as the original reporter of CVE-2011-2522.

Users of Samba are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1220</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2724</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111220"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111221" severity="medium">
    <xccdf:title>RHSA-2011:1221: samba and cifs-utils security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information. The cifs-utils package contains utilities for mounting
and managing CIFS (Common Internet File System) shares.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

It was found that the fix for CVE-2010-0547, provided in the cifs-utils
package included in the GA release of Red Hat Enterprise Linux 6, was
incomplete. The mount.cifs tool did not properly handle share or directory
names containing a newline character, allowing a local attacker to corrupt
the mtab (mounted file systems table) file via a specially-crafted CIFS
share mount request, if mount.cifs had the setuid bit set. (CVE-2011-2724)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the cifs-utils package distributed by Red Hat does
not have the setuid bit set. We recommend that administrators do not
manually set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522, and Dan Rosenberg for reporting CVE-2011-1678. Upstream
acknowledges Nobuhiro Tsuji of NTT DATA Security Corporation as the
original reporter of CVE-2011-2694, and Yoshihiro Ishikawa of LAC Co., Ltd.
as the original reporter of CVE-2011-2522.

This update also fixes the following bug:

* If plain text passwords were used ("encrypt passwords = no" in
"/etc/samba/smb.conf"), Samba clients running the Windows XP or Windows
Server 2003 operating system may not have been able to access Samba shares
after installing the Microsoft Security Bulletin MS11-043. This update
corrects this issue, allowing such clients to use plain text passwords to
access Samba shares. (BZ#728517)

Users of samba and cifs-utils are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues. After
installing this update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3585</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111221"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111240" severity="low">
    <xccdf:title>RHSA-2011:1240: Red Hat Enterprise Linux 4 - 6-Month End Of Life Notice (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111240"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111241" severity="medium">
    <xccdf:title>RHSA-2011:1241: ecryptfs-utils security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>eCryptfs is a stacked, cryptographic file system. It is transparent to the
underlying file system and provides per-file granularity. eCryptfs is
released as a Technology Preview for Red Hat Enterprise Linux 5 and 6.

The setuid mount.ecryptfs_private utility allows users to mount an eCryptfs
file system. This utility can only be run by users in the "ecryptfs" group.

A race condition flaw was found in the way mount.ecryptfs_private checked
the permissions of a requested mount point when mounting an encrypted file
system. A local attacker could possibly use this flaw to escalate their
privileges by mounting over an arbitrary directory. (CVE-2011-1831)

A race condition flaw in umount.ecryptfs_private could allow a local
attacker to unmount an arbitrary file system. (CVE-2011-1832)

It was found that mount.ecryptfs_private did not handle certain errors
correctly when updating the mtab (mounted file systems table) file,
allowing a local attacker to corrupt the mtab file and possibly unmount an
arbitrary file system. (CVE-2011-1834)

An insecure temporary file use flaw was found in the ecryptfs-setup-private
script. A local attacker could use this script to insert their own key that
will subsequently be used by a new user, possibly giving the attacker
access to the user's encrypted data if existing file permissions allow
access. (CVE-2011-1835)

A race condition flaw in mount.ecryptfs_private could allow a local
attacker to overwrite arbitrary files. (CVE-2011-1837)

A race condition flaw in the way temporary files were accessed in
mount.ecryptfs_private could allow a malicious, local user to make
arbitrary modifications to the mtab file. (CVE-2011-3145)

A race condition flaw was found in the way mount.ecryptfs_private checked
the permissions of the directory to mount. A local attacker could use this
flaw to mount (and then access) a directory they would otherwise not have
access to. Note: The fix for this issue is incomplete until a kernel-space
change is made. Future Red Hat Enterprise Linux 5 and 6 kernel updates
will correct this issue. (CVE-2011-1833)

Red Hat would like to thank the Ubuntu Security Team for reporting these
issues. The Ubuntu Security Team acknowledges Vasiliy Kulikov of Openwall
and Dan Rosenberg as the original reporters of CVE-2011-1831,
CVE-2011-1832, and CVE-2011-1833; Dan Rosenberg and Marc Deslauriers as the
original reporters of CVE-2011-1834; Marc Deslauriers as the original
reporter of CVE-2011-1835; and Vasiliy Kulikov of Openwall as the original
reporter of CVE-2011-1837.

Users of ecryptfs-utils are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1832</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3145</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111241"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111245" severity="high">
    <xccdf:title>RHSA-2011:1245: httpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

A flaw was found in the way the Apache HTTP Server handled Range HTTP
headers. A remote attacker could use this flaw to cause httpd to use an
excessive amount of memory and CPU time via HTTP requests with a
specially-crafted Range header. (CVE-2011-3192)

All httpd users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3192</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111245"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111247" severity="medium">
    <xccdf:title>RHSA-2011:1247: rsyslog security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rsyslog packages provide an enhanced, multi-threaded syslog daemon that
supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on
any message part, and fine grained output format control.

A two byte buffer overflow flaw was found in the rsyslog daemon's
parseLegacySyslogMsg function. An attacker able to submit log messages to
rsyslogd could use this flaw to crash the daemon. (CVE-2011-3200)

All rsyslog users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing this update, the
rsyslog daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111247"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111248" severity="high">
    <xccdf:title>RHSA-2011:1248: ca-certificates security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update removes that CA's root certificate from the
ca-certificates package, rendering any HTTPS certificates signed by that CA
as untrusted. (BZ#734381)

All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111248"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111264" severity="high">
    <xccdf:title>RHSA-2011:1264: gstreamer-plugins security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gstreamer-plugins packages contain plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media formats.

An integer overflow flaw, a boundary error, and multiple off-by-one flaws
were found in various ModPlug music file format library (libmodplug)
modules, embedded in GStreamer. An attacker could create specially-crafted
music files that, when played by a victim, would cause applications using
GStreamer to crash or, potentially, execute arbitrary code. (CVE-2011-2911,
CVE-2011-2912, CVE-2011-2913, CVE-2011-2914, CVE-2011-2915)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as Rhythmbox)
must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1264</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2911</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2912</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2914</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2915</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111264"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111289" severity="medium">
    <xccdf:title>RHSA-2011:1289: librsvg2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The librsvg2 packages provide an SVG (Scalable Vector Graphics) library
based on libart.

A flaw was found in the way librsvg2 parsed certain SVG files. An attacker
could create a specially-crafted SVG file that, when opened, would cause
applications that use librsvg2 (such as Eye of GNOME) to crash or,
potentially, execute arbitrary code. (CVE-2011-3146)

Red Hat would like to thank the Ubuntu Security Team for reporting this
issue. The Ubuntu Security Team acknowledges Sauli Pahlman as the original
reporter.

All librsvg2 users should upgrade to these updated packages, which contain
a backported patch to correct this issue. All running applications that use
librsvg2 must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3146</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111289"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111293" severity="medium">
    <xccdf:title>RHSA-2011:1293: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A buffer overflow flaw was found in the way Squid parsed replies from
remote Gopher servers. A remote user allowed to send Gopher requests to a
Squid proxy could possibly use this flaw to cause the squid child process
to crash or execute arbitrary code with the privileges of the squid user,
by making Squid perform a request to an attacker-controlled Gopher server.
(CVE-2011-3205)

Users of squid should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing this update, the
squid service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3205</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111293"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111294" severity="high">
    <xccdf:title>RHSA-2011:1294: httpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

A flaw was found in the way the Apache HTTP Server handled Range HTTP
headers. A remote attacker could use this flaw to cause httpd to use an
excessive amount of memory and CPU time via HTTP requests with a
specially-crafted Range header. (CVE-2011-3192)

All httpd users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1294</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3192</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111294"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111317" severity="high">
    <xccdf:title>RHSA-2011:1317: cyrus-imapd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

A buffer overflow flaw was found in the cyrus-imapd NNTP server, nntpd. A
remote user able to use the nntpd service could use this flaw to crash the
nntpd child process or, possibly, execute arbitrary code with the
privileges of the cyrus user. (CVE-2011-3208)

Red Hat would like to thank Greg Banks for reporting this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the update, cyrus-imapd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1317</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3208</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111317"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111321" severity="medium">
    <xccdf:title>RHSA-2011:1321: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel.

Security fix:

* A flaw in skb_gro_header_slow() in the Linux kernel could lead to GRO
(Generic Receive Offload) fields being left in an inconsistent state. An
attacker on the local network could use this flaw to trigger a denial of
service. (CVE-2011-2723, Moderate)

Red Hat would like to thank Brent Meshier for reporting this issue.

Bug fixes:

* When reading a file from a subdirectory in /proc/bus/pci/ while
hot-unplugging the device related to that file, the system will crash. Now,
the kernel correctly handles the simultaneous removal of a device and
access to the representation of that device in the proc file system.
(BZ#713454)

* RHSA-2011:0017 introduced a regression: Non-disk SCSI devices (except for
tape drives) such as enclosure or CD-ROM devices were hidden when attached
to a SAS based RAID controller that uses the megaraid_sas driver. With this
update, such devices are accessible, as expected. (BZ#726487)

* The fix for CVE-2010-3432 provided in RHSA-2011:0004 introduced a
regression: Information in sctp_packet_config(), which was called before
appending data chunks to a packet, was not reset, causing considerably poor
SCTP (Stream Control Transmission Protocol) performance. With this update,
the packet information is reset after transmission. (BZ#727591)

* Certain systems do not correctly set the ACPI FADT APIC mode bit. They
set the bit to "cluster" mode instead of "physical" mode which caused these
systems to boot without the TSC (Time Stamp Counter). With this update, the
ACPI FADT check has been removed due to its unreliability. (BZ#728162)

* Performance when invalidating and rereading cached data as a glock moves
around the cluster with GFS2 is improved. (BZ#729082)

* Performance issues occurred when multiple nodes attempted to call mmap()
on the same inode at the same time on a GFS2 file system, as it was using
an exclusive glock. With this update, a shared lock is used when "noatime"
is set on the mount, allowing mmap() operations to occur in parallel,
fixing this bug. Note that this issue only refers to mmap() system calls,
and not to subsequent page faults. (BZ#729090)

* Some of the functions in the GFS2 file system were not reserving enough
space for the resource group header in a transaction and for resource
groups bit blocks that get added when a memory allocation is performed.
That resulted in failed write and allocation operations. With this update,
GFS2 makes sure to reserve space in the described scenario, using the new
gfs2_rg_blocks() inline function. (BZ#729092)

* When GFS2 grew the file system, it never reread the rindex file during
the grow. This is necessary for large grows when the file system is almost
full, and GFS2 needs to use some of the space allocated earlier in the grow
to complete it. Now, if GFS2 fails to reserve the necessary space and the
rindex data is not up-to-date, it rereads it. (BZ#729094)

* Previously, when the Xen hypervisor split a 2 MB page into 4 KB pages, it
linked the new page from PDE (Page Directory Entry) before it filled
entries of the page with appropriate data. Consequently, when doing a live
migration with EPT (Extended Page Tables) enabled on a non-idle guest
running with more than two virtual CPUs, the guest often terminated
unexpectedly. With this update, the Xen hypervisor prepares the page table
entry first, and then links it in. (BZ#730684)

* Changes made to TSC as a clock source for IRQs caused virtual machines
running under the VMware ESX or ESXi hypervisors to become unresponsive
during the initial kernel boot process. With this update, the
enable_tsc_timer flag enables the do_timer_tsc_timekeeping() function to be
called in the do_timer_interrupt_hook() function, preventing a deadlock in
the timer interrupt handler. (BZ#730688)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2723</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111321"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111323" severity="medium">
    <xccdf:title>RHSA-2011:1323: qt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

A buffer overflow flaw was found in the way Qt handled certain gray-scale
image files. If a user loaded a specially-crafted gray-scale image file
with an application linked against Qt, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3194)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3194</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111324" severity="medium">
    <xccdf:title>RHSA-2011:1324: qt4 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt 4 is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A flaw in the way Qt 4 expanded certain UTF-8 characters could be used to
prevent a Qt 4 based application from properly sanitizing user input.
Depending on the application, this could allow an attacker to perform
directory traversal, or for web applications, a cross-site scripting (XSS)
attack. (CVE-2007-0242)

A buffer overflow flaw was found in the harfbuzz module in Qt 4. If a user
loaded a specially-crafted font file with an application linked against Qt
4, it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

Users of Qt 4 should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt 4 libraries must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-0242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111324"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111325" severity="medium">
    <xccdf:title>RHSA-2011:1325: evolution28-pango security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of evolution28-pango are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111325"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111326" severity="medium">
    <xccdf:title>RHSA-2011:1326: pango security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of pango are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, you must restart your system or restart the X server for the update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111326"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111327" severity="medium">
    <xccdf:title>RHSA-2011:1327: frysk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>frysk is an execution-analysis technology implemented using native Java and
C++. It provides developers and system administrators with the ability to
examine and analyze multi-host, multi-process, and multithreaded systems
while they are running. frysk is released as a Technology Preview for Red
Hat Enterprise Linux 4.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in the embedded Pango library. If a frysk application were used
to debug or trace a process that uses HarfBuzz while it loaded a
specially-crafted font file, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of frysk are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running frysk
applications must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111328" severity="medium">
    <xccdf:title>RHSA-2011:1328: qt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

A buffer overflow flaw was found in the way Qt handled certain gray-scale
image files. If a user loaded a specially-crafted gray-scale image file
with an application linked against Qt, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3194)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1328</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3194</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111328"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111338" severity="medium">
    <xccdf:title>RHSA-2011:1338: NetworkManager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times. The ifcfg-rh
NetworkManager plug-in is used in Red Hat Enterprise Linux distributions to
read and write configuration information from the
/etc/sysconfig/network-scripts/ifcfg-* files.

An input sanitization flaw was found in the way the ifcfg-rh NetworkManager
plug-in escaped network connection names containing special characters. If
PolicyKit was configured to allow local, unprivileged users to create and
save new network connections, they could create a connection with a
specially-crafted name, leading to the escalation of their privileges.
Note: By default, PolicyKit prevents unprivileged users from creating and
saving network connections. (CVE-2011-3364)

Red Hat would like to thank Matt McCutchen for reporting this issue.

Users of NetworkManager should upgrade to these updated packages, which
contain a backported patch to correct this issue. Running instances of
NetworkManager must be restarted ("service NetworkManager restart") for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3364</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111338"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111341" severity="high">
    <xccdf:title>RHSA-2011:1341: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2995)

A flaw was found in the way Firefox processed the "Enter" keypress event. A
malicious web page could present a download dialog while the key is
pressed, activating the default "Open" action. A remote attacker could
exploit this vulnerability by causing the browser to open malicious web
content. (CVE-2011-2372)

A flaw was found in the way Firefox handled Location headers in redirect
responses. Two copies of this header with different values could be a
symptom of a CRLF injection attack against a vulnerable server. Firefox now
treats two copies of the Location, Content-Length, or Content-Disposition
header as an error condition. (CVE-2011-3000)

A flaw was found in the way Firefox handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Firefox handled large
JavaScript regular expressions. A web page containing malicious JavaScript
could cause Firefox to access already freed memory, causing Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2011-2998)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.23. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.23, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111341"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111342" severity="high">
    <xccdf:title>RHSA-2011:1342: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could cause Thunderbird to
crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2995)

A flaw was found in the way Thunderbird processed the "Enter" keypress
event. A malicious HTML mail message could present a download dialog while
the key is pressed, activating the default "Open" action. A remote attacker
could exploit this vulnerability by causing the mail client to open
malicious web content. (CVE-2011-2372)

A flaw was found in the way Thunderbird handled Location headers in
redirect responses. Two copies of this header with different values could
be a symptom of a CRLF injection attack against a vulnerable server.
Thunderbird now treats two copies of the Location, Content-Length, or
Content-Disposition header as an error condition. (CVE-2011-3000)

A flaw was found in the way Thunderbird handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Thunderbird handled large
JavaScript regular expressions. An HTML mail message containing malicious
JavaScript could cause Thunderbird to access already freed memory, causing
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-2998)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111342"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111343" severity="high">
    <xccdf:title>RHSA-2011:1343: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Thunderbird handled large
JavaScript regular expressions. An HTML mail message containing malicious
JavaScript could cause Thunderbird to access already freed memory, causing
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-2998)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2999</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111343"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111344" severity="high">
    <xccdf:title>RHSA-2011:1344: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way SeaMonkey handled large
JavaScript regular expressions. A web page containing malicious JavaScript
could cause SeaMonkey to access already freed memory, causing SeaMonkey to
crash or, potentially, execute arbitrary code with the privileges of the
user running SeaMonkey. (CVE-2011-2998)
 
All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2999</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111344"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111349" severity="high">
    <xccdf:title>RHSA-2011:1349: rpm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a command line driven package management
system capable of installing, uninstalling, verifying, querying, and
updating software packages.

Multiple flaws were found in the way the RPM library parsed package
headers. An attacker could create a specially-crafted RPM package that,
when queried or installed, would cause rpm to crash or, potentially,
execute arbitrary code. (CVE-2011-3378)

Note: Although an RPM package can, by design, execute arbitrary code when
installed, this issue would allow a specially-crafted RPM package to
execute arbitrary code before its digital signature has been verified.
Package downloads from the Red Hat Network remain secure due to certificate
checks performed on the secure connection.

All RPM users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running applications linked
against the RPM library must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1349</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3378</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111349"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111350" severity="high">
    <xccdf:title>RHSA-2011:1350: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Flaws in the AGPGART driver implementation when handling certain IOCTL
commands could allow a local user to cause a denial of service or escalate
their privileges. (CVE-2011-1745, CVE-2011-2022, Important)

* An integer overflow flaw in agp_allocate_memory() could allow a local
user to cause a denial of service or escalate their privileges.
(CVE-2011-1746, Important)

* A race condition flaw was found in the Linux kernel's eCryptfs
implementation. A local attacker could use the mount.ecryptfs_private
utility to mount (and then access) a directory they would otherwise not
have access to. Note: To correct this issue, the RHSA-2011:1241
ecryptfs-utils update, which provides the user-space part of the fix, must
also be installed. (CVE-2011-1833, Moderate)

* A denial of service flaw was found in the way the taskstats subsystem
handled the registration of process exit handlers. A local, unprivileged
user could register an unlimited amount of these handlers, leading to
excessive CPU time and memory use. (CVE-2011-2484, Moderate)

* A flaw was found in the way mapping expansions were handled. A local,
unprivileged user could use this flaw to cause a wrapping condition,
triggering a denial of service. (CVE-2011-2496, Moderate)

* A flaw was found in the Linux kernel's Performance Events implementation.
It could falsely lead the NMI (Non-Maskable Interrupt) Watchdog to detect a
lockup and panic the system. A local, unprivileged user could use this flaw
to cause a denial of service (kernel panic) using the perf tool.
(CVE-2011-2521, Moderate)

* A flaw in skb_gro_header_slow() in the Linux kernel could lead to GRO
(Generic Receive Offload) fields being left in an inconsistent state. An
attacker on the local network could use this flaw to trigger a denial of
service. GRO is enabled by default in all network drivers that support it.
(CVE-2011-2723, Moderate)

* A flaw was found in the way the Linux kernel's Performance Events
implementation handled PERF_COUNT_SW_CPU_CLOCK counter overflow. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2011-2918, Moderate)

* A flaw was found in the Linux kernel's Trusted Platform Module (TPM)
implementation. A local, unprivileged user could use this flaw to leak
information to user-space. (CVE-2011-1160, Low)

* Flaws were found in the tpacket_rcv() and packet_recvmsg() functions in
the Linux kernel. A local, unprivileged user could use these flaws to leak
information to user-space. (CVE-2011-2898, Low)

Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting
CVE-2011-1745, CVE-2011-2022, CVE-2011-1746, and CVE-2011-2484; the Ubuntu
Security Team for reporting CVE-2011-1833; Robert Swiecki for reporting
CVE-2011-2496; Li Yu for reporting CVE-2011-2521; Brent Meshier for
reporting CVE-2011-2723; and Peter Huewe for reporting CVE-2011-1160. The
Ubuntu Security Team acknowledges Vasiliy Kulikov of Openwall and Dan
Rosenberg as the original reporters of CVE-2011-1833.

This update also fixes various bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1350</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1745</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2918</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111350"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111356" severity="medium">
    <xccdf:title>RHSA-2011:1356: openswan security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks.

A NULL pointer dereference flaw was found in the way Openswan's pluto IKE
daemon handled certain error conditions. A remote, unauthenticated attacker
could send a specially-crafted IKE packet that would crash the pluto
daemon. (CVE-2011-3380)

Red Hat would like to thank the Openswan project for reporting this issue.
Upstream acknowledges Paul Wouters as the original reporter.

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1356</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3380</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111356"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111359" severity="medium">
    <xccdf:title>RHSA-2011:1359: xorg-x11-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple input sanitization flaws were found in the X.Org GLX (OpenGL
extension to the X Window System) extension. A malicious, authorized client
could use these flaws to crash the X.Org server or, potentially, execute
arbitrary code with root privileges. (CVE-2010-4818)

An input sanitization flaw was found in the X.Org Render extension. A
malicious, authorized client could use this flaw to leak arbitrary memory
from the X.Org server process, or possibly crash the X.Org server.
(CVE-2010-4819)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues. All running X.Org
server instances must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1359</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4818</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4819</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111359"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111360" severity="medium">
    <xccdf:title>RHSA-2011:1360: xorg-x11 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple input sanitization flaws were found in the X.Org GLX (OpenGL
extension to the X Window System) extension. A malicious, authorized client
could use these flaws to crash the X.Org server or, potentially, execute
arbitrary code with root privileges. (CVE-2010-4818)

An input sanitization flaw was found in the X.Org Render extension. A
malicious, authorized client could use this flaw to leak arbitrary memory
from the X.Org server process, or possibly crash the X.Org server.
(CVE-2010-4819)

Users of xorg-x11 should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running X.Org server
instances must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1360</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4818</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4819</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111360"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111364" severity="medium">
    <xccdf:title>RHSA-2011:1364: kdelibs security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An
attacker could supply a specially-crafted SSL certificate (for example, via
a web page) to an application using KSSL, such as the Konqueror web
browser, causing misleading information to be presented to the user,
possibly tricking them into accepting the certificate as valid.
(CVE-2011-3365)

This update also adds the following enhancement:

* kdelibs provided its own set of trusted Certificate Authority (CA)
certificates. This update makes kdelibs use the system set from the
ca-certificates package, instead of its own copy. (BZ#743951)

Users should upgrade to these updated packages, which contain backported
patches to correct this issue and add this enhancement. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3365</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111364"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111371" severity="medium">
    <xccdf:title>RHSA-2011:1371: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted SILC message. (CVE-2011-3594)

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

Red Hat would like to thank the Pidgin project for reporting CVE-2011-1091.
Upstream acknowledges Marius Wachtler as the original reporter of
CVE-2011-1091.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1371</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3594</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111371"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111377" severity="medium">
    <xccdf:title>RHSA-2011:1377: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A signedness issue was found in the way the crypt() function in the
PostgreSQL pgcrypto module handled 8-bit characters in passwords when using
Blowfish hashing. Up to three characters immediately preceding a non-ASCII
character (one with the high bit set) had no effect on the hash result,
thus shortening the effective password length. This made brute-force
guessing more efficient as several different passwords were hashed to the
same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to applications that store user passwords, hashed
with Blowfish using the PostgreSQL crypt() function, in a back-end
PostgreSQL database. Unsafe processing can be re-enabled for specific
passwords (allowing affected users to log in) by changing their hash prefix
to "$2x$".

For Red Hat Enterprise Linux 6, the updated postgresql packages upgrade
PostgreSQL to version 8.4.9. Refer to the PostgreSQL Release Notes for a
full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

For Red Hat Enterprise Linux 4 and 5, the updated postgresql packages
contain a backported patch.

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2483</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111377"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111378" severity="medium">
    <xccdf:title>RHSA-2011:1378: postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A signedness issue was found in the way the crypt() function in the
PostgreSQL pgcrypto module handled 8-bit characters in passwords when using
Blowfish hashing. Up to three characters immediately preceding a non-ASCII
character (one with the high bit set) had no effect on the hash result,
thus shortening the effective password length. This made brute-force
guessing more efficient as several different passwords were hashed to the
same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to applications that store user passwords, hashed
with Blowfish using the PostgreSQL crypt() function, in a back-end
PostgreSQL database. Unsafe processing can be re-enabled for specific
passwords (allowing affected users to log in) by changing their hash prefix
to "$2x$".

These updated postgresql84 packages upgrade PostgreSQL to version 8.4.9.
Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2483</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111378"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111379" severity="medium">
    <xccdf:title>RHSA-2011:1379: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

Multiple NULL pointer dereference and assertion failure flaws were found
in the MIT Kerberos KDC when it was configured to use an LDAP (Lightweight
Directory Access Protocol) or Berkeley Database (Berkeley DB) back end. A
remote attacker could use these flaws to crash the KDC. (CVE-2011-1527,
CVE-2011-1528, CVE-2011-1529)

Red Hat would like to thank the MIT Kerberos project for reporting the
CVE-2011-1527 issue. Upstream acknowledges Andrej Ota as the original
reporter of CVE-2011-1527.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1379</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1529</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111379"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111380" severity="high">
    <xccdf:title>RHSA-2011:1380: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A flaw was found in the Java RMI (Remote Method Invocation) registry
implementation. A remote RMI client could use this flaw to execute
arbitrary code on the RMI server running the registry. (CVE-2011-3556)

A flaw was found in the Java RMI registry implementation. A remote RMI
client could use this flaw to execute code on the RMI server with
unrestricted privileges. (CVE-2011-3557)

A flaw was found in the IIOP (Internet Inter-Orb Protocol) deserialization
code. An untrusted Java application or applet running in a sandbox could
use this flaw to bypass sandbox restrictions by deserializing
specially-crafted input. (CVE-2011-3521)

It was found that the Java ScriptingEngine did not properly restrict the
privileges of sandboxed applications. An untrusted Java application or
applet running in a sandbox could use this flaw to bypass sandbox
restrictions. (CVE-2011-3544)

A flaw was found in the AWTKeyStroke implementation. An untrusted Java
application or applet running in a sandbox could use this flaw to bypass
sandbox restrictions. (CVE-2011-3548)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the Java2D code used to perform transformations of graphic shapes
and images. An untrusted Java application or applet running in a sandbox
could use this flaw to bypass sandbox restrictions. (CVE-2011-3551)

An insufficient error checking flaw was found in the unpacker for JAR files
in pack200 format. A specially-crafted JAR file could use this flaw to
crash the Java Virtual Machine (JVM) or, possibly, execute arbitrary code
with JVM privileges. (CVE-2011-3554)

It was found that HttpsURLConnection did not perform SecurityManager checks
in the setSSLSocketFactory method. An untrusted Java application or applet
running in a sandbox could use this flaw to bypass connection restrictions
defined in the policy. (CVE-2011-3560)

A flaw was found in the way the SSL 3 and TLS 1.0 protocols used block
ciphers in cipher-block chaining (CBC) mode. An attacker able to perform a
chosen plain text attack against a connection mixing trusted and untrusted
data could use this flaw to recover portions of the trusted data sent over
the connection. (CVE-2011-3389)

Note: This update mitigates the CVE-2011-3389 issue by splitting the first
application data record byte to a separate SSL/TLS protocol record. This
mitigation may cause compatibility issues with some SSL/TLS implementations
and can be disabled using the jsse.enableCBCProtection boolean property.
This can be done on the command line by appending the flag
"-Djsse.enableCBCProtection=false" to the java command.

An information leak flaw was found in the InputStream.skip implementation.
An untrusted Java application or applet could possibly use this flaw to
obtain bytes skipped by other threads. (CVE-2011-3547)

A flaw was found in the Java HotSpot virtual machine. An untrusted Java
application or applet could use this flaw to disclose portions of the VM
memory, or cause it to crash. (CVE-2011-3558)

The Java API for XML Web Services (JAX-WS) implementation in OpenJDK was
configured to include the stack trace in error messages sent to clients. A
remote client could possibly use this flaw to obtain sensitive information.
(CVE-2011-3553)

It was found that Java applications running with SecurityManager
restrictions were allowed to use too many UDP sockets by default. If
multiple instances of a malicious application were started at the same
time, they could exhaust all available UDP sockets on the system.
(CVE-2011-3552)

This erratum also upgrades the OpenJDK package to IcedTea6 1.9.10. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1380</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3560</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111380"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111385" severity="medium">
    <xccdf:title>RHSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs and kdelibs3 packages provide libraries for the K Desktop
Environment (KDE).

An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An
attacker could supply a specially-crafted SSL certificate (for example, via
a web page) to an application using KSSL, such as the Konqueror web
browser, causing misleading information to be presented to the user,
possibly tricking them into accepting the certificate as valid.
(CVE-2011-3365)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The desktop must be restarted (log out, then
log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3365</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111385"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111386" severity="high">
    <xccdf:title>RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* The maximum file offset handling for ext4 file systems could allow a
local, unprivileged user to cause a denial of service. (CVE-2011-2695,
Important)

* IPv6 fragment identification value generation could allow a remote
attacker to disrupt a target system's networking, preventing legitimate
users from accessing its services. (CVE-2011-2699, Important)

* A malicious CIFS (Common Internet File System) server could send a
specially-crafted response to a directory read request that would result in
a denial of service or privilege escalation on a system that has a CIFS
share mounted. (CVE-2011-3191, Important)

* A local attacker could use mount.ecryptfs_private to mount (and then
access) a directory they would otherwise not have access to. Note: To
correct this issue, the RHSA-2011:1241 ecryptfs-utils update must also be
installed. (CVE-2011-1833, Moderate)

* A flaw in the taskstats subsystem could allow a local, unprivileged user
to cause excessive CPU time and memory use. (CVE-2011-2484, Moderate)

* Mapping expansion handling could allow a local, unprivileged user to
cause a denial of service. (CVE-2011-2496, Moderate)

* GRO (Generic Receive Offload) fields could be left in an inconsistent
state. An attacker on the local network could use this flaw to cause a
denial of service. GRO is enabled by default in all network drivers that
support it. (CVE-2011-2723, Moderate)

* RHSA-2011:1065 introduced a regression in the Ethernet bridge
implementation. If a system had an interface in a bridge, and an attacker
on the local network could send packets to that interface, they could cause
a denial of service on that system. Xen hypervisor and KVM (Kernel-based
Virtual Machine) hosts often deploy bridge interfaces. (CVE-2011-2942,
Moderate)

* A flaw in the Xen hypervisor IOMMU error handling implementation could
allow a privileged guest user, within a guest operating system that has
direct control of a PCI device, to cause performance degradation on the
host and possibly cause it to hang. (CVE-2011-3131, Moderate)

* IPv4 and IPv6 protocol sequence number and fragment ID generation could
allow a man-in-the-middle attacker to inject packets and possibly hijack
connections. Protocol sequence number and fragment IDs are now more random.
(CVE-2011-3188, Moderate)

* A flaw in the kernel's clock implementation could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-3209, Moderate)

* Non-member VLAN (virtual LAN) packet handling for interfaces in
promiscuous mode and also using the be2net driver could allow an attacker
on the local network to cause a denial of service. (CVE-2011-3347,
Moderate)

* A flaw in the auerswald USB driver could allow a local, unprivileged user
to cause a denial of service or escalate their privileges by inserting a
specially-crafted USB device. (CVE-2009-4067, Low)

* A flaw in the Trusted Platform Module (TPM) implementation could allow a
local, unprivileged user to leak information to user space. (CVE-2011-1160,
Low)

* A local, unprivileged user could possibly mount a CIFS share that
requires authentication without knowing the correct password if the mount
was already mounted by another local user. (CVE-2011-1585, Low)

Red Hat would like to thank Fernando Gont for reporting CVE-2011-2699;
Darren Lavender for reporting CVE-2011-3191; the Ubuntu Security Team for
reporting CVE-2011-1833; Vasiliy Kulikov of Openwall for reporting
CVE-2011-2484; Robert Swiecki for reporting CVE-2011-2496; Brent Meshier
for reporting CVE-2011-2723; Dan Kaminsky for reporting CVE-2011-3188;
Yasuaki Ishimatsu for reporting CVE-2011-3209; Somnath Kotur for reporting
CVE-2011-3347; Rafael Dominguez Vega for reporting CVE-2009-4067; and Peter
Huewe for reporting CVE-2011-1160. The Ubuntu Security Team acknowledges
Vasiliy Kulikov of Openwall and Dan Rosenberg as the original reporters of
CVE-2011-1833.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3191</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3347</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111391" severity="medium">
    <xccdf:title>RHSA-2011:1391: httpd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

It was discovered that mod_proxy_ajp incorrectly returned an "Internal
Server Error" response when processing certain malformed HTTP requests,
which caused the back-end server to be marked as failed in configurations
where mod_proxy was used in load balancer mode. A remote attacker could
cause mod_proxy to not send requests to back-end AJP (Apache JServ
Protocol) servers for the retry timeout period or until all back-end
servers were marked as failed. (CVE-2011-3348)

Red Hat would like to thank Context Information Security for reporting the
CVE-2011-3368 issue.

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by the RHSA-2011:1245 update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions. (BZ#736592)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3368</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111391"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111392" severity="medium">
    <xccdf:title>RHSA-2011:1392: httpd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

Red Hat would like to thank Context Information Security for reporting this
issue.

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by the RHSA-2011:1245 update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions. (BZ#736593, BZ#736594)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3368</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111392"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111401" severity="medium">
    <xccdf:title>RHSA-2011:1401: xen security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A buffer overflow flaw was found in the Xen hypervisor SCSI subsystem
emulation. An unprivileged, local guest user could provide a large number
of bytes that are used to zero out a fixed-sized buffer via a SAI READ
CAPACITY SCSI command, overwriting memory and causing the guest to crash.
(CVE-2011-3346)

This update also fixes the following bugs:

* Prior to this update, the vif-bridge script used a maximum transmission
unit (MTU) of 1500 for a new Virtual Interface (VIF). As a result, the MTU
of the VIF could differ from that of the target bridge. This update fixes
the VIF hot-plug script so that the default MTU for new VIFs will match
that of the target Xen hypervisor bridge. In combination with a new enough
kernel (RHSA-2011:1386), this enables the use of jumbo frames in Xen
hypervisor guests. (BZ#738608)

* Prior to this update, the network-bridge script set the MTU of the bridge
to 1500. As a result, the MTU of the Xen hypervisor bridge could differ
from that of the physical interface. This update fixes the network script
so the MTU of the bridge can be set higher than 1500, thus also providing
support for jumbo frames. Now, the MTU of the Xen hypervisor bridge will
match that of the physical interface. (BZ#738610)

* Red Hat Enterprise Linux 5.6 introduced an optimized migration handling
that speeds up the migration of guests with large memory. However, the new
migration procedure can theoretically cause data corruption. While no cases
were observed in practice, with this update, the xend daemon properly waits
for correct device release before the guest is started on a destination
machine, thus fixing this bug. (BZ#743850)

Note: Before a guest is using a new enough kernel (RHSA-2011:1386), the MTU
of the VIF will drop back to 1500 (if it was set higher) after migration.

All xen users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the xend service must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3346</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111401"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111402" severity="high">
    <xccdf:title>RHSA-2011:1402: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.

Multiple input validation flaws were found in the way FreeType processed
bitmap font files. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3256)

Note: These issues only affected the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3256</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111402"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111409" severity="medium">
    <xccdf:title>RHSA-2011:1409: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An uninitialized variable use flaw was found in OpenSSL. This flaw could
cause an application using the OpenSSL Certificate Revocation List (CRL)
checking functionality to incorrectly accept a CRL that has a nextUpdate
date in the past. (CVE-2011-3207)

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. For the update to take effect, all
services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3207</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111409"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111422" severity="medium">
    <xccdf:title>RHSA-2011:1422: openswan security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks.

A use-after-free flaw was found in the way Openswan's pluto IKE daemon used
cryptographic helpers. A remote, authenticated attacker could send a
specially-crafted IKE packet that would crash the pluto daemon. This issue
only affected SMP (symmetric multiprocessing) systems that have the
cryptographic helpers enabled. The helpers are disabled by default on Red
Hat Enterprise Linux 5, but enabled by default on Red Hat Enterprise Linux
6. (CVE-2011-4073)

Red Hat would like to thank the Openswan project for reporting this issue.
Upstream acknowledges Petar Tsankov, Mohammad Torabi Dashti and David Basin
of the information security group at ETH Zurich as the original reporters.

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4073</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111422"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111423" severity="medium">
    <xccdf:title>RHSA-2011:1423: php53 and php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A signedness issue was found in the way the PHP crypt() function handled
8-bit characters in passwords when using Blowfish hashing. Up to three
characters immediately preceding a non-ASCII character (one with the high
bit set) had no effect on the hash result, thus shortening the effective
password length. This made brute-force guessing more efficient as several
different passwords were hashed to the same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to PHP applications that hash passwords with
Blowfish using the PHP crypt() function. Refer to the upstream
"CRYPT_BLOWFISH security fix details" document, linked to in the
References, for details.

An insufficient input validation flaw, leading to a buffer over-read, was
found in the PHP exif extension. A specially-crafted image file could cause
the PHP interpreter to crash when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-0708)

An integer overflow flaw was found in the PHP calendar extension. A remote
attacker able to make a PHP script call SdnToJulian() with a large value
could cause the PHP interpreter to crash. (CVE-2011-1466)

Multiple memory leak flaws were found in the PHP OpenSSL extension. A
remote attacker able to make a PHP script use openssl_encrypt() or
openssl_decrypt() repeatedly could cause the PHP interpreter to use an
excessive amount of memory. (CVE-2011-1468)

A use-after-free flaw was found in the PHP substr_replace() function. If a
PHP script used the same variable as multiple function arguments, a remote
attacker could possibly use this to crash the PHP interpreter or, possibly,
execute arbitrary code. (CVE-2011-1148)

A bug in the PHP Streams component caused the PHP interpreter to crash if
an FTP wrapper connection was made through an HTTP proxy. A remote attacker
could possibly trigger this issue if a PHP script accepted an untrusted URL
to connect to. (CVE-2011-1469)

An integer signedness issue was found in the PHP zip extension. An attacker
could use a specially-crafted ZIP archive to cause the PHP interpreter to
use an excessive amount of CPU time until the script execution time limit
is reached. (CVE-2011-1471)

A stack-based buffer overflow flaw was found in the way the PHP socket
extension handled long AF_UNIX socket addresses. An attacker able to make a
PHP script connect to a long AF_UNIX socket address could use this flaw to
crash the PHP interpreter. (CVE-2011-1938)

An off-by-one flaw was found in PHP. If an attacker uploaded a file with a
specially-crafted file name it could cause a PHP script to attempt to write
a file to the root (/) directory. By default, PHP runs as the "apache"
user, preventing it from writing to the root directory. (CVE-2011-2202)

All php53 and php users should upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1938</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2483</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111423"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111424" severity="medium">
    <xccdf:title>RHSA-2011:1424: perl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming.

A heap-based buffer overflow flaw was found in the way Perl decoded Unicode
strings. An attacker could create a malicious Unicode string that, when
decoded by a Perl program, would cause the program to crash or,
potentially, execute arbitrary code with the permissions of the user
running the program. (CVE-2011-2939)

It was found that the "new" constructor of the Digest module used its
argument as part of the string expression passed to the eval() function. An
attacker could possibly use this flaw to execute arbitrary Perl code with
the privileges of a Perl program that uses untrusted input as an argument
to the constructor. (CVE-2011-3597)

All Perl users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running Perl programs must
be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3597</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111424"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111437" severity="high">
    <xccdf:title>RHSA-2011:1437: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox handled certain add-ons. A web page
containing malicious content could cause an add-on to grant itself full
browser privileges, which could lead to arbitrary code execution with the
privileges of the user running Firefox. (CVE-2011-3647)

A cross-site scripting (XSS) flaw was found in the way Firefox handled
certain multibyte character sets. A web page containing malicious content
could cause Firefox to run JavaScript code with the permissions of a
different website. (CVE-2011-3648)

A flaw was found in the way Firefox handled large JavaScript scripts. A web
page containing malicious JavaScript could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-3650)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.24. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.24, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1437</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3650</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111437"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111438" severity="medium">
    <xccdf:title>RHSA-2011:1438: thunderbird security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A cross-site scripting (XSS) flaw was found in the way Thunderbird handled
certain multibyte character sets. Malicious, remote content could cause
Thunderbird to run JavaScript code with the permissions of different remote
content. (CVE-2011-3648)

Note: This issue cannot be exploited by a specially-crafted HTML mail
message as JavaScript is disabled by default for mail messages. It could be
exploited another way in Thunderbird, for example, when viewing the full
remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be restarted
for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3648</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111438"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111439" severity="high">
    <xccdf:title>RHSA-2011:1439: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled certain add-ons. Malicious,
remote content could cause an add-on to elevate its privileges, which could
lead to arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-3647)

A cross-site scripting (XSS) flaw was found in the way Thunderbird handled
certain multibyte character sets. Malicious, remote content could cause
Thunderbird to run JavaScript code with the permissions of different
remote content. (CVE-2011-3648)

A flaw was found in the way Thunderbird handled large JavaScript scripts.
Malicious, remote content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-3650)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3650</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111439"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111440" severity="medium">
    <xccdf:title>RHSA-2011:1440: seamonkey security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A cross-site scripting (XSS) flaw was found in the way SeaMonkey handled
certain multibyte character sets. A web page containing malicious content
could cause SeaMonkey to run JavaScript code with the permissions of a
different website. (CVE-2011-3648)
 
All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1440</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3648</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111440"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111441" severity="medium">
    <xccdf:title>RHSA-2011:1441: icedtea-web security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

A flaw was found in the same-origin policy implementation in the
IcedTea-Web browser plug-in. A malicious Java applet could use this flaw to
open network connections to hosts other than the originating host,
violating the same-origin policy. (CVE-2011-3377)

All IcedTea-Web users should upgrade to these updated packages, which
upgrade IcedTea-Web to version 1.0.6 to correct this issue. Web browsers
using the IcedTea-Web browser plug-in must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3377</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111441"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111455" severity="high">
    <xccdf:title>RHSA-2011:1455: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.

Multiple input validation flaws were found in the way FreeType processed
CID-keyed fonts. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3439)

Note: These issues only affected the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3439</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111458" severity="high">
    <xccdf:title>RHSA-2011:1458: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4313</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111458"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111459" severity="high">
    <xccdf:title>RHSA-2011:1459: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind97 are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4313</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111465" severity="high">
    <xccdf:title>RHSA-2011:1465: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* IPv6 fragment identification value generation could allow a remote
attacker to disrupt a target system's networking, preventing legitimate
users from accessing its services. (CVE-2011-2699, Important)

* A signedness issue was found in the Linux kernel's CIFS (Common Internet
File System) implementation. A malicious CIFS server could send a
specially-crafted response to a directory read request that would result in
a denial of service or privilege escalation on a system that has a CIFS
share mounted. (CVE-2011-3191, Important)

* A flaw was found in the way the Linux kernel handled fragmented IPv6 UDP
datagrams over the bridge with UDP Fragmentation Offload (UFO)
functionality on. A remote attacker could use this flaw to cause a denial
of service. (CVE-2011-4326, Important)

* The way IPv4 and IPv6 protocol sequence numbers and fragment IDs were
generated could allow a man-in-the-middle attacker to inject packets and
possibly hijack connections. Protocol sequence numbers and fragment IDs are
now more random. (CVE-2011-3188, Moderate)

* A buffer overflow flaw was found in the Linux kernel's FUSE (Filesystem
in Userspace) implementation. A local user in the fuse group who has access
to mount a FUSE file system could use this flaw to cause a denial of
service. (CVE-2011-3353, Moderate)

* A flaw was found in the b43 driver in the Linux kernel. If a system had
an active wireless interface that uses the b43 driver, an attacker able to
send a specially-crafted frame to that interface could cause a denial of
service. (CVE-2011-3359, Moderate)

* A flaw was found in the way CIFS shares with DFS referrals at their root
were handled. An attacker on the local network who is able to deploy a
malicious CIFS server could create a CIFS network share that, when mounted,
would cause the client system to crash. (CVE-2011-3363, Moderate)

* A flaw was found in the way the Linux kernel handled VLAN 0 frames with
the priority tag set. When using certain network drivers, an attacker on
the local network could use this flaw to cause a denial of service.
(CVE-2011-3593, Moderate)

* A flaw in the way memory containing security-related data was handled in
tpm_read() could allow a local, unprivileged user to read the results of a
previously run TPM command. (CVE-2011-1162, Low)

* A heap overflow flaw was found in the Linux kernel's EFI GUID Partition
Table (GPT) implementation. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partition tables. (CVE-2011-1577, Low)

* The I/O statistics from the taskstats subsystem could be read without
any restrictions. A local, unprivileged user could use this flaw to gather
confidential information, such as the length of a password used in a
process. (CVE-2011-2494, Low)

* It was found that the perf tool, a part of the Linux kernel's Performance
Events implementation, could load its configuration file from the current
working directory. If a local user with access to the perf tool were
tricked into running perf in a directory that contains a specially-crafted
configuration file, it could cause perf to overwrite arbitrary files and
directories accessible to that user. (CVE-2011-2905, Low)

Red Hat would like to thank Fernando Gont for reporting CVE-2011-2699;
Darren Lavender for reporting CVE-2011-3191; Dan Kaminsky for reporting
CVE-2011-3188; Yogesh Sharma for reporting CVE-2011-3363; Gideon Naim for
reporting CVE-2011-3593; Peter Huewe for reporting CVE-2011-1162; Timo
Warns for reporting CVE-2011-1577; and Vasiliy Kulikov of Openwall for
reporting CVE-2011-2494.

This update also fixes various bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3191</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3359</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4326</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111465"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111479" severity="high">
    <xccdf:title>RHSA-2011:1479: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Using PCI passthrough without interrupt remapping support allowed Xen
hypervisor guests to generate MSI interrupts and thus potentially inject
traps. A privileged guest user could use this flaw to crash the host or
possibly escalate their privileges on the host. The fix for this issue can
prevent PCI passthrough working and guests starting. Refer to Red Hat
Bugzilla bug 715555 for details. (CVE-2011-1898, Important)

* A flaw was found in the way CIFS (Common Internet File System) shares
with DFS referrals at their root were handled. An attacker on the local
network who is able to deploy a malicious CIFS server could create a CIFS
network share that, when mounted, would cause the client system to crash.
(CVE-2011-3363, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
key management facility handled user-defined key types. A local,
unprivileged user could use the keyctl utility to cause a denial of
service. (CVE-2011-4110, Moderate)

* A flaw in the way memory containing security-related data was handled in
tpm_read() could allow a local, unprivileged user to read the results of a
previously run TPM command. (CVE-2011-1162, Low)

* A NULL pointer dereference flaw was found in the Linux kernel's HFS file
system implementation. A local attacker could use this flaw to cause a
denial of service by mounting a disk that contains a specially-crafted HFS
file system with a corrupted MDB extent record. (CVE-2011-2203, Low)

* The I/O statistics from the taskstats subsystem could be read without
any restrictions. A local, unprivileged user could use this flaw to gather
confidential information, such as the length of a password used in a
process. (CVE-2011-2494, Low)

Red Hat would like to thank Yogesh Sharma for reporting CVE-2011-3363;
Peter Huewe for reporting CVE-2011-1162; Clement Lecigne for reporting
CVE-2011-2203; and Vasiliy Kulikov of Openwall for reporting CVE-2011-2494.

This update also fixes several bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4110</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111479"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111496" severity="high">
    <xccdf:title>RHSA-2011:1496: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4313</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111496"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111506" severity="low">
    <xccdf:title>RHSA-2011:1506: Red Hat Enterprise Linux 4 - 3-Month End Of Life Notice (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1506</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111506"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111507" severity="medium">
    <xccdf:title>RHSA-2011:1507: libarchive security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libarchive programming library can create and read several different
streaming archive formats, including GNU tar and cpio. It can also read ISO
9660 CD-ROM images.

Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)

All libarchive users should upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using libarchive must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1778</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111507"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111508" severity="medium">
    <xccdf:title>RHSA-2011:1508: cyrus-imapd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

An authentication bypass flaw was found in the cyrus-imapd NNTP server,
nntpd. A remote user able to use the nntpd service could use this flaw to
read or post newsgroup messages on an NNTP server configured to require
user authentication, without providing valid authentication credentials.
(CVE-2011-3372)

A NULL pointer dereference flaw was found in the cyrus-imapd IMAP server,
imapd. A remote attacker could send a specially-crafted mail message to a
victim that would possibly prevent them from accessing their mail normally,
if they were using an IMAP client that relies on the server threading IMAP
feature. (CVE-2011-3481)

Red Hat would like to thank the Cyrus IMAP project for reporting the
CVE-2011-3372 issue. Upstream acknowledges Stefan Cornelius of Secunia
Research as the original reporter of CVE-2011-3372.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the update, cyrus-imapd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3481</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111508"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111526" severity="low">
    <xccdf:title>RHSA-2011:1526: glibc security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system
cannot function properly.

A flaw was found in the way the ldd utility identified dynamically linked
libraries. If an attacker could trick a user into running ldd on a
malicious binary, it could result in arbitrary code execution with the
privileges of the user running ldd. (CVE-2009-5064)

It was found that the glibc addmntent() function, used by various mount
helper utilities, did not handle certain errors correctly when updating the
mtab (mounted file systems table) file. If such utilities had the setuid
bit set, a local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1089)

Red Hat would like to thank Dan Rosenberg for reporting the CVE-2011-1089
issue.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

Users are advised to upgrade to these updated glibc packages, which contain
backported patches to resolve these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1089</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111526"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111530" severity="medium">
    <xccdf:title>RHSA-2011:1530: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* The proc file system could allow a local, unprivileged user to obtain
sensitive information or possibly cause integrity issues. (CVE-2011-1020,
Moderate)

* Non-member VLAN (virtual LAN) packet handling for interfaces in
promiscuous mode and also using the be2net driver could allow an attacker
on the local network to cause a denial of service. (CVE-2011-3347,
Moderate)

* A flaw was found in the Linux kernel in the way splitting two extents in
ext4_ext_convert_to_initialized() worked. A local, unprivileged user with
access to mount and unmount ext4 file systems could use this flaw to cause
a denial of service. (CVE-2011-3638, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
key management facility handled user-defined key types. A local,
unprivileged user could use the keyctl utility to cause a denial of
service. (CVE-2011-4110, Moderate)

Red Hat would like to thank Kees Cook for reporting CVE-2011-1020; Somnath
Kotur for reporting CVE-2011-3347; and Zheng Liu for reporting
CVE-2011-3638.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.2 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.2 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4110</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111530"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111531" severity="medium">
    <xccdf:title>RHSA-2011:1531: qemu-kvm security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that qemu-kvm did not properly drop supplemental group
privileges when the root user started guests from the command line
("/usr/libexec/qemu-kvm") with the "-runas" option. A qemu-kvm process
started this way could use this flaw to gain access to files on the host
that are accessible to the supplementary groups and not accessible to the
primary group. (CVE-2011-2527)

Note: This issue only affected qemu-kvm when it was started directly from
the command line. It did not affect the Red Hat Enterprise Virtualization
platform or applications that start qemu-kvm via libvirt, such as the
Virtual Machine Manager (virt-manager).

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All users of qemu-kvm are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements. After installing this update, shut down all running virtual
machines. Once all virtual machines have shut down, start them again for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2527</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111531"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111532" severity="medium">
    <xccdf:title>RHSA-2011:1532: kexec-tools security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kexec allows for booting a Linux kernel from the context of an already
running kernel.

Kdump used the SSH (Secure Shell) "StrictHostKeyChecking=no" option when
dumping to SSH targets, causing the target kdump server's SSH host key not
to be checked. This could make it easier for a man-in-the-middle attacker
on the local network to impersonate the kdump SSH target server and
possibly gain access to sensitive information in the vmcore dumps.
(CVE-2011-3588)

mkdumprd created initrd files with world-readable permissions. A local user
could possibly use this flaw to gain access to sensitive information, such
as the private SSH key used to authenticate to a remote server when kdump
was configured to dump to an SSH target. (CVE-2011-3589)

mkdumprd included unneeded sensitive files (such as all files from the
"/root/.ssh/" directory and the host's private SSH keys) in the resulting
initrd. This could lead to an information leak when initrd files were
previously created with world-readable permissions. Note: With this update,
only the SSH client configuration, known hosts files, and the SSH key
configured via the newly introduced sshkey option in "/etc/kdump.conf" are
included in the initrd. The default is the key generated when running the
"service kdump propagate" command, "/root/.ssh/kdump_id_rsa".
(CVE-2011-3590)

Red Hat would like to thank Kevan Carstensen for reporting these issues.

This update also fixes several bugs and adds various enhancements.
Space precludes documenting all of these changes in this advisory.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All kexec-tools users should upgrade to this updated package, which
contains backported patches to resolve these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3588</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3589</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3590</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111532"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111533" severity="medium">
    <xccdf:title>RHSA-2011:1533: ipa security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud based
enterprise environments. It integrates components of the Red Hat Directory
Server, MIT Kerberos, Red Hat Certificate System, NTP and DNS. It provides
web browser and command-line interfaces. Its administration tools allow an
administrator to quickly install, set up, and administer a group of domain
controllers to meet the authentication and identity management requirements
of large scale Linux and UNIX deployments.

A Cross-Site Request Forgery (CSRF) flaw was found in Red Hat Identity
Management. If a remote attacker could trick a user, who was logged into
the management web interface, into visiting a specially-crafted URL, the
attacker could perform Red Hat Identity Management configuration changes
with the privileges of the logged in user. (CVE-2011-3636)

Due to the changes required to fix CVE-2011-3636, client tools will need to
be updated for client systems to communicate with updated Red Hat Identity
Management servers. New client systems will need to have the updated
ipa-client package installed to be enrolled. Already enrolled client
systems will need to have the updated certmonger package installed to be
able to renew their system certificate. Note that system certificates are
valid for two years by default.

Updated ipa-client and certmonger packages for Red Hat Enterprise Linux 6
were released as part of Red Hat Enterprise Linux 6.2. Future updates will
provide updated packages for Red Hat Enterprise Linux 5.

This update includes several bug fixes. Space precludes documenting all of
these changes in this advisory. Users are directed to the Red Hat
Enterprise Linux 6.2 Technical Notes for information on the most
significant of these changes, linked to in the References section.

Users of Red Hat Identity Management should upgrade to these updated
packages, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111533"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111534" severity="low">
    <xccdf:title>RHSA-2011:1534: nfs-utils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils packages provide a daemon for the kernel Network File System
(NFS) server, and related tools such as the mount.nfs, umount.nfs, and
showmount programs.

A flaw was found in the way nfs-utils performed IP based authentication of
mount requests. In configurations where a directory was exported to a group
of systems using a DNS wildcard or NIS (Network Information Service)
netgroup, an attacker could possibly gain access to other directories
exported to a specific host or subnet, bypassing intended access
restrictions. (CVE-2011-2500)

It was found that the mount.nfs tool did not handle certain errors
correctly when updating the mtab (mounted file systems table) file. A local
attacker could use this flaw to corrupt the mtab file. (CVE-2011-1749)

This update also fixes several bugs and adds an enhancement. Documentation
for these bug fixes and the enhancement will be available shortly from the
Technical Notes document, linked to in the References section.

Users of nfs-utils are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add this
enhancement. After installing this update, the nfs service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2500</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111534"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111536" severity="low">
    <xccdf:title>RHSA-2011:1536: sos security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sos is a set of tools that gather information about system hardware and
configuration.

The sosreport utility incorrectly included Certificate-based Red Hat
Network private entitlement keys in the resulting archive of debugging
information. An attacker able to access the archive could use the keys to
access Red Hat Network content available to the host. This issue did not
affect users of Red Hat Network Classic. (CVE-2011-4083)

This updated sos package also includes numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All users of sos are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4083</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111536"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111580" severity="low">
    <xccdf:title>RHSA-2011:1580: resource-agents security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The resource-agents package contains a set of scripts to interface with
several services to operate in a High Availability environment for both
Pacemaker and rgmanager service managers.

It was discovered that certain resource agent scripts set the
LD_LIBRARY_PATH environment variable to an insecure value containing empty
path elements. A local user able to trick a user running those scripts to
run them while working from an attacker-writable directory could use this
flaw to escalate their privileges via a specially-crafted dynamic library.
(CVE-2010-3389)

Red Hat would like to thank Raphael Geissert for reporting this issue.

This update also fixes the following bugs:

* When using the Sybase database and the ASEHAagent resource in the
cluster.conf file, it was not possible to run more than one ASEHAagent per
Sybase installation. Consequently, a second ASEHA (Sybase Adaptive Server
Enterprise (ASE) with the High Availability Option) agent could not be run.
This bug has been fixed and it is now possible to use two ASEHA agents
using the same Sybase installation. (BZ#711852)

* The s/lang scripts, which implement internal functionality for the
rgmanager package, while the central_processing option is in use, were
included in the wrong package. Now, the rgmanager and resource-agents
packages require each other for installation to prevent problems when they
are used separately. (BZ#693518)

* Previously, the oracledb.sh script was using the "shutdown abort" command
as the first attempt to shut down a database. With this update, oracledb.sh
first attempts a graceful shutdown via the "shutdown immediate" command
before forcing the shutdown. (BZ#689801)

* Previously, when setting up a service on a cluster with a shared IP
resource and an Apache resource, the generated httpd.conf file contained a
bug in the line describing the shared IP address (the "Listen" line). Now,
the Apache resource agent generates the "Listen" line properly. (BZ#667217)

* If a high-availability (HA) cluster service was defined with an Apache
resource and was named with two words, such as "kickstart httpd", the
service never started because it could not find a directory with the space
character in its name escaped. Now, Apache resources work properly if a
name contains a space as described above. (BZ#667222)

* When inheritance was used in the cluster.conf file, a bug in the
/usr/share/cluster/nfsclient.sh file prevented it from monitoring NFS
exports properly. Consequently, monitoring of NFS exports to NFS clients
resulted in an endless loop. This bug has been fixed and the monitoring now
works as expected. (BZ#691814)

* Previously, the postgres-8 resource agent did not detect when a
PostgreSQL server failed to start. This bug has been fixed and postgres-8
now works as expected in the described scenario. (BZ#694816)

* When using the Pacemaker resource manager, the fs.sh resource agent
reported an error condition, if called with the "monitor" parameter and the
referenced device did not exist. Consequently, the error condition
prevented the resource from being started. Now, fs.sh returns the proper
response code in the described scenario, thus fixing this bug. (BZ#709400)

* Previously, numerous RGManager resource agents returned incorrect
response codes when coupled with the Pacemaker resource manager. Now, the
agents have been updated to work with Pacemaker properly. (BZ#727643)

This update also adds the following enhancement:

* With this update, when the network is removed from a node using the
netfs.sh resource agent, it now recovers faster than previously.
(BZ#678497)

As well, this update upgrades the resource-agents package to upstream
version 3.9.2, which provides a number of bug fixes and enhancements over
the previous version. (BZ#707127)

All users of resource-agents are advised to upgrade to this updated
package, which corrects these issues and adds these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3389</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111581" severity="low">
    <xccdf:title>RHSA-2011:1581: ruby security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

It was found that Ruby did not reinitialize the PRNG (pseudorandom number
generator) after forking a child process. This could eventually lead to the
PRNG returning the same result twice. An attacker keeping track of the
values returned by one child process could use this flaw to predict the
values the PRNG would return in other child processes (as long as the
parent process persisted). (CVE-2011-3009)

A flaw was found in the Ruby SecureRandom module. When using the
SecureRandom.random_bytes class, the PRNG state was not modified after
forking a child process. This could eventually lead to
SecureRandom.random_bytes returning the same string more than once. An
attacker keeping track of the strings returned by one child process could
use this flaw to predict the strings SecureRandom.random_bytes would return
in other child processes (as long as the parent process persisted).
(CVE-2011-2705)

This update also fixes the following bugs:

* The ruby package has been upgraded to upstream point release 1.8.7-p352,
which provides a number of bug fixes over the previous version. (BZ#706332)

* The MD5 message-digest algorithm is not a FIPS-approved algorithm.
Consequently, when a Ruby script attempted to calculate an MD5 checksum in
FIPS mode, the interpreter terminated unexpectedly. This bug has been fixed
and an exception is now raised in the described scenario. (BZ#717709)

* Due to inappropriately handled line continuations in the mkconfig.rb
source file, an attempt to build the ruby package resulted in unexpected
termination. An upstream patch has been applied to address this issue and
the ruby package can now be built properly. (BZ#730287)

* When the 32-bit ruby-libs library was installed on a 64-bit machine, the
mkmf library failed to load various modules necessary for building
Ruby-related packages. This bug has been fixed and mkmf now works properly
in the described scenario. (BZ#674787)

* Previously, the load paths for scripts and binary modules were duplicated
on the i386 architecture. Consequently, an ActiveSupport test failed. With
this update, the load paths are no longer stored in duplicates on the i386
architecture. (BZ#722887)

This update also adds the following enhancement:

* With this update, SystemTap probes have been added to the ruby package.
(BZ#673162)

All users of ruby are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3009</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111581"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111615" severity="low">
    <xccdf:title>RHSA-2011:1615: virt-v2v security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>virt-v2v is a tool for converting and importing virtual machines to
libvirt-managed KVM (Kernel-based Virtual Machine), or Red Hat Enterprise
Virtualization.

Using virt-v2v to convert a guest that has a password-protected VNC console
to a KVM guest removed that password protection from the converted guest:
after conversion, a password was not required to access the converted
guest's VNC console. Now, converted guests will require the same VNC
console password as the original guest. Note that when converting a guest
to run on Red Hat Enterprise Virtualization, virt-v2v will display a
warning that VNC passwords are not supported. (CVE-2011-1773)

Note: The Red Hat Enterprise Linux 6.2 perl-Sys-Virt update must also be
installed to correct CVE-2011-1773.

Bug fixes:

* When converting a guest virtual machine (VM), whose name contained
certain characters, virt-v2v would create a converted guest with a
corrupted name. Now, virt-v2v will not corrupt guest names. (BZ#665883)

* There were numerous usability issues when running virt-v2v as a non-root
user. This update makes it simpler to run virt-v2v as a non-root user.
(BZ#671094)

* virt-v2v failed to convert a Microsoft Windows guest with Windows
Recovery Console installed in a separate partition. Now, virt-v2v will
successfully convert a guest with Windows Recovery Console installed in a
separate partition by ignoring that partition. (BZ#673066)

* virt-v2v failed to convert a Red Hat Enterprise Linux guest which did not
have the symlink "/boot/grub/menu.lst". With this update, virt-v2v can
select a grub configuration file from several places. (BZ#694364)

* This update removes information about the usage of deprecated command
line options in the virt-v2v man page. (BZ#694370)

* virt-v2v would fail to correctly change the allocation policy, (sparse or
preallocated) when converting a guest with QCOW2 image format. The error
message "Cannot import VM, The selected disk configuration is not
supported" was displayed. With this update, allocation policy changes to a
guest with QCOW2 storage will work correctly. (BZ#696089)

* The options "--network" and "--bridge" can not be used in conjunction
when converting a guest, but no error message was displayed. With this
update, virt-v2v will now display an error message if the mutually
exclusive "--network" and "--bridge" command line options are both
specified. (BZ#700759)

* virt-v2v failed to convert a multi-boot guest, and did not clean up
temporary storage and mount points after failure. With this update,
virt-v2v will prompt for which operating system to convert from a
multi-boot guest, and will correctly clean up if the process fails.
(BZ#702007)

* virt-v2v failed to correctly configure modprobe aliases when converting a
VMware ESX guest with VMware Tools installed. With this update, modprobe
aliases will be correctly configured. (BZ#707261)

* When converting a guest with preallocated raw storage using the
libvirtxml input method, virt-v2v failed with the erroneous error message
"size(X) &lt; usage(Y)". This update removes this erroneous error. (BZ#727489)

* When converting a Red Hat Enterprise Linux guest, virt-v2v did not check
that the Cirrus X driver was available before configuring it. With this
update, virt-v2v will attempt to install the Cirrus X driver if it is
required. (BZ#708961)

* VirtIO systems do not support the Windows Recovery Console on 32-bit
Windows XP. The virt-v2v man page has been updated to note this. On Windows
XP Professional x64 Edition, however, if Windows Recovery Console is
re-installed after conversion, it will work as expected. (BZ#732421)

* Placing comments in the guest fstab file by means of the leading "#"
symbol caused an "unknown filesystem" error after conversion of a guest.
With this update comments can now be used and error messages will not be
displayed. (BZ#677870)

Users of virt-v2v should upgrade to this updated package, which fixes these
issues and upgrades virt-v2v to version 0.8.3.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1773</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111615"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111635" severity="low">
    <xccdf:title>RHSA-2011:1635: cups security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)
decompression algorithm implementation used by the CUPS GIF image format
reader. An attacker could create a malicious GIF image file that, when
printed, could possibly cause CUPS to crash or, potentially, execute
arbitrary code with the privileges of the "lp" user. (CVE-2011-2896)

These updated cups packages also provide fixes for the following bugs:

* Previously CUPS was not correctly handling the language setting
LANG=en_US.ASCII. As a consequence lpadmin, lpstat and lpinfo binaries were
not displaying any output when the LANG=en_US.ASCII environment variable
was used. As a result of this update the problem is fixed and the expected
output is now displayed. (BZ#681836)

* Previously the scheduler did not check for empty values of several
configuration directives. As a consequence it was possible for the CUPS
daemon (cupsd) to crash when a configuration file contained certain empty
values. With this update the problem is fixed and cupsd no longer crashes
when reading such a configuration file. (BZ#706673)

* Previously when printing to a raw print queue, when using certain printer
models, CUPS was incorrectly sending SNMP queries. As a consequence there
was a noticeable 4-second delay between queueing the job and the start of
printing. With this update the problem is fixed and CUPS no longer tries to
collect SNMP supply and status information for raw print queues.
(BZ#709896)

* Previously when using the BrowsePoll directive it could happen that the
CUPS printer polling daemon (cups-polld) began polling before the network
interfaces were set up after a system boot. CUPS was then caching the
failed hostname lookup. As a consequence no printers were found and the
error, "Host name lookup failure", was logged. With this update the code
that re-initializes the resolver after failure in cups-polld is fixed and
as a result CUPS will obtain the correct network settings to use in printer
discovery. (BZ#712430)

* The MaxJobs directive controls the maximum number of print jobs that are
kept in memory. Previously, once the number of jobs reached the limit, the
CUPS system failed to automatically purge the data file associated with the
oldest completed job from the system in order to make room for a new print
job. This bug has been fixed, and the jobs beyond the set limit are now
properly purged. (BZ#735505)

* The cups init script (/etc/rc.d/init.d/cups) uses the daemon function
(from /etc/rc.d/init.d/functions) to start the cups process, but previously
it did not source a configuration file from the /etc/sysconfig/ directory.
As a consequence, it was difficult to cleanly set the nice level or cgroup
for the cups daemon by setting the NICELEVEL or CGROUP_DAEMON variables.
With this update, the init script is fixed. (BZ#744791)

All users of CUPS are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1635</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2896</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111635"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111691" severity="low">
    <xccdf:title>RHSA-2011:1691: util-linux-ng security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux-ng packages contain a large variety of low-level system
utilities that are necessary for a Linux operating system to function.

Multiple flaws were found in the way the mount and umount commands
performed mtab (mounted file systems table) file updates. A local,
unprivileged user allowed to mount or unmount file systems could use these
flaws to corrupt the mtab file and create a stale lock file, preventing
other users from mounting and unmounting file systems. (CVE-2011-1675,
CVE-2011-1677)

This update also fixes the following bugs:

* Due to a hard coded limit of 128 devices, an attempt to run the
"blkid -c" command on more than 128 devices caused blkid to terminate
unexpectedly. This update increases the maximum number of devices to 8192
so that blkid no longer crashes in this scenario. (BZ#675999)

* Previously, the "swapon -a" command did not detect device-mapper
devices that were already in use. This update corrects the swapon utility
to detect such devices as expected. (BZ#679741)

* Prior to this update, the presence of an invalid line in the /etc/fstab
file could cause the umount utility to terminate unexpectedly with
a segmentation fault. This update applies a patch that corrects this error
so that umount now correctly reports invalid lines and no longer crashes.
(BZ#684203)

* Previously, an attempt to use the wipefs utility on a partitioned
device caused the utility to terminate unexpectedly with an error. This
update adapts wipefs to only display a warning message in this situation.
(BZ#696959)

* When providing information on interprocess communication (IPC)
facilities, the ipcs utility could previously display a process owner as
a negative number if the user's UID was too large. This update adapts the
underlying source code to make sure the UID values are now displayed
correctly. (BZ#712158)

* In the installation scriptlets, the uuidd package uses the chkconfig
utility to enable and disable the uuidd service. Previously, this package
did not depend on the chkconfig package, which could lead to errors during
installation if chkconfig was not installed. This update adds chkconfig
to the list of dependencies so that such errors no longer occur.
(BZ#712808)

* The previous version of the /etc/udev/rules.d/60-raw.rules file
contained a statement that both this file and raw devices are deprecated.
This is no longer true and the Red Hat Enterprise Linux kernel supports
this functionality. With this update, the aforementioned file no longer
contains this incorrect statement. (BZ#716995)

* Previously, an attempt to use the cfdisk utility to read the default
Red Hat Enterprise Linux 6 partition layout failed with an error. This
update corrects this error and the cfdisk utility can now read the default
partition layout as expected. (BZ#723352)

* The previous version of the tailf(1) manual page incorrectly stated that
users can use the "--lines=NUMBER" command line option to limit the number
of displayed lines. However, the tailf utility does not allow the use of
the equals sign (=) between the option and its argument. This update
corrects this error. (BZ#679831)

* The fstab(5) manual page has been updated to clarify that empty lines in
the /etc/fstab configuration file are ignored. (BZ#694648)

As well, this update adds the following enhancements:

* A new fstrim utility has been added to the package. This utility allows
the root user to discard unused blocks on a mounted file system.
(BZ#692119)

* The login utility has been updated to provide support for failed login
attempts that are reported by PAM. (BZ#696731)

* The lsblk utility has been updated to provide additional information
about the topology and status of block devices. (BZ#723638)

* The agetty utility has been updated to pass the hostname to the login
utility. (BZ#726092)

All users of util-linux-ng are advised to upgrade to these updated
packages, which contain backported patches to correct these issues and add
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1691</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1677</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111691"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111694" severity="low">
    <xccdf:title>RHSA-2011:1694: libcap security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libcap packages provide a library and tools for getting and setting
POSIX capabilities.

It was found that capsh did not change into the new root when using the
"--chroot" option. An application started via the "capsh --chroot" command
could use this flaw to escape the chroot restrictions. (CVE-2011-4099)

This update also fixes the following bug:

* Previously, the libcap packages did not contain the capsh(1) manual page.
With this update, the capsh(1) manual page is included. (BZ#730957)

All libcap users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4099</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111694"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111741" severity="low">
    <xccdf:title>RHSA-2011:1741: php-pear security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The php-pear package contains the PHP Extension and Application Repository
(PEAR), a framework and distribution system for reusable PHP components.

It was found that the "pear" command created temporary files in an insecure
way when installing packages. A malicious, local user could use this flaw
to conduct a symbolic link attack, allowing them to overwrite the contents
of arbitrary files accessible to the victim running the "pear install"
command. (CVE-2011-1072)

This update also fixes the following bugs:

* The php-pear package has been upgraded to version 1.9.4, which provides a
number of bug fixes over the previous version. (BZ#651897)

* Prior to this update, php-pear created a cache in the
"/var/cache/php-pear/" directory when attempting to list all packages. As a
consequence, php-pear failed to create or update the cache file as a
regular user without sufficient file permissions and could not list all
packages. With this update, php-pear no longer fails if writing to the
cache directory is not permitted. Now, all packages are listed as expected.
(BZ#747361)

All users of php-pear are advised to upgrade to this updated package, which
corrects these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1072</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111741"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111749" severity="low">
    <xccdf:title>RHSA-2011:1749: libxml2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards. One of those standards is the XML Path Language
(XPath), which is a language for addressing parts of an XML document.

An off-by-one error, leading to a heap-based buffer overflow, was found in
the way libxml2 parsed certain XML files. A remote attacker could provide
a specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0216)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way libxml2 parsed certain XPath expressions. If an attacker
were able to supply a specially-crafted XML file to an application using
libxml2, as well as an XPath expression for that application to run against
the crafted file, it could cause the application to crash or, possibly,
execute arbitrary code. (CVE-2011-1944)

Multiple flaws were found in the way libxml2 parsed certain XPath
expressions. If an attacker were able to supply a specially-crafted XML
file to an application using libxml2, as well as an XPath expression for
that application to run against the crafted file, it could cause the
application to crash. (CVE-2010-4008, CVE-2010-4494, CVE-2011-2821,
CVE-2011-2834)

Note: Red Hat does not ship any applications that use libxml2 in a way that
would allow the CVE-2011-1944, CVE-2010-4008, CVE-2010-4494, CVE-2011-2821,
and CVE-2011-2834 flaws to be exploited; however, third-party applications
may allow XPath expressions to be passed which could trigger these flaws.

Red Hat would like to thank the Google Security Team for reporting the
CVE-2010-4008 issue. Upstream acknowledges Bui Quang Minh from Bkis as the
original reporter of CVE-2010-4008.

This update also fixes the following bugs:

* A number of patches have been applied to harden the XPath processing code
in libxml2, such as fixing memory leaks, rounding errors, XPath numbers
evaluations, and a potential error in encoding conversion. (BZ#732335)

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2834</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111749"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111777" severity="high">
    <xccdf:title>RHSA-2011:1777: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

A flaw was found in the way qemu-kvm handled VSC_ATR messages when a guest
was configured for a CCID (Chip/Smart Card Interface Devices) USB smart
card reader in passthrough mode. An attacker able to connect to the port on
the host being used for such a device could use this flaw to crash the
qemu-kvm process on the host or, possibly, escalate their privileges on the
host. (CVE-2011-4111)

All users of qemu-kvm should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4111</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111777"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111780" severity="medium">
    <xccdf:title>RHSA-2011:1780: tomcat6 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

APR (Apache Portable Runtime) as mentioned in the CVE-2011-3190 and
CVE-2011-2526 descriptions does not refer to APR provided by the apr
packages. It refers to the implementation of APR provided by the Tomcat
Native library, which provides support for using APR with Tomcat. This
library is not shipped with Red Hat Enterprise Linux 6. This update
includes fixes for users who have elected to use APR with Tomcat by taking
the Tomcat Native library from a different product. Such a configuration is
not supported by Red Hat, however.

Multiple flaws were found in the way Tomcat handled HTTP DIGEST
authentication. These flaws weakened the Tomcat HTTP DIGEST authentication
implementation, subjecting it to some of the weaknesses of HTTP BASIC
authentication, for example, allowing remote attackers to perform session
replay attacks. (CVE-2011-1184)

A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor)
and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ
Protocol) connectors processed certain POST requests. An attacker could
send a specially-crafted request that would cause the connector to treat
the message body as a new request. This allows arbitrary AJP messages to be
injected, possibly allowing an attacker to bypass a web application's
authentication checks and gain access to information they would otherwise
be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler)
connector is used by default when the APR libraries are not present. The JK
connector is not affected by this flaw. (CVE-2011-3190)

A flaw was found in the Tomcat MemoryUserDatabase. If a runtime exception
occurred when creating a new user with a JMX client, that user's password
was logged to Tomcat log files. Note: By default, only administrators have
access to such log files. (CVE-2011-2204)

A flaw was found in the way Tomcat handled sendfile request attributes when
using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web
application running on a Tomcat instance could use this flaw to bypass
security manager restrictions and gain access to files it would otherwise
be unable to access, or possibly terminate the Java Virtual Machine (JVM).
The HTTP blocking IO (BIO) connector, which is not vulnerable to this
issue, is used by default in Red Hat Enterprise Linux 6. (CVE-2011-2526)

Red Hat would like to thank the Apache Tomcat project for reporting the
CVE-2011-2526 issue.

This update also fixes the following bug:

* Previously, in certain cases, if "LANG=fr_FR" or "LANG=fr_FR.UTF-8" was
set as an environment variable or in "/etc/sysconfig/tomcat6" on 64-bit
PowerPC systems, Tomcat may have failed to start correctly. With this
update, Tomcat works as expected when LANG is set to "fr_FR" or
"fr_FR.UTF-8". (BZ#748807)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3190</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5064</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111780"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111790" severity="medium">
    <xccdf:title>RHSA-2011:1790: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed certain TGS (Ticket-granting Server) requests. A remote,
authenticated attacker could use this flaw to crash the KDC via a
specially-crafted TGS request. (CVE-2011-1530)

Red Hat would like to thank the MIT Kerberos project for reporting this
issue.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1530</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111790"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111791" severity="medium">
    <xccdf:title>RHSA-2011:1791: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects. 

An input validation flaw was found in the way Squid calculated the total
number of resource records in the answer section of multiple name server
responses. An attacker could use this flaw to cause Squid to crash. 
(CVE-2011-4096)

Users of squid should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing this update, the
squid service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4096</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111791"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111797" severity="medium">
    <xccdf:title>RHSA-2011:1797: perl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming.

It was found that the "new" constructor of the Digest module used its
argument as part of the string expression passed to the eval() function. An
attacker could possibly use this flaw to execute arbitrary Perl code with
the privileges of a Perl program that uses untrusted input as an argument
to the constructor. (CVE-2011-3597)

It was found that the Perl CGI module used a hard-coded value for the MIME
boundary string in multipart/x-mixed-replace content. A remote attacker
could possibly use this flaw to conduct an HTTP response splitting attack
via a specially-crafted HTTP request. (CVE-2010-2761)

A CRLF injection flaw was found in the way the Perl CGI module processed a
sequence of non-whitespace preceded by newline characters in the header. A
remote attacker could use this flaw to conduct an HTTP response splitting
attack via a specially-crafted sequence of characters provided to the CGI
module. (CVE-2010-4410)

All Perl users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running Perl programs must
be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2761</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3597</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111797"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111801" severity="high">
    <xccdf:title>RHSA-2011:1801: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

A flaw was found in the way qemu-kvm handled VSC_ATR messages when a guest
was configured for a CCID (Chip/Smart Card Interface Devices) USB smart
card reader in passthrough mode. An attacker able to connect to the port on
the host being used for such a device could use this flaw to crash the
qemu-kvm process on the host or, possibly, escalate their privileges on the
host. (CVE-2011-4111)

All users of qemu-kvm should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4111</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111801"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111807" severity="high">
    <xccdf:title>RHSA-2011:1807: jasper security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>JasPer is an implementation of Part 1 of the JPEG 2000 image compression
standard.

Two heap-based buffer overflow flaws were found in the way JasPer decoded
JPEG 2000 compressed image files. An attacker could create a malicious JPEG
2000 compressed image file that, when opened, would cause applications that
use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary
code. (CVE-2011-4516, CVE-2011-4517)

Red Hat would like to thank Jonathan Foote of the CERT Coordination Center
for reporting these issues.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. All applications using the JasPer
libraries (such as Nautilus) must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4517</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111807"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111811" severity="high">
    <xccdf:title>RHSA-2011:1811: netpbm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The netpbm packages contain a library of functions which support programs
for handling various graphics file formats, including .pbm (Portable Bit
Map), .pgm (Portable Gray Map), .pnm (Portable Any Map), .ppm (Portable
Pixel Map), and others.

Two heap-based buffer overflow flaws were found in the embedded JasPer
library, which is used to provide support for Part 1 of the JPEG 2000 image
compression standard in the jpeg2ktopam and pamtojpeg2k tools. An attacker
could create a malicious JPEG 2000 compressed image file that could cause
jpeg2ktopam to crash or, potentially, execute arbitrary code with the
privileges of the user running jpeg2ktopam. These flaws do not affect
pamtojpeg2k. (CVE-2011-4516, CVE-2011-4517)

A stack-based buffer overflow flaw was found in the way the xpmtoppm tool
processed X PixMap (XPM) image files. An attacker could create a malicious
XPM file that would cause xpmtoppm to crash or, potentially, execute
arbitrary code with the privileges of the user running xpmtoppm.
(CVE-2009-4274)

Red Hat would like to thank Jonathan Foote of the CERT Coordination Center
for reporting the CVE-2011-4516 and CVE-2011-4517 issues.

All users of netpbm are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-4274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4517</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111811"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111814" severity="medium">
    <xccdf:title>RHSA-2011:1814: ipmitool security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ipmitool package contains a command line utility for interfacing with
devices that support the Intelligent Platform Management Interface (IPMI)
specification. IPMI is an open standard for machine health, inventory, and
remote power control.

It was discovered that the IPMI event daemon (ipmievd) created its process
ID (PID) file with world-writable permissions. A local user could use this
flaw to make the ipmievd init script kill an arbitrary process when the
ipmievd daemon is stopped or restarted. (CVE-2011-4339)

All users of ipmitool are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. After installing this
update, the IPMI event daemon (ipmievd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4339</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111814"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111815" severity="medium">
    <xccdf:title>RHSA-2011:1815: icu security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A stack-based buffer overflow flaw was found in the way ICU performed
variant canonicalization for some locale identifiers. If a
specially-crafted locale representation was opened in an application
linked against ICU, it could cause the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-4599)

All users of ICU should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All applications linked against
ICU must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4599</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111815"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111819" severity="medium">
    <xccdf:title>RHSA-2011:1819: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

A denial of service flaw was found in the way the dhcpd daemon handled DHCP
request packets when regular expression matching was used in
"/etc/dhcp/dhcpd.conf". A remote attacker could use this flaw to crash
dhcpd. (CVE-2011-4539)

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing this update, all
DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1819</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4539</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111819"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111820" severity="medium">
    <xccdf:title>RHSA-2011:1820: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the AOL Open System for
Communication in Realtime (OSCAR) protocol plug-in in Pidgin, used by the
AOL ICQ and AIM instant messaging systems, escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted OSCAR message. (CVE-2011-4601)

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters in channel messages. A remote attacker could use this flaw to
crash Pidgin via a specially-crafted SILC message. (CVE-2011-4603)

Multiple NULL pointer dereference flaws were found in the Jingle extension
of the Extensible Messaging and Presence Protocol (XMPP) protocol plug-in
in Pidgin. A remote attacker could use these flaws to crash Pidgin via a
specially-crafted Jingle multimedia message. (CVE-2011-4602)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Evgeny Boger as the original reporter of
CVE-2011-4601; Diego Bauche Madero from IOActive as the original reporter
of CVE-2011-4603; and Thijs Alkemade as the original reporter of
CVE-2011-4602.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4603</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111820"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111821" severity="medium">
    <xccdf:title>RHSA-2011:1821: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the AOL Open System for
Communication in Realtime (OSCAR) protocol plug-in in Pidgin, used by the
AOL ICQ and AIM instant messaging systems, escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted OSCAR message. (CVE-2011-4601)

Multiple NULL pointer dereference flaws were found in the Jingle extension
of the Extensible Messaging and Presence Protocol (XMPP) protocol plug-in
in Pidgin. A remote attacker could use these flaws to crash Pidgin via a
specially-crafted Jingle multimedia message. (CVE-2011-4602)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Evgeny Boger as the original reporter of
CVE-2011-4601, and Thijs Alkemade as the original reporter of
CVE-2011-4602.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4602</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111821"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111845" severity="medium">
    <xccdf:title>RHSA-2011:1845: tomcat5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that web applications could modify the location of the Tomcat
host's work directory. As web applications deployed on Tomcat have read and
write access to this directory, a malicious web application could use this
flaw to trick Tomcat into giving it read and write access to an arbitrary
directory on the file system. (CVE-2010-3718)

A cross-site scripting (XSS) flaw was found in the Manager application,
used for managing web applications on Apache Tomcat. A malicious web
application could use this flaw to conduct an XSS attack, leading to
arbitrary web script execution with the privileges of victims who are
logged into and viewing Manager application web pages. (CVE-2011-0013)

Multiple flaws were found in the way Tomcat handled HTTP DIGEST
authentication. These flaws weakened the Tomcat HTTP DIGEST authentication
implementation, subjecting it to some of the weaknesses of HTTP BASIC
authentication, for example, allowing remote attackers to perform session
replay attacks. (CVE-2011-1184)

A flaw was found in the Tomcat MemoryUserDatabase. If a runtime exception
occurred when creating a new user with a JMX client, that user's password
was logged to Tomcat log files. Note: By default, only administrators have
access to such log files. (CVE-2011-2204)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5064</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111845"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111849" severity="high">
    <xccdf:title>RHSA-2011:1849: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fix:

* Using the SG_IO IOCTL to issue SCSI requests to partitions or LVM volumes
resulted in the requests being passed to the underlying block device. If a
privileged user only had access to a single partition or LVM volume, they
could use this flaw to bypass those restrictions and gain read and write
access (and be able to issue other SCSI commands) to the entire block
device.

In KVM (Kernel-based Virtual Machine) environments using raw format virtio
disks backed by a partition or LVM volume, a privileged guest user could
bypass intended restrictions and issue read and write requests (and other
SCSI commands) on the host, and possibly access the data of other guests
that reside on the same underlying block device. Partition-based and
LVM-based storage pools are not used by default. Refer to Red Hat Bugzilla
bug 752375 for further details and a mitigation script for users who cannot
apply this update immediately. (CVE-2011-4127, Important)

Bug fixes:

* Previously, idle load balancer kick requests from other CPUs could be
serviced without first receiving an inter-processor interrupt (IPI). This
could have led to a deadlock. (BZ#750459)

* This update fixes a performance regression that may have caused processes
(including KVM guests) to hang for a number of seconds. (BZ#751403)

* When md_raid1_unplug_device() was called while holding a spinlock, under
certain device failure conditions, it was possible for the lock to be
requested again, deeper in the call chain, causing a deadlock. Now,
md_raid1_unplug_device() is no longer called while holding a spinlock.
(BZ#755545)

* In hpet_next_event(), an interrupt could have occurred between the read
and write of the HPET (High Performance Event Timer) and the value of
HPET_COUNTER was then beyond that being written to the comparator
(HPET_Tn_CMP). Consequently, the timers were overdue for up to several
minutes. Now, a comparison is performed between the value of the counter
and the comparator in the HPET code. If the counter is beyond the
comparator, the "-ETIME" error code is returned. (BZ#756426)

* Index allocation in the virtio-blk module was based on a monotonically
increasing variable "index". Consequently, released indexes were not reused
and after a period of time, no new were available. Now, virtio-blk uses the
ida API to allocate indexes. (BZ#756427)

* A bug related to Context Caching existed in the Intel IOMMU support
module. On some newer Intel systems, the Context Cache mode has changed
from previous hardware versions, potentially exposing a Context coherency
race. The bug was exposed when performing a series of hot plug and unplug
operations of a Virtual Function network device which was immediately
configured into the network stack, i.e., successfully performed dynamic
host configuration protocol (DHCP). When the coherency race occurred, the
assigned device would not work properly in the guest virtual machine. With
this update, the Context coherency is corrected and the race and
potentially resulting device assignment failure no longer occurs.
(BZ#757671)

* The align_va_addr kernel parameter was ignored if secondary CPUs were
initialized. This happened because the parameter settings were overridden
during the initialization of secondary CPUs. Also, the align_va_addr
parameter documentation contained incorrect parameter arguments. With this
update, the underlying code has been modified to prevent the overriding and
the documentation has been updated. This update also removes the unused
code introduced by the patch for BZ#739456. (BZ#758028)

* Dell systems based on a future Intel processor with graphics acceleration
required the selection of the install system with basic video driver
installation option. This update removes this requirement. (BZ#758513)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4621</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111849"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111851" severity="high">
    <xccdf:title>RHSA-2011:1851: krb5 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and servers
to authenticate to each other using symmetric encryption and a trusted third-
party, the Key Distribution Center (KDC).

A buffer overflow flaw was found in the MIT krb5 telnet daemon (telnetd). A
remote attacker who can access the telnet port of a target machine could use
this flaw to execute arbitrary code as root. (CVE-2011-4862)

Note that the krb5 telnet daemon is not enabled by default in any version of 
Red Hat Enterprise Linux. In addition, the default firewall rules block
remote access to the telnet port. This flaw does not affect the telnet
daemon distributed in the telnet-server package.

For users who have installed the krb5-workstation package, have enabled the
telnet daemon, and have it accessible remotely, this update should be
applied immediately. 

All krb5-workstation users should upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1851</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4862</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111851"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20111852" severity="high">
    <xccdf:title>RHSA-2011:1852: krb5-appl security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The krb5-appl packages provide Kerberos-aware telnet, ftp, rcp, rsh, and
rlogin clients and servers. Kerberos is a network authentication system
which allows clients and servers to authenticate to each other using
symmetric encryption and a trusted third-party, the Key Distribution Center
(KDC).

A buffer overflow flaw was found in the MIT krb5 telnet daemon (telnetd). A 
remote attacker who can access the telnet port of a target machine could use
this flaw to execute arbitrary code as root. (CVE-2011-4862) 

Note that the krb5 telnet daemon is not enabled by default in any version of
Red Hat Enterprise Linux. In addition, the default firewall rules block
remote access to the telnet port. This flaw does not affect the telnet
daemon distributed in the telnet-server package.

For users who have installed the krb5-appl-servers package, have enabled the 
krb5 telnet daemon, and have it accessible remotely, this update should be
applied immediately. 

All krb5-appl-server users should upgrade to these updated packages, which 
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2011:1852</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4862</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20111852"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120007" severity="high">
    <xccdf:title>RHSA-2012:0007: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the way the Linux kernel's XFS file
system implementation handled links with overly long path names. A local,
unprivileged user could use this flaw to cause a denial of service or
escalate their privileges by mounting a specially-crafted disk.
(CVE-2011-4077, Important)

* The fix for CVE-2011-2482 provided by RHSA-2011:1212 introduced a
regression: on systems that do not have Security-Enhanced Linux (SELinux)
in Enforcing mode, a socket lock race could occur between sctp_rcv() and
sctp_accept(). A remote attacker could use this flaw to cause a denial of
service. By default, SELinux runs in Enforcing mode on Red Hat Enterprise
Linux 5. (CVE-2011-4348, Important)

* The proc file system could allow a local, unprivileged user to obtain
sensitive information or possibly cause integrity issues. (CVE-2011-1020,
Moderate)

* A missing validation flaw was found in the Linux kernel's m_stop()
implementation. A local, unprivileged user could use this flaw to trigger a
denial of service. (CVE-2011-3637, Moderate)

* A flaw was found in the Linux kernel's Journaling Block Device (JBD).
A local attacker could use this flaw to crash the system by mounting a
specially-crafted ext3 or ext4 disk. (CVE-2011-4132, Moderate)

* A flaw was found in the Linux kernel's encode_share_access()
implementation. A local, unprivileged user could use this flaw to trigger a
denial of service by creating a regular file on an NFSv4 (Network File
System version 4) file system via mknod(). (CVE-2011-4324, Moderate)

* A flaw was found in the Linux kernel's NFS implementation. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2011-4325, Moderate)

* A missing boundary check was found in the Linux kernel's HFS file system
implementation. A local attacker could use this flaw to cause a denial of
service or escalate their privileges by mounting a specially-crafted disk.
(CVE-2011-4330, Moderate)

Red Hat would like to thank Kees Cook for reporting CVE-2011-1020, and
Clement Lecigne for reporting CVE-2011-4330.

This update also fixes several bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1020</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3637</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4348</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120007"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120016" severity="high">
    <xccdf:title>RHSA-2012:0016: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards. One of those standards is the XML Path Language
(XPath), which is a language for addressing parts of an XML document.

A heap-based buffer overflow flaw was found in the way libxml2 decoded
entity references with long names. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-3919)

An off-by-one error, leading to a heap-based buffer overflow, was found in
the way libxml2 parsed certain XML files. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0216)

A flaw was found in the way libxml2 parsed certain XPath expressions. If an
attacker were able to supply a specially-crafted XML file to an application
using libxml2, as well as an XPath expression for that application to run
against the crafted file, it could cause the application to crash.
(CVE-2011-2834)

Note: Red Hat does not ship any applications that use libxml2 in a way that
would allow the CVE-2011-2834 flaw to be exploited; however, third-party
applications may allow XPath expressions to be passed which could trigger
this flaw.

An out-of-bounds memory read flaw was found in libxml2. A remote attacker
could provide a specially-crafted XML file that, when opened in an
application linked against libxml2, would cause the application to crash.
(CVE-2011-3905)

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3919</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120017" severity="high">
    <xccdf:title>RHSA-2012:0017: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards. One of those standards is the XML Path Language
(XPath), which is a language for addressing parts of an XML document.

A heap-based buffer overflow flaw was found in the way libxml2 decoded
entity references with long names. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-3919)

An off-by-one error, leading to a heap-based buffer overflow, was found in
the way libxml2 parsed certain XML files. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0216)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way libxml2 parsed certain XPath expressions. If an attacker
were able to supply a specially-crafted XML file to an application using
libxml2, as well as an XPath expression for that application to run against
the crafted file, it could cause the application to crash or, possibly,
execute arbitrary code. (CVE-2011-1944)

Flaws were found in the way libxml2 parsed certain XPath expressions. If an
attacker were able to supply a specially-crafted XML file to an application
using libxml2, as well as an XPath expression for that application to run
against the crafted file, it could cause the application to crash.
(CVE-2010-4008, CVE-2011-2834)

An out-of-bounds memory read flaw was found in libxml2. A remote attacker
could provide a specially-crafted XML file that, when opened in an
application linked against libxml2, would cause the application to crash.
(CVE-2011-3905)

Note: Red Hat does not ship any applications that use libxml2 in a way that
would allow the CVE-2011-1944, CVE-2010-4008, and CVE-2011-2834 flaws to be
exploited; however, third-party applications may allow XPath expressions to
be passed which could trigger these flaws.

Red Hat would like to thank the Google Security Team for reporting the
CVE-2010-4008 issue. Upstream acknowledges Bui Quang Minh from Bkis as the
original reporter of CVE-2010-4008.

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3919</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120017"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120018" severity="high">
    <xccdf:title>RHSA-2012:0018: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A heap-based buffer overflow flaw was found in the way libxml2 decoded
entity references with long names. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-3919)

An out-of-bounds memory read flaw was found in libxml2. A remote attacker
could provide a specially-crafted XML file that, when opened in an
application linked against libxml2, would cause the application to crash.
(CVE-2011-3905)

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3919</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120018"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120019" severity="medium">
    <xccdf:title>RHSA-2012:0019: php53 and php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that the hashing routine used by PHP arrays was susceptible
to predictable hash collisions. If an HTTP POST request to a PHP
application contained many parameters whose names map to the same hash
value, a large amount of CPU time would be consumed. This flaw has been
mitigated by adding a new configuration directive, max_input_vars, that
limits the maximum number of parameters processed per request. By
default, max_input_vars is set to 1000. (CVE-2011-4885)

An integer overflow flaw was found in the PHP exif extension. On 32-bit
systems, a specially-crafted image file could cause the PHP interpreter to
crash or disclose portions of its memory when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-4566)

Red Hat would like to thank oCERT for reporting CVE-2011-4885. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4885.

All php53 and php users should upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4885</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120019"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120033" severity="medium">
    <xccdf:title>RHSA-2012:0033: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that the hashing routine used by PHP arrays was susceptible
to predictable hash collisions. If an HTTP POST request to a PHP
application contained many parameters whose names map to the same hash
value, a large amount of CPU time would be consumed. This flaw has been
mitigated by adding a new configuration directive, max_input_vars, that
limits the maximum number of parameters processed per request. By
default, max_input_vars is set to 1000. (CVE-2011-4885)

A use-after-free flaw was found in the PHP substr_replace() function. If a
PHP script used the same variable as multiple function arguments, a remote
attacker could possibly use this to crash the PHP interpreter or, possibly,
execute arbitrary code. (CVE-2011-1148)

An integer overflow flaw was found in the PHP exif extension. On 32-bit
systems, a specially-crafted image file could cause the PHP interpreter to
crash or disclose portions of its memory when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-4566)

An insufficient input validation flaw, leading to a buffer over-read, was
found in the PHP exif extension. A specially-crafted image file could cause
the PHP interpreter to crash when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-0708)

An integer overflow flaw was found in the PHP calendar extension. A remote
attacker able to make a PHP script call SdnToJulian() with a large value
could cause the PHP interpreter to crash. (CVE-2011-1466)

A bug in the PHP Streams component caused the PHP interpreter to crash if
an FTP wrapper connection was made through an HTTP proxy. A remote attacker
could possibly trigger this issue if a PHP script accepted an untrusted URL
to connect to. (CVE-2011-1469)

An off-by-one flaw was found in PHP. If an attacker uploaded a file with a
specially-crafted file name it could cause a PHP script to attempt to write
a file to the root (/) directory. By default, PHP runs as the "apache"
user, preventing it from writing to the root directory. (CVE-2011-2202)

Red Hat would like to thank oCERT for reporting CVE-2011-4885. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4885.

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4885</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120033"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120050" severity="high">
    <xccdf:title>RHSA-2012:0050: qemu-kvm security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

A heap overflow flaw was found in the way QEMU-KVM emulated the e1000
network interface card. A privileged guest user in a virtual machine whose
network interface is configured to use the e1000 emulated driver could use
this flaw to crash the host or, possibly, escalate their privileges on the
host. (CVE-2012-0029)

Red Hat would like to thank Nicolae Mogoreanu for reporting this issue.

This update also fixes the following bug:

* qemu-kvm has a "scsi" option, to be used, for example, with the
"-device" option: "-device virtio-blk-pci,drive=[drive name],scsi=off".
Previously, however, it only masked the feature bit, and did not reject
SCSI commands if a malicious guest ignored the feature bit and issued a
request. This update corrects this issue. The "scsi=off" option can be
used to mitigate the virtualization aspect of CVE-2011-4127 before the
RHSA-2011:1849 kernel update is installed on the host.

This mitigation is only required if you do not have the RHSA-2011:1849
kernel update installed on the host and you are using raw format virtio
disks backed by a partition or LVM volume.

If you run guests by invoking /usr/libexec/qemu-kvm directly, use the
"-global virtio-blk-pci.scsi=off" option to apply the mitigation. If you
are using libvirt, as recommended by Red Hat, and have the RHBA-2012:0013
libvirt update installed, no manual action is required: guests will
automatically use "scsi=off". (BZ#767721)

Note: After installing the RHSA-2011:1849 kernel update, SCSI requests
issued by guests via the SG_IO IOCTL will not be passed to the underlying
block device when using raw format virtio disks backed by a partition or
LVM volume, even if "scsi=on" is used.

As well, this update adds the following enhancement:

* Prior to this update, qemu-kvm was not built with RELRO or PIE support.
qemu-kvm is now built with full RELRO and PIE support as a security
enhancement. (BZ#767906)

All users of qemu-kvm should upgrade to these updated packages, which
correct these issues and add this enhancement. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0050</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120050"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120051" severity="high">
    <xccdf:title>RHSA-2012:0051: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A heap overflow flaw was found in the way QEMU-KVM emulated the e1000
network interface card. A privileged guest user in a virtual machine whose
network interface is configured to use the e1000 emulated driver could use
this flaw to crash the host or, possibly, escalate their privileges on the
host. (CVE-2012-0029)

A flaw was found in the way the KVM subsystem of a Linux kernel handled PIT
(Programmable Interval Timer) IRQs (interrupt requests) when there was no
virtual interrupt controller set up. A malicious user in the kvm group on
the host could force this situation to occur, resulting in the host
crashing. (CVE-2011-4622)

Red Hat would like to thank Nicolae Mogoreanu for reporting CVE-2012-0029.

All KVM users should upgrade to these updated packages, which contain
backported patches to correct these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4622</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120051"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120052" severity="high">
    <xccdf:title>RHSA-2012:0052: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that permissions were not checked properly in the Linux
kernel when handling the /proc/[pid]/mem writing functionality. A local,
unprivileged user could use this flaw to escalate their privileges. Refer
to Red Hat Knowledgebase article DOC-69129, linked to in the References,
for further information. (CVE-2012-0056, Important)

Red Hat would like to thank Jüri Aedla for reporting this issue.

This update fixes the following bugs:

* The RHSA-2011:1849 kernel update introduced a bug in the Linux kernel
scheduler, causing a "WARNING: at kernel/sched.c:5915 thread_return"
message and a call trace to be logged. This message was harmless, and was
not due to any system malfunctions or adverse behavior. With this update,
the WARN_ON_ONCE() call in the scheduler that caused this harmless message
has been removed. (BZ#768288)

* The RHSA-2011:1530 kernel update introduced a regression in the way
the Linux kernel maps ELF headers for kernel modules into kernel memory.
If a third-party kernel module is compiled on a Red Hat Enterprise Linux
system with a kernel prior to RHSA-2011:1530, then loading that module on
a system with RHSA-2011:1530 kernel would result in corruption of one byte
in the memory reserved for the module. In some cases, this could prevent
the module from functioning correctly. (BZ#769595)

* On some SMP systems the tsc may erroneously be marked as unstable during
early system boot or while the system is under heavy load. A "Clocksource
tsc unstable" message was logged when this occurred. As a result the system
would switch to the slower access, but higher precision HPET clock.

The "tsc=reliable" kernel parameter is supposed to avoid this problem by
indicating that the system has a known good clock, however, the parameter
only affected run time checks.  A fix has been put in to avoid the boot
time checks so that the TSC remains as the clock for the duration of
system runtime. (BZ#755867)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0056</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120052"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120058" severity="medium">
    <xccdf:title>RHSA-2012:0058: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the glibc library read timezone files. If a
carefully-crafted timezone file was loaded by an application linked against
glibc, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-5029)

A denial of service flaw was found in the remote procedure call (RPC)
implementation in glibc. A remote attacker able to open a large number of
connections to an RPC service that is using the RPC implementation from
glibc, could use this flaw to make that service use an excessive amount of
CPU time. (CVE-2011-4609)

This update also fixes the following bugs:

* glibc had incorrect information for numeric separators and groupings for
specific French, Spanish, and German locales. Therefore, applications
utilizing glibc's locale support printed numbers with the wrong separators
and groupings when those locales were in use. With this update, the
separator and grouping information has been fixed. (BZ#754116)

* The RHBA-2011:1179 glibc update introduced a regression, causing glibc to
incorrectly parse groups with more than 126 members, resulting in
applications such as "id" failing to list all the groups a particular user
was a member of. With this update, group parsing has been fixed.
(BZ#766484)

* glibc incorrectly allocated too much memory due to a race condition
within its own malloc routines. This could cause a multi-threaded
application to allocate more memory than was expected. With this update,
the race condition has been fixed, and malloc's behavior is now consistent
with the documentation regarding the MALLOC_ARENA_TEST and MALLOC_ARENA_MAX
environment variables. (BZ#769594)

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0058</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120058"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120059" severity="medium">
    <xccdf:title>RHSA-2012:0059: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that the Datagram Transport Layer Security (DTLS)
protocol implementation in OpenSSL leaked timing information when
performing certain operations. A remote attacker could possibly use this
flaw to retrieve plain text from the encrypted packets by using a DTLS
server as a padding oracle. (CVE-2011-4108)

An information leak flaw was found in the SSL 3.0 protocol implementation
in OpenSSL. Incorrect initialization of SSL record padding bytes could
cause an SSL client or server to send a limited amount of possibly
sensitive data to its SSL peer via the encrypted connection.
(CVE-2011-4576)

A denial of service flaw was found in the RFC 3779 implementation in
OpenSSL. A remote attacker could use this flaw to make an application using
OpenSSL exit unexpectedly by providing a specially-crafted X.509
certificate that has malformed RFC 3779 extension data. (CVE-2011-4577)

It was discovered that OpenSSL did not limit the number of TLS/SSL
handshake restarts required to support Server Gated Cryptography. A remote
attacker could use this flaw to make a TLS/SSL server using OpenSSL consume
an excessive amount of CPU by continuously restarting the handshake.
(CVE-2011-4619)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4619</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120059"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120060" severity="medium">
    <xccdf:title>RHSA-2012:0060: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that the Datagram Transport Layer Security (DTLS)
protocol implementation in OpenSSL leaked timing information when
performing certain operations. A remote attacker could possibly use this
flaw to retrieve plain text from the encrypted packets by using a DTLS
server as a padding oracle. (CVE-2011-4108)

A double free flaw was discovered in the policy checking code in OpenSSL.
A remote attacker could use this flaw to crash an application that uses
OpenSSL by providing an X.509 certificate that has specially-crafted
policy extension data. (CVE-2011-4109)

An information leak flaw was found in the SSL 3.0 protocol implementation
in OpenSSL. Incorrect initialization of SSL record padding bytes could
cause an SSL client or server to send a limited amount of possibly
sensitive data to its SSL peer via the encrypted connection.
(CVE-2011-4576)

It was discovered that OpenSSL did not limit the number of TLS/SSL
handshake restarts required to support Server Gated Cryptography. A remote
attacker could use this flaw to make a TLS/SSL server using OpenSSL consume
an excessive amount of CPU by continuously restarting the handshake.
(CVE-2011-4619)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4109</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4619</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120060"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120062" severity="medium">
    <xccdf:title>RHSA-2012:0062: t1lib security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The t1lib library allows you to rasterize bitmaps from PostScript Type 1
fonts.

Two heap-based buffer overflow flaws were found in the way t1lib processed
Adobe Font Metrics (AFM) files. If a specially-crafted font file was opened
by an application linked against t1lib, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2010-2642, CVE-2011-0433)

An invalid pointer dereference flaw was found in t1lib. A specially-crafted
font file could, when opened, cause an application linked against t1lib to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-0764)

A use-after-free flaw was found in t1lib. A specially-crafted font file
could, when opened, cause an application linked against t1lib to crash or,
potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-1553)

An off-by-one flaw was found in t1lib. A specially-crafted font file could,
when opened, cause an application linked against t1lib to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-1554)

An out-of-bounds memory read flaw was found in t1lib. A specially-crafted
font file could, when opened, cause an application linked against t1lib to
crash. (CVE-2011-1552)

Red Hat would like to thank the Evince development team for reporting
CVE-2010-2642. Upstream acknowledges Jon Larimer of IBM X-Force as the
original reporter of CVE-2010-2642.

All users of t1lib are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All applications linked
against t1lib must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1554</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120062"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120069" severity="medium">
    <xccdf:title>RHSA-2012:0069: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A denial of service flaw was found in the implementation of associative
arrays (hashes) in Ruby. An attacker able to supply a large number of
inputs to a Ruby application (such as HTTP POST request parameters sent to
a web application) that are used as keys when inserting data into an array
could trigger multiple hash function collisions, making array operations
take an excessive amount of CPU time. To mitigate this issue, randomization
has been added to the hash function to reduce the chance of an attacker
successfully causing intentional collisions. (CVE-2011-4815)

Red Hat would like to thank oCERT for reporting this issue. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters.

All users of ruby are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4815</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120069"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120070" severity="medium">
    <xccdf:title>RHSA-2012:0070: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A denial of service flaw was found in the implementation of associative
arrays (hashes) in Ruby. An attacker able to supply a large number of
inputs to a Ruby application (such as HTTP POST request parameters sent to
a web application) that are used as keys when inserting data into an array
could trigger multiple hash function collisions, making array operations
take an excessive amount of CPU time. To mitigate this issue, randomization
has been added to the hash function to reduce the chance of an attacker
successfully causing intentional collisions. (CVE-2011-4815)

It was found that Ruby did not reinitialize the PRNG (pseudorandom number
generator) after forking a child process. This could eventually lead to the
PRNG returning the same result twice. An attacker keeping track of the
values returned by one child process could use this flaw to predict the
values the PRNG would return in other child processes (as long as the
parent process persisted). (CVE-2011-3009)

Red Hat would like to thank oCERT for reporting CVE-2011-4815. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4815.

All users of ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4815</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120070"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120071" severity="medium">
    <xccdf:title>RHSA-2012:0071: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that the hashing routine used by PHP arrays was susceptible
to predictable hash collisions. If an HTTP POST request to a PHP
application contained many parameters whose names map to the same hash
value, a large amount of CPU time would be consumed. This flaw has been
mitigated by adding a new configuration directive, max_input_vars, that
limits the maximum number of parameters processed per request. By
default, max_input_vars is set to 1000. (CVE-2011-4885)

An integer overflow flaw was found in the PHP exif extension. On 32-bit
systems, a specially-crafted image file could cause the PHP interpreter to
crash or disclose portions of its memory when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-4566)

An insufficient input validation flaw, leading to a buffer over-read, was
found in the PHP exif extension. A specially-crafted image file could cause
the PHP interpreter to crash when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-0708)

An integer overflow flaw was found in the PHP calendar extension. A remote
attacker able to make a PHP script call SdnToJulian() with a large value
could cause the PHP interpreter to crash. (CVE-2011-1466)

An off-by-one flaw was found in PHP. If an attacker uploaded a file with a
specially-crafted file name it could cause a PHP script to attempt to write
a file to the root (/) directory. By default, PHP runs as the "apache"
user, preventing it from writing to the root directory. (CVE-2011-2202)

Red Hat would like to thank oCERT for reporting CVE-2011-4885. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4885.

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4885</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120071"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120073" severity="low">
    <xccdf:title>RHSA-2012:0073: Red Hat Enterprise Linux 4 - 30 day End Of Life Notice (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>In accordance with the Red Hat Enterprise Linux Errata Support Policy,
the 7 year life-cycle of Red Hat Enterprise Linux 4 will end on February
29, 2012 and your subscription services for that version will change.
Active Red Hat Enterprise Linux subscribers using Red Hat Enterprise
Linux 4 will have the option to upgrade to currently supported versions
of Red Hat Enterprise Linux and receive the full benefits of the
subscription.

After February 29, 2012, Red Hat will discontinue technical support
services as well as software maintenance services for Red Hat Enterprise
Linux 4 meaning that new bug fixes, security errata and product
enhancements will no longer be provided for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers who choose to continue to deploy Red Hat Enterprise Linux 4
offerings will continue to have access via Red Hat Network (RHN) to the
following content as part of their active Red Hat Enterprise Linux
subscription:

- Previously released bug fixes, security errata and product
  enhancements.
- Red Hat Knowledge Base and other content (whitepapers, reference
  architectures, etc) found in the Red Hat Customer Portal.
- All Red Hat Enterprise Linux 4 documentation.

Customers are strongly encouraged to take advantage of the upgrade
benefits of their active Red Hat Enterprise Linux subscription and
migrate to an active version of Red Hat Enterprise Linux such as
version 5 or 6.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date and require software maintenance and/or
technical support, Red Hat offers an optional support extension called
the Extended Life-cycle Support (ELS) Add-On Subscription. The ELS
Subscription provides up to three additional years of limited Software
Maintenance (Production 3 Phase) for Red Hat Enterprise Linux 4 with
unlimited technical support, critical Security Advisories (RHSAs) and
selected Urgent Priority Bug Advisories (RHBAs). For more information,
contact your Red Hat sales representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the
Red Hat website: https://access.redhat.com/support/policy/updates/errata/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0073</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120073"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120079" severity="high">
    <xccdf:title>RHSA-2012:0079: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A use-after-free flaw was found in the way Firefox removed nsDOMAttribute
child nodes. In certain circumstances, due to the premature notification
of AttributeChildRemoved, a malicious script could possibly use this flaw
to cause Firefox to crash or, potentially, execute arbitrary code with the
privileges of the user running Firefox. (CVE-2011-3659)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-0442)

A flaw was found in the way Firefox parsed Ogg Vorbis media files. A web
page containing a malicious Ogg Vorbis media file could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2012-0444)

A flaw was found in the way Firefox parsed certain Scalable Vector Graphics
(SVG) image files that contained eXtensible Style Sheet Language
Transformations (XSLT). A web page containing a malicious SVG image file
could cause Firefox to crash or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2012-0449)

The same-origin policy in Firefox treated http://example.com and
http://[example.com] as interchangeable. A malicious script could possibly
use this flaw to gain access to sensitive information (such as a client's
IP and user e-mail address, or httpOnly cookies) that may be included in
HTTP proxy error replies, generated in response to invalid URLs using
square brackets. (CVE-2011-3670)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.26. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.26, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0449</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120079"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120080" severity="high">
    <xccdf:title>RHSA-2012:0080: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A use-after-free flaw was found in the way Thunderbird removed
nsDOMAttribute child nodes. In certain circumstances, due to the premature
notification of AttributeChildRemoved, a malicious script could possibly
use this flaw to cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-3659)

Several flaws were found in the processing of malformed content. An HTML
mail message containing malicious content could cause Thunderbird to crash
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2012-0442)

A flaw was found in the way Thunderbird parsed certain Scalable Vector
Graphics (SVG) image files that contained eXtensible Style Sheet Language
Transformations (XSLT). An HTML mail message containing a malicious SVG
image file could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2012-0449)

The same-origin policy in Thunderbird treated http://example.com and
http://[example.com] as interchangeable. A malicious script could possibly
use this flaw to gain access to sensitive information (such as a client's
IP and user e-mail address, or httpOnly cookies) that may be included in
HTTP proxy error replies, generated in response to invalid URLs using
square brackets. (CVE-2011-3670)

Note: The CVE-2011-3659 and CVE-2011-3670 issues cannot be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. It could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 3.1.18. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to these updated packages, which
contain Thunderbird version 3.1.18, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0449</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120080"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120084" severity="high">
    <xccdf:title>RHSA-2012:0084: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, e-mail and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the processing of malformed web content. A web page
containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2012-0442)

The same-origin policy in SeaMonkey treated http://example.com and
http://[example.com] as interchangeable. A malicious script could possibly
use this flaw to gain access to sensitive information (such as a client's
IP and user e-mail address, or httpOnly cookies) that may be included in
HTTP proxy error replies, generated in response to invalid URLs using
square brackets. (CVE-2011-3670)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0442</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120084"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120085" severity="high">
    <xccdf:title>RHSA-2012:0085: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the processing of malformed content. An HTML mail
message containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2012-0442)

The same-origin policy in Thunderbird treated http://example.com and
http://[example.com] as interchangeable. A malicious script could possibly
use this flaw to gain access to sensitive information (such as a client's
IP and user e-mail address, or httpOnly cookies) that may be included in
HTTP proxy error replies, generated in response to invalid URLs using
square brackets. (CVE-2011-3670)

Note: The CVE-2011-3670 issue cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
It could be exploited another way in Thunderbird, for example, when viewing
the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0442</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120085"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120086" severity="medium">
    <xccdf:title>RHSA-2012:0086: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An information leak flaw was found in the SSL 3.0 protocol implementation
in OpenSSL. Incorrect initialization of SSL record padding bytes could
cause an SSL client or server to send a limited amount of possibly
sensitive data to its SSL peer via the encrypted connection.
(CVE-2011-4576)

It was discovered that OpenSSL did not limit the number of TLS/SSL
handshake restarts required to support Server Gated Cryptography. A remote
attacker could use this flaw to make a TLS/SSL server using OpenSSL consume
an excessive amount of CPU by continuously restarting the handshake.
(CVE-2011-4619)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4619</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120086"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120092" severity="high">
    <xccdf:title>RHSA-2012:0092: php53 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was discovered that the fix for CVE-2011-4885 (released via
RHSA-2012:0019 for php53 packages in Red Hat Enterprise Linux 5) introduced
an uninitialized memory use flaw. A remote attacker could send a specially-
crafted HTTP request to cause the PHP interpreter to crash or, possibly,
execute arbitrary code. (CVE-2012-0830)

All php53 users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0830</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120092"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120093" severity="high">
    <xccdf:title>RHSA-2012:0093: php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was discovered that the fix for CVE-2011-4885 (released via
RHSA-2012:0071, RHSA-2012:0033, and RHSA-2012:0019 for php packages in Red
Hat Enterprise Linux 4, 5, and 6 respectively) introduced an uninitialized
memory use flaw. A remote attacker could send a specially-crafted HTTP
request to cause the PHP interpreter to crash or, possibly, execute
arbitrary code. (CVE-2012-0830)

All php users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0830</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120093"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120095" severity="medium">
    <xccdf:title>RHSA-2012:0095: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

An integer overflow flaw was found in Ghostscript's TrueType bytecode
interpreter. An attacker could create a specially-crafted PostScript or PDF
file that, when interpreted, could cause Ghostscript to crash or,
potentially, execute arbitrary code. (CVE-2009-3743)

It was found that Ghostscript always tried to read Ghostscript system
initialization files from the current working directory before checking
other directories, even if a search path that did not contain the current
working directory was specified with the "-I" option, or the "-P-" option
was used (to prevent the current working directory being searched first).
If a user ran Ghostscript in an attacker-controlled directory containing a
system initialization file, it could cause Ghostscript to execute arbitrary
PostScript code. (CVE-2010-2055)

Ghostscript included the current working directory in its library search
path by default. If a user ran Ghostscript without the "-P-" option in an
attacker-controlled directory containing a specially-crafted PostScript
library file, it could cause Ghostscript to execute arbitrary PostScript
code. With this update, Ghostscript no longer searches the current working
directory for library files by default. (CVE-2010-4820)

Note: The fix for CVE-2010-4820 could possibly break existing
configurations. To use the previous, vulnerable behavior, run Ghostscript
with the "-P" option (to always search the current working directory
first).

A flaw was found in the way Ghostscript interpreted PostScript Type 1 and
PostScript Type 2 font files. An attacker could create a specially-crafted
PostScript Type 1 or PostScript Type 2 font file that, when interpreted,
could cause Ghostscript to crash or, potentially, execute arbitrary code.
(CVE-2010-4054)

Users of Ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3743</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4820</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120095"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120096" severity="medium">
    <xccdf:title>RHSA-2012:0096: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

Ghostscript included the current working directory in its library search
path by default. If a user ran Ghostscript without the "-P-" option in an
attacker-controlled directory containing a specially-crafted PostScript
library file, it could cause Ghostscript to execute arbitrary PostScript
code. With this update, Ghostscript no longer searches the current working
directory for library files by default. (CVE-2010-4820)

Note: The fix for CVE-2010-4820 could possibly break existing
configurations. To use the previous, vulnerable behavior, run Ghostscript
with the "-P" option (to always search the current working directory
first).

A flaw was found in the way Ghostscript interpreted PostScript Type 1 and
PostScript Type 2 font files. An attacker could create a specially-crafted
PostScript Type 1 or PostScript Type 2 font file that, when interpreted,
could cause Ghostscript to crash or, potentially, execute arbitrary code.
(CVE-2010-4054)

Users of Ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4820</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120096"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120103" severity="medium">
    <xccdf:title>RHSA-2012:0103: squirrelmail security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

A cross-site scripting (XSS) flaw was found in the way SquirrelMail
performed the sanitization of HTML style tag content. A remote attacker
could use this flaw to send a specially-crafted Multipurpose Internet Mail
Extensions (MIME) message that, when opened by a victim, would lead to
arbitrary web script execution in the context of their SquirrelMail
session. (CVE-2011-2023)

Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. A
remote attacker could possibly use these flaws to execute arbitrary web
script in the context of a victim's SquirrelMail session. (CVE-2010-4555)

An input sanitization flaw was found in the way SquirrelMail handled the
content of various HTML input fields. A remote attacker could use this
flaw to alter user preference values via a newline character contained in
the input for these fields. (CVE-2011-2752)

It was found that the SquirrelMail Empty Trash and Index Order pages did
not protect against Cross-Site Request Forgery (CSRF) attacks. If a remote
attacker could trick a user, who was logged into SquirrelMail, into
visiting a specially-crafted URL, the attacker could empty the victim's
trash folder or alter the ordering of the columns on the message index
page. (CVE-2011-2753)

SquirrelMail was allowed to be loaded into an HTML sub-frame, allowing a
remote attacker to perform a clickjacking attack against logged in users
and possibly gain access to sensitive user data. With this update, the
SquirrelMail main frame can only be loaded into the top most browser frame.
(CVE-2010-4554)

A flaw was found in the way SquirrelMail handled failed log in attempts. A
user preference file was created when attempting to log in with a password
containing an 8-bit character, even if the username was not valid. A
remote attacker could use this flaw to eventually consume all hard disk
space on the target SquirrelMail server. (CVE-2010-2813)

A flaw was found in the SquirrelMail Mail Fetch plug-in. If an
administrator enabled this plug-in, a SquirrelMail user could use this flaw
to port scan the local network the server was on. (CVE-2010-1637)

Users of SquirrelMail should upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0103</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1637</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2753</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120103"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120105" severity="high">
    <xccdf:title>RHSA-2012:0105: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2011-2262,
CVE-2012-0075, CVE-2012-0087, CVE-2012-0101, CVE-2012-0102, CVE-2012-0112,
CVE-2012-0113, CVE-2012-0114, CVE-2012-0115, CVE-2012-0116, CVE-2012-0118,
CVE-2012-0119, CVE-2012-0120, CVE-2012-0484, CVE-2012-0485, CVE-2012-0490,
CVE-2012-0492)

These updated packages upgrade MySQL to version 5.1.61. Refer to the MySQL
release notes for a full list of changes:

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0113</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0118</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0119</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0120</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0583</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120105"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120107" severity="high">
    <xccdf:title>RHSA-2012:0107: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Using the SG_IO ioctl to issue SCSI requests to partitions or LVM volumes
resulted in the requests being passed to the underlying block device. If a
privileged user only had access to a single partition or LVM volume, they
could use this flaw to bypass those restrictions and gain read and write
access (and be able to issue other SCSI commands) to the entire block
device. Refer to Red Hat Knowledgebase article DOC-67874, linked to in the
References, for further details about this issue. (CVE-2011-4127,
Important)

* A flaw was found in the way the Linux kernel handled robust list pointers
of user-space held futexes across exec() calls. A local, unprivileged user
could use this flaw to cause a denial of service or, eventually, escalate
their privileges. (CVE-2012-0028, Important)

* A flaw was found in the Linux kernel in the way splitting two extents in
ext4_ext_convert_to_initialized() worked. A local, unprivileged user with
the ability to mount and unmount ext4 file systems could use this flaw to
cause a denial of service. (CVE-2011-3638, Moderate)

* A flaw was found in the way the Linux kernel's journal_unmap_buffer()
function handled buffer head states. On systems that have an ext4 file
system with a journal mounted, a local, unprivileged user could use this
flaw to cause a denial of service. (CVE-2011-4086, Moderate)

* A divide-by-zero flaw was found in the Linux kernel's igmp_heard_query()
function. An attacker able to send certain IGMP (Internet Group Management
Protocol) packets to a target system could use this flaw to cause a denial
of service. (CVE-2012-0207, Moderate)

Red Hat would like to thank Zheng Liu for reporting CVE-2011-3638, and
Simon McVittie for reporting CVE-2012-0207.

This update also fixes the following bugs:

* When a host was in recovery mode and a SCSI scan operation was initiated,
the scan operation failed and provided no error output. This bug has been
fixed and the SCSI layer now waits for recovery of the host to complete
scan operations for devices. (BZ#772162)

* SG_IO ioctls were not implemented correctly in the Red Hat Enterprise
Linux 5 virtio-blk driver. Sending an SG_IO ioctl request to a virtio-blk
disk caused the sending thread to enter an uninterruptible sleep state ("D"
state). With this update, SG_IO ioctls are rejected by the virtio-blk
driver: the ioctl system call will simply return an ENOTTY ("Inappropriate
ioctl for device") error and the thread will continue normally. (BZ#773322)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0107</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0207</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120107"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120125" severity="medium">
    <xccdf:title>RHSA-2012:0125: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the glibc library read timezone files. If a
carefully-crafted timezone file was loaded by an application linked against
glibc, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-5029)

A flaw was found in the way the ldd utility identified dynamically linked
libraries. If an attacker could trick a user into running ldd on a
malicious binary, it could result in arbitrary code execution with the
privileges of the user running ldd. (CVE-2009-5064)

It was discovered that the glibc addmntent() function, used by various
mount helper utilities, did not sanitize its input properly. A local
attacker could possibly use this flaw to inject malformed lines into the
mtab (mounted file systems table) file via certain setuid mount helpers, if
the attacker were allowed to mount to an arbitrary directory under their
control. (CVE-2010-0296)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the glibc library loaded ELF (Executable and Linking
Format) files. If a carefully-crafted ELF file was loaded by an
application linked against glibc, it could cause the application to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2010-0830)

It was discovered that the glibc fnmatch() function did not properly
restrict the use of alloca(). If the function was called on sufficiently
large inputs, it could cause an application using fnmatch() to crash or,
possibly, execute arbitrary code with the privileges of the application.
(CVE-2011-1071)

It was found that the glibc addmntent() function, used by various mount
helper utilities, did not handle certain errors correctly when updating the
mtab (mounted file systems table) file. If such utilities had the setuid
bit set, a local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1089)

It was discovered that the locale command did not produce properly escaped
output as required by the POSIX specification. If an attacker were able to
set the locale environment variables in the environment of a script that
performed shell evaluation on the output of the locale command, and that
script were run with different privileges than the attacker's, it could
execute arbitrary code with the privileges of the script. (CVE-2011-1095)

An integer overflow flaw was found in the glibc fnmatch() function. If an
attacker supplied a long UTF-8 string to an application linked against
glibc, it could cause the application to crash. (CVE-2011-1659)

A denial of service flaw was found in the remote procedure call (RPC)
implementation in glibc. A remote attacker able to open a large number of
connections to an RPC service that is using the RPC implementation from
glibc, could use this flaw to make that service use an excessive amount of
CPU time. (CVE-2011-4609)

Red Hat would like to thank the Ubuntu Security Team for reporting
CVE-2010-0830, and Dan Rosenberg for reporting CVE-2011-1089. The Ubuntu
Security Team acknowledges Dan Rosenberg as the original reporter of
CVE-2010-0830.

This update also fixes the following bug:

* When using an nscd package that is a different version than the glibc
package, the nscd service could fail to start. This update makes the nscd
package require a specific glibc version to prevent this problem.
(BZ#657009)

Users should upgrade to these updated packages, which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120125"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120126" severity="medium">
    <xccdf:title>RHSA-2012:0126: glibc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the glibc library read timezone files. If a
carefully-crafted timezone file was loaded by an application linked against
glibc, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-5029)

A flaw was found in the way the ldd utility identified dynamically linked
libraries. If an attacker could trick a user into running ldd on a
malicious binary, it could result in arbitrary code execution with the
privileges of the user running ldd. (CVE-2009-5064)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the glibc library loaded ELF (Executable and Linking
Format) files. If a carefully-crafted ELF file was loaded by an
application linked against glibc, it could cause the application to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2010-0830)

It was found that the glibc addmntent() function, used by various mount
helper utilities, did not handle certain errors correctly when updating the
mtab (mounted file systems table) file. If such utilities had the setuid
bit set, a local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1089)

A denial of service flaw was found in the remote procedure call (RPC)
implementation in glibc. A remote attacker able to open a large number of
connections to an RPC service that is using the RPC implementation from
glibc, could use this flaw to make that service use an excessive amount of
CPU time. (CVE-2011-4609)

Red Hat would like to thank the Ubuntu Security Team for reporting
CVE-2010-0830, and Dan Rosenberg for reporting CVE-2011-1089. The Ubuntu
Security Team acknowledges Dan Rosenberg as the original reporter of
CVE-2010-0830.

Users should upgrade to these updated packages, which resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120127" severity="medium">
    <xccdf:title>RHSA-2012:0127: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2012-0075,
CVE-2012-0087, CVE-2012-0101, CVE-2012-0102, CVE-2012-0114, CVE-2012-0484,
CVE-2012-0490)

These updated packages upgrade MySQL to version 5.0.95. Refer to the MySQL
release notes for a full list of changes:

http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0490</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120127"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120128" severity="medium">
    <xccdf:title>RHSA-2012:0128: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

It was discovered that the fix for CVE-2011-3368 (released via
RHSA-2011:1391) did not completely address the problem. An attacker could
bypass the fix and make a reverse proxy connect to an arbitrary server not
directly accessible to the attacker by sending an HTTP version 0.9 request,
or by using a specially-crafted URI. (CVE-2011-3639, CVE-2011-4317)

The httpd server included the full HTTP header line in the default error
page generated when receiving an excessively long or malformed header.
Malicious JavaScript running in the server's domain context could use this
flaw to gain access to httpOnly cookies. (CVE-2012-0053)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way httpd performed substitutions in regular expressions. An
attacker able to set certain httpd settings, such as a user permitted to
override the httpd configuration for a specific directory using a
".htaccess" file, could use this flaw to crash the httpd child process or,
possibly, execute arbitrary code with the privileges of the "apache" user.
(CVE-2011-3607)

A flaw was found in the way httpd handled child process status information.
A malicious program running with httpd child process privileges (such as a
PHP or CGI script) could use this flaw to cause the parent httpd process to
crash during httpd service shutdown. (CVE-2012-0031)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3607</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3639</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4317</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0053</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120128"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120135" severity="high">
    <xccdf:title>RHSA-2012:0135: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

It was discovered that Java2D did not properly check graphics rendering
objects before passing them to the native renderer. Malicious input, or an
untrusted Java application or applet could use this flaw to crash the Java
Virtual Machine (JVM), or bypass Java sandbox restrictions. (CVE-2012-0497)

It was discovered that the exception thrown on deserialization failure did
not always contain a proper identification of the cause of the failure. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2012-0505)

The AtomicReferenceArray class implementation did not properly check if
the array was of the expected Object[] type. A malicious Java application
or applet could use this flaw to bypass Java sandbox restrictions.
(CVE-2011-3571)

It was discovered that the use of TimeZone.setDefault() was not restricted
by the SecurityManager, allowing an untrusted Java application or applet to
set a new default time zone, and hence bypass Java sandbox restrictions.
(CVE-2012-0503)

The HttpServer class did not limit the number of headers read from HTTP
requests. A remote attacker could use this flaw to make an application
using HttpServer use an excessive amount of CPU time via a
specially-crafted request. This update introduces a header count limit
controlled using the sun.net.httpserver.maxReqHeaders property. The default
value is 200. (CVE-2011-5035)

The Java Sound component did not properly check buffer boundaries.
Malicious input, or an untrusted Java application or applet could use this
flaw to cause the Java Virtual Machine (JVM) to crash or disclose a portion
of its memory. (CVE-2011-3563)

A flaw was found in the AWT KeyboardFocusManager that could allow an
untrusted Java application or applet to acquire keyboard focus and possibly
steal sensitive information. (CVE-2012-0502)

It was discovered that the CORBA (Common Object Request Broker
Architecture) implementation in Java did not properly protect repository
identifiers on certain CORBA objects. This could have been used to modify
immutable object data. (CVE-2012-0506)

An off-by-one flaw, causing a stack overflow, was found in the unpacker for
ZIP files. A specially-crafted ZIP archive could cause the Java Virtual
Machine (JVM) to crash when opened. (CVE-2012-0501)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.10.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5035</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0507</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120136" severity="high">
    <xccdf:title>RHSA-2012:0136: libvorbis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

A heap-based buffer overflow flaw was found in the way the libvorbis
library parsed Ogg Vorbis media files. If a specially-crafted Ogg Vorbis
media file was opened by an application using libvorbis, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2012-0444)

Users of libvorbis should upgrade to these updated packages, which contain
a backported patch to correct this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0444</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120136"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120137" severity="medium">
    <xccdf:title>RHSA-2012:0137: texlive security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>TeX Live is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (DVI) file as output. The texlive packages provide a number of
utilities, including dvips.

TeX Live embeds a copy of t1lib. The t1lib library allows you to rasterize
bitmaps from PostScript Type 1 fonts. The following issues affect t1lib
code:

Two heap-based buffer overflow flaws were found in the way t1lib processed
Adobe Font Metrics (AFM) files. If a specially-crafted font file was opened
by a TeX Live utility, it could cause the utility to crash or, potentially,
execute arbitrary code with the privileges of the user running the utility.
(CVE-2010-2642, CVE-2011-0433)

An invalid pointer dereference flaw was found in t1lib. A specially-crafted
font file could, when opened, cause a TeX Live utility to crash or,
potentially, execute arbitrary code with the privileges of the user running
the utility. (CVE-2011-0764)

A use-after-free flaw was found in t1lib. A specially-crafted font file
could, when opened, cause a TeX Live utility to crash or, potentially,
execute arbitrary code with the privileges of the user running the utility.
(CVE-2011-1553)

An off-by-one flaw was found in t1lib. A specially-crafted font file could,
when opened, cause a TeX Live utility to crash or, potentially, execute
arbitrary code with the privileges of the user running the utility.
(CVE-2011-1554)

An out-of-bounds memory read flaw was found in t1lib. A specially-crafted
font file could, when opened, cause a TeX Live utility to crash.
(CVE-2011-1552)

Red Hat would like to thank the Evince development team for reporting
CVE-2010-2642. Upstream acknowledges Jon Larimer of IBM X-Force as the
original reporter of CVE-2010-2642.

All users of texlive are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1554</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120137"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120140" severity="high">
    <xccdf:title>RHSA-2012:0140: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A heap-based buffer overflow flaw was found in the way Thunderbird handled
PNG (Portable Network Graphics) images. An HTML mail message or remote
content containing a specially-crafted PNG image could cause Thunderbird to
crash or, possibly, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2011-3026)

All Thunderbird users should upgrade to this updated package, which
corrects this issue. After installing the update, Thunderbird must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3026</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120141" severity="high">
    <xccdf:title>RHSA-2012:0141: seamonkey security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SeaMonkey is an open source web browser, e-mail and newsgroup client, IRC
chat client, and HTML editor.

A heap-based buffer overflow flaw was found in the way SeaMonkey handled
PNG (Portable Network Graphics) images. A web page containing a malicious
PNG image could cause SeaMonkey to crash or, possibly, execute arbitrary
code with the privileges of the user running SeaMonkey. (CVE-2011-3026)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3026</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120141"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120142" severity="high">
    <xccdf:title>RHSA-2012:0142: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

A heap-based buffer overflow flaw was found in the way Firefox handled
PNG (Portable Network Graphics) images. A web page containing a malicious
PNG image could cause Firefox to crash or, possibly, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2011-3026)

All Firefox users should upgrade to this updated package, which corrects
this issue. After installing the update, Firefox must be restarted for the
changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3026</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120142"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120143" severity="high">
    <xccdf:title>RHSA-2012:0143: xulrunner security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>XULRunner provides the XUL Runtime environment for applications using the
Gecko layout engine.

A heap-based buffer overflow flaw was found in the way XULRunner handled
PNG (Portable Network Graphics) images. A web page containing a malicious
PNG image could cause an application linked against XULRunner (such as
Firefox) to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-3026)

All XULRunner users should upgrade to these updated packages, which correct
this issue. After installing the update, applications using XULRunner must
be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3026</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120143"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120149" severity="medium">
    <xccdf:title>RHSA-2012:0149: kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

It was found that the kvm_vm_ioctl_assign_device() function in the KVM
subsystem of a Linux kernel did not check if the user requesting device
assignment was privileged or not. A member of the kvm group on the host
could assign unused PCI devices, or even devices that were in use and
whose resources were not properly claimed by the respective drivers, which
could result in the host crashing. (CVE-2011-4347)

Red Hat would like to thank Sasha Levin for reporting this issue.

These updated kvm packages include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 5.8 Technical Notes, linked to in the
References, for information on the most significant of these changes.

All KVM users should upgrade to these updated packages, which contain
backported patches to correct these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0149</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4347</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120149"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120150" severity="medium">
    <xccdf:title>RHSA-2012:0150: Red Hat Enterprise Linux 5.8 kernel update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the way the Linux kernel's Event Poll (epoll)
subsystem handled large, nested epoll structures. A local, unprivileged
user could use this flaw to cause a denial of service. (CVE-2011-1083,
Moderate)

Red Hat would like to thank Nelson Elhage for reporting this issue.

These updated kernel packages include a number of bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 5.8 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which correct these issues and add these enhancements. The system
must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1083</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120150"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120151" severity="medium">
    <xccdf:title>RHSA-2012:0151: conga security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The conga packages provide a web-based administration tool for remote
cluster and storage management.

Multiple cross-site scripting (XSS) flaws were found in luci, the conga
web-based administration application. If a remote attacker could trick a
user, who was logged into the luci interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's luci session. (CVE-2010-1104, CVE-2011-1948)

These updated conga packages include several bug fixes and an enhancement.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 5.8 Technical Notes, linked to
in the References, for information on the most significant of these
changes.

Users of conga are advised to upgrade to these updated packages, which
correct these issues and add this enhancement. After installing the updated
packages, luci must be restarted ("service luci restart") for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1104</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1948</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120151"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120152" severity="medium">
    <xccdf:title>RHSA-2012:0152: kexec-tools security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kexec-tools package contains the /sbin/kexec binary and utilities that 
together form the user-space component of the kernel's kexec feature. The 
/sbin/kexec binary facilitates a new kernel to boot using the kernel's 
kexec feature either on a normal or a panic reboot. The kexec fastboot 
mechanism allows booting a Linux kernel from the context of an already 
running kernel.

Kdump used the SSH (Secure Shell) "StrictHostKeyChecking=no" option when
dumping to SSH targets, causing the target kdump server's SSH host key not
to be checked. This could make it easier for a man-in-the-middle attacker
on the local network to impersonate the kdump SSH target server and
possibly gain access to sensitive information in the vmcore dumps.
(CVE-2011-3588)

The mkdumprd utility created initrd files with world-readable permissions.
A local user could possibly use this flaw to gain access to sensitive 
information, such as the private SSH key used to authenticate to a remote 
server when kdump was configured to dump to an SSH target. (CVE-2011-3589)

The mkdumprd utility included unneeded sensitive files (such as all files 
from the "/root/.ssh/" directory and the host's private SSH keys) in the 
resulting initrd. This could lead to an information leak when initrd 
files were previously created with world-readable permissions. Note: With 
this update, only the SSH client configuration, known hosts files, and the 
SSH key configured via the newly introduced sshkey option in 
"/etc/kdump.conf" are included in the initrd. The default is the key 
generated when running the "service kdump propagate" command, 
"/root/.ssh/kdump_id_rsa". (CVE-2011-3590)

Red Hat would like to thank Kevan Carstensen for reporting these issues.

This updated kexec-tools package also includes numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 5.8 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All users of kexec-tools are advised to upgrade to this updated package, 
which resolves these security issues, fixes these bugs and adds these 
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3588</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3589</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3590</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120152"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120153" severity="low">
    <xccdf:title>RHSA-2012:0153: sos security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Sos is a set of tools that gather information about system hardware and
configuration.

The sosreport utility incorrectly included Certificate-based Red Hat
Network private entitlement keys in the resulting archive of debugging
information. An attacker able to access the archive could use the keys to
access Red Hat Network content available to the host. This issue did not
affect users of Red Hat Network Classic. (CVE-2011-4083)

This updated sos package also includes numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 5.8 Technical Notes, linked
to in the References, for information on the most significant of these
changes.

All sos users are advised to upgrade to this updated package, which
resolves these issues and adds these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4083</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120153"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120301" severity="low">
    <xccdf:title>RHSA-2012:0301: ImageMagick security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

It was found that ImageMagick utilities tried to load ImageMagick
configuration files from the current working directory. If a user ran an
ImageMagick utility in an attacker-controlled directory containing a
specially-crafted ImageMagick configuration file, it could cause the
utility to execute arbitrary code. (CVE-2010-4167)

This update also fixes the following bugs:

* Previously, the "identify -verbose" command failed with an assertion if
there was no image information available. An upstream patch has been
applied, so that GetImageOption() is now called correctly. Now, the
"identify -verbose" command works correctly even if no image information is
available. (BZ#502626)

* Previously, an incorrect use of the semaphore data type led to a
deadlock. As a consequence, the ImageMagick utility could become
unresponsive when converting JPEG files to PDF (Portable Document Format)
files. A patch has been applied to address the deadlock issue, and JPEG
files can now be properly converted to PDF files. (BZ#530592)

* Previously, running the "convert" command with the "-color" option failed
with a memory allocation error. The source code has been modified to fix
problems with memory allocation. Now, using the "convert" command with the
"-color" option works correctly. (BZ#616538)

* Previously, ImageMagick could become unresponsive when using the
"display" command on damaged GIF files. The source code has been revised to
prevent the issue. ImageMagick now produces an error message in the
described scenario. A file selector is now opened so the user can choose
another image to display. (BZ#693989)

* Prior to this update, the "convert" command did not handle rotated PDF
files correctly. As a consequence, the output was rendered as a portrait
with the content being cropped. With this update, the PDF render geometry
is modified, and the output produced by the "convert" command is properly
rendered as a landscape. (BZ#694922)

All users of ImageMagick are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of ImageMagick must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4167</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120301"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120302" severity="low">
    <xccdf:title>RHSA-2012:0302: cups security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for Linux, UNIX, and similar operating systems.

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)
decompression algorithm implementation used by the CUPS GIF image format
reader. An attacker could create a malicious GIF image file that, when
printed, could possibly cause CUPS to crash or, potentially, execute
arbitrary code with the privileges of the "lp" user. (CVE-2011-2896)

This update also fixes the following bugs:

* Prior to this update, the "Show Completed Jobs," "Show All Jobs," and
"Show Active Jobs" buttons returned results globally across all printers
and not the results for the specified printer. With this update, jobs from
only the selected printer are shown. (BZ#625900)

* Prior to this update, the code of the serial backend contained a wrong
condition. As a consequence, print jobs on the raw print queue could not be
canceled. This update modifies the condition in the serial backend code.
Now, the user can cancel these print jobs. (BZ#625955)

* Prior to this update, the textonly filter did not work if used as a pipe,
for example when the command line did not specify the filename and the
number of copies was always 1. This update modifies the condition in the
textonly filter. Now, the data are sent to the printer regardless of the
number of copies specified. (BZ#660518)

* Prior to this update, the file descriptor count increased until it ran
out of resources when the cups daemon was running with enabled
Security-Enhanced Linux (SELinux) features. With this update, all resources
are allocated only once. (BZ#668009)

* Prior to this update, CUPS incorrectly handled the en_US.ASCII value for
the LANG environment variable. As a consequence, the lpadmin, lpstat, and
lpinfo binaries failed to write to standard output if using LANG with the
value. This update fixes the handling of the en_US.ASCII value and the
binaries now write to standard output properly. (BZ#759081)

All users of cups are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2896</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120302"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120303" severity="low">
    <xccdf:title>RHSA-2012:0303: xorg-x11-server security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way the X.Org server handled lock files. A local
user with access to the system console could use this flaw to determine the
existence of a file in a directory not accessible to the user, via a
symbolic link attack. (CVE-2011-4028)

Red Hat would like to thank the researcher with the nickname vladz for
reporting this issue.

This update also fixes the following bugs:

* In rare cases, if the front and back buffer of the miDbePositionWindow()
function were not both allocated in video memory, or were both allocated in
system memory, the X Window System sometimes terminated unexpectedly. A
patch has been provided to address this issue and X no longer crashes in
the described scenario. (BZ#596899)

* Previously, when the miSetShape() function called the miRegionDestroy()
function with a NULL region, X terminated unexpectedly if the backing store
was enabled. Now, X no longer crashes in the described scenario.
(BZ#676270)

* On certain workstations running in 32-bit mode, the X11 mouse cursor
occasionally became stuck near the left edge of the X11 screen. A patch has
been provided to address this issue and the mouse cursor no longer becomes
stuck in the described scenario. (BZ#529717)

* On certain workstations with a dual-head graphics adapter using the r500
driver in Zaphod mode, the mouse pointer was confined to one monitor screen
and could not move to the other screen. A patch has been provided to
address this issue and the mouse cursor works properly across both screens.
(BZ#559964)

* Due to a double free operation, Xvfb (X virtual framebuffer) terminated
unexpectedly with a segmentation fault randomly when the last client
disconnected, that is when the server reset. This bug has been fixed in the
miDCCloseScreen() function and Xvfb no longer crashes. (BZ#674741)

* Starting the Xephyr server on an AMD64 or Intel 64 architecture with an
integrated graphics adapter caused the server to terminate unexpectedly.
This bug has been fixed in the code and Xephyr no longer crashes in the
described scenario. (BZ#454409)

* Previously, when a client made a request bigger than 1/4th of the limit
advertised in the BigRequestsEnable reply, the X server closed the
connection unexpectedly. With this update, the maxBigRequestSize variable
has been added to the code to check the size of client requests, thus
fixing this bug. (BZ#555000)

* When an X client running on a big-endian system called the
XineramaQueryScreens() function, the X server terminated unexpectedly. This
bug has been fixed in the xf86Xinerama module and the X server no longer
crashes in the described scenario. (BZ#588346)

* When installing Red Hat Enterprise Linux 5 on an IBM eServer System p
blade server, the installer did not set the correct mode on the built-in
KVM (Keyboard-Video-Mouse). Consequently, the graphical installer took a
very long time to appear and then was displayed incorrectly. A patch has
been provided to address this issue and the graphical installer now works
as expected in the described scenario. Note that this fix requires the
Red Hat Enterprise Linux 5.8 kernel update. (BZ#740497)

* Lines longer than 46,340 pixels can be drawn with one of the coordinates
being negative. However, for dashed lines, the miPolyBuildPoly() function
overflowed the "int" type when setting up edges for a section of a dashed
line. Consequently, dashed segments were not drawn at all. An upstream
patch has been applied to address this issue and dashed lines are now drawn
correctly. (BZ#649810)

All users of xorg-x11-server are advised to upgrade to these updated
packages, which correct these issues. All running X.Org server instances
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0303</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4028</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120303"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120304" severity="low">
    <xccdf:title>RHSA-2012:0304: vixie-cron security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times. The
vixie-cron package adds improved security and more powerful configuration
options to the standard version of cron.

A race condition was found in the way the crontab program performed file
time stamp updates on a temporary file created when editing a user crontab
file. A local attacker could use this flaw to change the modification time
of arbitrary system files via a symbolic link attack. (CVE-2010-0424)

Red Hat would like to thank Dan Rosenberg for reporting this issue.

This update also fixes the following bugs:

* Cron jobs of users with home directories mounted on a Lightweight
Directory Access Protocol (LDAP) server or Network File System (NFS) were
often refused because jobs were marked as orphaned (typically due to a
temporary NSS lookup failure, when NIS and LDAP servers were unreachable).
With this update, a database of orphans is created, and cron jobs are
performed as expected. (BZ#455664)

* Previously, cron did not log any errors if a cron job file located in the
/etc/cron.d/ directory contained invalid entries. An upstream patch has
been applied to address this problem and invalid entries in the cron job
files now produce warning messages. (BZ#460070)

* Previously, the "@reboot" crontab macro incorrectly ran jobs when the
crond daemon was restarted. If the user used the macro on multiple
machines, all entries with the "@reboot" option were executed every time
the crond daemon was restarted. With this update, jobs are executed only
when the machine is rebooted. (BZ#476972)

* The crontab utility is now compiled as a position-independent executable
(PIE), which enhances the security of the system. (BZ#480930)

* When the parent crond daemon was stopped, but a child crond daemon was
running (executing a program), the "service crond status" command
incorrectly reported that crond was running. The source code has been
modified, and the "service crond status" command now correctly reports that
crond is stopped. (BZ#529632)

* According to the pam(8) manual page, the cron daemon, crond, supports
access control with PAM (Pluggable Authentication Module). However, the PAM
configuration file for crond did not export environment variables correctly
and, consequently, setting PAM variables via cron did not work. This update
includes a corrected /etc/pam.d/crond file that exports environment
variables correctly. Setting pam variables via cron now works as documented
in the pam(8) manual page. (BZ#541189)

* Previously, the mcstransd daemon modified labels for the crond daemon.
When the crond daemon attempted to use the modified label and mcstransd was
not running, crond used an incorrect label. Consequently, Security-Enhanced
Linux (SELinux) denials filled up the cron log, no jobs were executed, and
crond had to be restarted. With this update, both mcstransd and crond use
raw SELinux labels, which prevents the problem. (BZ#625016)

* Previously, the crontab(1) and cron(8) manual pages contained multiple
typographical errors. This update fixes those errors. (BZ#699620,
BZ#699621)

In addition, this update adds the following enhancement:

* Previously, the crontab utility did not use the Pluggable Authentication
Module (PAM) for verification of users. As a consequence, a user could
access crontab even if access had been restricted (usually by being denied
in the access.conf file). With this update, crontab returns an error
message that the user is not allowed to access crontab because of PAM
configuration. (BZ#249512)

All vixie-cron users should upgrade to this updated package, which resolves
these issues and adds this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0424</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120304"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120305" severity="low">
    <xccdf:title>RHSA-2012:0305: boost security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The boost packages provide free, peer-reviewed, portable C++ source
libraries with emphasis on libraries which work well with the C++ Standard
Library.

Invalid pointer dereference flaws were found in the way the Boost regular
expression library processed certain, invalid expressions. An attacker able
to make an application using the Boost library process a specially-crafted
regular expression could cause that application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2008-0171)

NULL pointer dereference flaws were found in the way the Boost regular
expression library processed certain, invalid expressions. An attacker able
to make an application using the Boost library process a specially-crafted
regular expression could cause that application to crash. (CVE-2008-0172)

Red Hat would like to thank Will Drewry for reporting these issues.

This update also fixes the following bugs:

* Prior to this update, the construction of a regular expression object
could fail when several regular expression objects were created
simultaneously, such as in a multi-threaded program. With this update, the
object variables have been moved from the shared memory to the stack. Now,
the constructing function is thread safe. (BZ#472384)

* Prior to this update, header files in several Boost libraries contained
preprocessor directives that the GNU Compiler Collection (GCC) 4.4 could
not handle. This update instead uses equivalent constructs that are
standard C. (BZ#567722)

All users of boost are advised to upgrade to these updated packages, which
fix these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0172</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120305"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120306" severity="low">
    <xccdf:title>RHSA-2012:0306: krb5 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

It was found that ftpd, a Kerberos-aware FTP server, did not properly drop
privileges. On Red Hat Enterprise Linux 5, the ftpd daemon did not check
for the potential failure of the effective group ID change system call. If
the group ID change failed, a remote FTP user could use this flaw to gain
unauthorized read or write access to files that are owned by the root
group. (CVE-2011-1526)

Red Hat would like to thank the MIT Kerberos project for reporting this
issue. Upstream acknowledges Tim Zingelman as the original reporter.

This update also fixes the following bugs:

* Due to a mistake in the Kerberos libraries, a client could fail to
contact a Key Distribution Center (KDC) or terminate unexpectedly if the
client had already more than 1024 file descriptors in use. This update
backports modifications to the Kerberos libraries and the libraries use
the poll() function instead of the select() function, as poll() does not
have this limitation. (BZ#701444)

* The KDC failed to release memory when processing a TGS (ticket-granting
server) request from a client if the client request included an
authenticator with a subkey. As a result, the KDC consumed an excessive
amount of memory. With this update, the code releasing the memory has been
added and the problem no longer occurs. (BZ#708516)

* Under certain circumstances, if services requiring Kerberos
authentication sent two authentication requests to the authenticating
server, the second authentication request was flagged as a replay attack.
As a result, the second authentication attempt was denied. This update
applies an upstream patch that fixes this bug. (BZ#713500)

* Previously, if Kerberos credentials had expired, the klist command could
terminate unexpectedly with a segmentation fault when invoked with the -s
option. This happened when klist encountered and failed to process an entry
with no realm name while scanning the credential cache. With this update,
the underlying code has been modified and the command handles such entries
correctly. (BZ#729067)

* Due to a regression, multi-line FTP macros terminated prematurely with a
segmentation fault. This occurred because the previously-added patch failed
to properly support multi-line macros. This update restores the support for
multi-line macros and the problem no longer occurs. (BZ#735363, BZ#736132)

All users of krb5 are advised to upgrade to these updated packages, which
resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1526</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120306"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120307" severity="low">
    <xccdf:title>RHSA-2012:0307: util-linux security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. Among others,
util-linux contains the fdisk configuration tool and the login program.

Multiple flaws were found in the way the mount and umount commands
performed mtab (mounted file systems table) file updates. A local,
unprivileged user allowed to mount or unmount file systems could use these
flaws to corrupt the mtab file and create a stale lock file, preventing
other users from mounting and unmounting file systems. (CVE-2011-1675,
CVE-2011-1677)

This update also fixes the following bugs:

* When the user logged into a telnet server, the login utility did not
update the utmp database properly if the utility was executed from the
telnetd daemon. This was due to telnetd not creating an appropriate entry
in a utmp file before executing login. With this update, correct entries
are created and the database is updated properly. (BZ#646300)

* Various options were not described on the blockdev(8) manual page. With
this update, the blockdev(8) manual page includes all the relevant options.
(BZ#650937)

* Prior to this update, the build process of the util-linux package failed
in the po directory with the following error message: "@MKINSTALLDIRS@:
No such file or directory". An upstream patch has been applied to address
this issue, and the util-linux package now builds successfully. (BZ#677452)

* Previously, the ipcs(1) and ipcrm(1) manual pages mentioned an invalid
option, "-b". With this update, only valid options are listed on those
manual pages. (BZ#678407)

* Previously, the mount(8) manual page contained incomplete information
about the ext4 and XFS file systems. With this update, the mount(8) manual
page contains the missing information. (BZ#699639)

In addition, this update adds the following enhancements:

* Previously, if DOS mode was enabled on a device, the fdisk utility could
report error messages similar to the following:

Partition 1 has different physical/logical beginnings (non-Linux?):
phys=(0, 1, 1) logical=(0, 2, 7)

This update enables users to switch off DOS compatible mode (by specifying
the "-c" option), and such error messages are no longer displayed.
(BZ#678430)

* This update adds the "fsfreeze" command which halts access to a file
system on a disk. (BZ#726572)

All users of util-linux are advised to upgrade to this updated package,
which contains backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1677</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120308" severity="low">
    <xccdf:title>RHSA-2012:0308: busybox security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>BusyBox provides a single binary that includes versions of a large number
of system commands, including a shell. This can be very useful for
recovering from certain types of system failures, particularly those
involving broken shared libraries.

A buffer underflow flaw was found in the way the uncompress utility of
BusyBox expanded certain archive files compressed using Lempel-Ziv
compression. If a user were tricked into expanding a specially-crafted
archive file with uncompress, it could cause BusyBox to crash or,
potentially, execute arbitrary code with the privileges of the user running
BusyBox. (CVE-2006-1168)

The BusyBox DHCP client, udhcpc, did not sufficiently sanitize certain
options provided in DHCP server replies, such as the client hostname. A
malicious DHCP server could send such an option with a specially-crafted
value to a DHCP client. If this option's value was saved on the client
system, and then later insecurely evaluated by a process that assumes the
option is trusted, it could lead to arbitrary code execution with the
privileges of that process. Note: udhcpc is not used on Red Hat Enterprise
Linux by default, and no DHCP client script is provided with the busybox
packages. (CVE-2011-2716)

This update also fixes the following bugs:

* Prior to this update, the cp command wrongly returned the exit code 0 to
indicate success if a device ran out of space while attempting to copy
files of more than 4 gigabytes. This update modifies BusyBox, so that in
such situations, the exit code 1 is returned. Now, the cp command shows
correctly whether a process failed. (BZ#689659)

* Prior to this update, the findfs command failed to check all existing
block devices on a system with thousands of block device nodes in "/dev/".
This update modifies BusyBox so that findfs checks all block devices even
in this case. (BZ#756723)

All users of busybox are advised to upgrade to these updated packages,
which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0308</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2716</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120308"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120309" severity="low">
    <xccdf:title>RHSA-2012:0309: sudo security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the sudo password checking logic. In configurations
where the sudoers settings allowed a user to run a command using sudo
with only the group ID changed, sudo failed to prompt for the user's
password before running the specified command with the elevated group
privileges. (CVE-2011-0010)

In addition, this update fixes the following bugs:

* A NULL pointer dereference bug caused the sudo utility to terminate
unexpectedly with a segmentation fault. This happened if the utility was
run with the -g option and configured not to demand the password from the
user who ran the sudo utility. With this update, the code has been modified
and the problem no longer occurs. (BZ#673072)

* The sudo utility failed to load sudoers from an LDAP (Lightweight
Directory Access Protocol) server after the sudo tool was upgraded. This
happened because the upgraded nsswitch.conf file did not contain the
instruction to search for sudoers on the LDAP server. This update adds the
lost instruction to /etc/nsswitch.conf and the system searches for sources
of sudoers on the local file system and then on LDAP, if applicable.
(BZ#617061)

* The sudo tool interpreted a Runas alias specifying a group incorrectly as
a user alias and the alias seemed to be ignored. With this update, the code
for interpreting such aliases has been modified and the Runas group aliases
are honored as expected. (BZ#627543)

* Prior to this update, sudo did not parse comment characters (#) in the
ldap.conf file correctly and could fail to work. With this update, parsing
of the LDAP configuration file has been modified and the comment characters
are parsed correctly. (BZ#750318)

* The sudo utility formats its output to fit the width of the terminal
window. However, this behavior is undesirable if the output is redirected
through a pipeline. With this update, the output formatting is not applied
in the scenario described. (BZ#697111)

* Previously, the sudo utility performed Security-Enhanced Linux (SELinux)
related initialization after switching to an unprivileged user. This
prevented the correct setup of the SELinux environment before executing the
specified command and could potentially cause an access denial. The bug has
been fixed by backporting the SELinux related code and the execution model
from a newer version of sudo. (BZ#477185)

* On execv(3) function failure, the sudo tool executed an auditing call
before reporting the failure. The call reset the error state and,
consequently, the tool incorrectly reported that the command succeeded.
With this update, the code has been modified and the problem no longer
occurs. (BZ#673157)

All users of sudo are advised to upgrade to this updated package, which
resolves these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0010</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120309"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120310" severity="low">
    <xccdf:title>RHSA-2012:0310: nfs-utils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nfs-utils package provides a daemon for the kernel Network File System
(NFS) server, and related tools such as the mount.nfs, umount.nfs, and
showmount programs.

It was found that the mount.nfs tool did not handle certain errors
correctly when updating the mtab (mounted file systems table) file. A
local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1749)

This update also fixes the following bugs:

* The nfs service failed to start if the NFSv1, NFSv2, and NFSv4 support
was disabled (the MOUNTD_NFS_V1="no", MOUNTD_NFS_V2="no" MOUNTD_NFS_V3="no"
lines in /etc/sysconfig/nfs were uncommented) because the mountd daemon
failed to handle the settings correctly. With this update, the underlying
code has been modified and the nfs service starts successfully in the
described scenario. (BZ#529588)

* When a user's Kerberos ticket expired, the "sh rpc.gssd" messages flooded
the /var/log/messages file. With this update, the excessive logging has
been suppressed. (BZ#593097)

* The crash simulation (SM_SIMU_CRASH) of the rpc.statd service had a
vulnerability that could be detected by ISS (Internet Security Scanner). As
a result, the rpc.statd service terminated unexpectedly with the following
error after an ISS scan:

  rpc.statd[xxxx]: recv_rply: can't decode RPC message!
  rpc.statd[xxxx]: *** SIMULATING CRASH! ***
  rpc.statd[xxxx]: unable to register (statd, 1, udp).

However, the rpc.statd service ignored SM_SIMU_CRASH. This update removes
the simulation crash support from the service and the problem no longer
occurs. (BZ#600497)

* The nfs-utils init scripts returned incorrect status codes in the
following cases: if the rpcgssd and rpcsvcgssd daemon were not configured,
were provided an unknown argument, their function call failed, if a program
was no longer running and a /var/lock/subsys/$SERVICE file existed, if
starting a service under an unprivileged user, if a program was no longer
running and its pid file still existed in the /var/run/ directory. With
this update, the correct codes are returned in these scenarios. (BZ#710020)

* The "nfsstat -m" command did not display NFSv4 mounts. With this update,
the underlying code has been modified and the command returns the list of
all mounts, including any NFSv4 mounts, as expected. (BZ#712438)

* Previously, the nfs manual pages described the fsc mount option; however,
this option is not supported. This update removes the option description
from the manual pages. (BZ#715523)

* The nfs-utils preinstall scriptlet failed to change the default group ID
for the nfsnobody user to 65534. This update modifies the preinstall
scriptlet and the default group ID is changed to 65534 after nfs-utils
upgrade as expected. (BZ#729603)

* The mount.nfs command with the "-o retry" option did not try to mount for
the time specified in the "retry=X" configuration option. This occurred due
to incorrect error handling by the command. With this update, the
underlying code has been fixed and the "-o retry" option works as expected.
(BZ#736677)

In addition, this update adds the following enhancement:

* The noresvport option, which allows NFS clients to use insecure ports
(ports above 1023), has been added to the NFS server configuration options.
(BZ#513094)

All nfs-utils users are advised to upgrade to this updated package, which
resolves these issues and adds this enhancement. After installing this
update, the nfs service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1749</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120310"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120311" severity="low">
    <xccdf:title>RHSA-2012:0311: ibutils security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ibutils packages provide InfiniBand network and path diagnostics.

It was found that the ibmssh executable had an insecure relative RPATH
(runtime library search path) set in the ELF (Executable and Linking
Format) header. A local user able to convince another user to run ibmssh in
an attacker-controlled directory could run arbitrary code with the
privileges of the victim. (CVE-2008-3277)

This update also fixes the following bug:

* Under certain circumstances, the "ibdiagnet -r" command could suffer from
memory corruption and terminate with a "double free or corruption" message
and a backtrace. With this update, the correct memory management function
is used to prevent the corruption. (BZ#711779)

All users of ibutils are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0311</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-3277</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120311"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120312" severity="low">
    <xccdf:title>RHSA-2012:0312: initscripts security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The initscripts package contains system scripts to boot your system, change
runlevels, activate and deactivate most network interfaces, and shut the
system down cleanly.

With the default IPsec (Internet Protocol Security) ifup script
configuration, the racoon IKE key management daemon used aggressive IKE
mode instead of main IKE mode. This resulted in the preshared key (PSK)
hash being sent unencrypted, which could make it easier for an attacker
able to sniff network traffic to obtain the plain text PSK from a
transmitted hash. (CVE-2008-1198)

Red Hat would like to thank Aleksander Adamowski for reporting this issue.

This update also fixes the following bugs:

* Prior to this update, the DHCPv6 client was not terminated when the
network service was stopped. This update modifies the source so that the
client is now terminated when stopping the network service. (BZ#568896)

* Prior to this update, on some systems the rm command failed and reported
the error message "rm: cannot remove directory `/var/run/dovecot/login/':
Is a directory" during system boot. This update modifies the source so that
this error message no longer appears. (BZ#679998)

* Prior to this update, the netconsole script could not discover and
resolve the MAC address of the router specified in the
/etc/sysconfig/netconsole file. This update modifies the netconsole script
so that the script no longer fails when the arping tool returns the MAC
address of the router more than once. (BZ#744734)

* Prior to this update, the arp_ip_target was, due to a logic error, not
correctly removed via sysfs. As a consequence, the error "ifdown-eth: line
64: echo: write error: Invalid argument" was reported when attempting to
shut down a bonding device. This update modifies the script so that the
error no longer appears and arp_ip_target is now correctly removed.
(BZ#745681)

All users of initscripts are advised to upgrade to this updated package,
which fixes these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-1198</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120312"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120313" severity="low">
    <xccdf:title>RHSA-2012:0313: samba security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

The default Samba server configuration enabled both the "wide links" and
"unix extensions" options, allowing Samba clients with write access to a
share to create symbolic links that point to any location on the file
system. Clients connecting with CIFS UNIX extensions disabled could have
such links resolved on the server, allowing them to access and possibly
overwrite files outside of the share. With this update, "wide links" is
set to "no" by default. In addition, the update ensures "wide links" is
disabled for shares that have "unix extensions" enabled. (CVE-2010-0926)

Warning: This update may cause files and directories that are only linked
to Samba shares using symbolic links to become inaccessible to Samba
clients. In deployments where support for CIFS UNIX extensions is not
needed (such as when files are exported to Microsoft Windows clients),
administrators may prefer to set the "unix extensions" option to "no" to
allow the use of symbolic links to access files out of the shared
directories. All existing symbolic links in a share should be reviewed
before re-enabling "wide links".

These updated samba packages also fix the following bug:

* The smbclient tool sometimes failed to return the proper exit status
code. Consequently, using smbclient in a script caused some scripts to
fail. With this update, an upstream patch has been applied and smbclient
now returns the correct exit status. (BZ#768908)

In addition, these updated samba packages provide the following
enhancement:

* With this update, support for Windows Server 2008 R2 domains has been
added. (BZ#736124)

Users are advised to upgrade to these updated samba packages, which correct
these issues and add this enhancement. After installing this update, the
smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-0926</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120313"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120317" severity="high">
    <xccdf:title>RHSA-2012:0317: libpng security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap-based buffer overflow flaw was found in libpng. An attacker could
create a specially-crafted PNG image that, when opened, could cause an
application using libpng to crash or, possibly, execute arbitrary code with
the privileges of the user running the application. (CVE-2011-3026)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain a backported patch to correct this issue. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0317</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3026</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120317"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120321" severity="medium">
    <xccdf:title>RHSA-2012:0321: cvs security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Concurrent Version System (CVS) is a version control system that can record
the history of your files.

A heap-based buffer overflow flaw was found in the way the CVS client
handled responses from HTTP proxies. A malicious HTTP proxy could use this
flaw to cause the CVS client to crash or, possibly, execute arbitrary code
with the privileges of the user running the CVS client. (CVE-2012-0804)

All users of cvs are advised to upgrade to these updated packages, which
contain a patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0804</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120321"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120322" severity="high">
    <xccdf:title>RHSA-2012:0322: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

It was discovered that Java2D did not properly check graphics rendering
objects before passing them to the native renderer. Malicious input, or an
untrusted Java application or applet could use this flaw to crash the Java
Virtual Machine (JVM), or bypass Java sandbox restrictions. (CVE-2012-0497)

It was discovered that the exception thrown on deserialization failure did
not always contain a proper identification of the cause of the failure. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2012-0505)

The AtomicReferenceArray class implementation did not properly check if
the array was of the expected Object[] type. A malicious Java application
or applet could use this flaw to bypass Java sandbox restrictions.
(CVE-2011-3571)

It was discovered that the use of TimeZone.setDefault() was not restricted
by the SecurityManager, allowing an untrusted Java application or applet to
set a new default time zone, and hence bypass Java sandbox restrictions.
(CVE-2012-0503)

The HttpServer class did not limit the number of headers read from HTTP
requests. A remote attacker could use this flaw to make an application
using HttpServer use an excessive amount of CPU time via a
specially-crafted request. This update introduces a header count limit
controlled using the sun.net.httpserver.maxReqHeaders property. The default
value is 200. (CVE-2011-5035)

The Java Sound component did not properly check buffer boundaries.
Malicious input, or an untrusted Java application or applet could use this
flaw to cause the Java Virtual Machine (JVM) to crash or disclose a portion
of its memory. (CVE-2011-3563)

A flaw was found in the AWT KeyboardFocusManager that could allow an
untrusted Java application or applet to acquire keyboard focus and possibly
steal sensitive information. (CVE-2012-0502)

It was discovered that the CORBA (Common Object Request Broker
Architecture) implementation in Java did not properly protect repository
identifiers on certain CORBA objects. This could have been used to modify
immutable object data. (CVE-2012-0506)

An off-by-one flaw, causing a stack overflow, was found in the unpacker for
ZIP files. A specially-crafted ZIP archive could cause the Java Virtual
Machine (JVM) to crash when opened. (CVE-2012-0501)

This erratum also upgrades the OpenJDK package to IcedTea6 1.10.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5035</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0507</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120322"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120323" severity="medium">
    <xccdf:title>RHSA-2012:0323: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

It was discovered that the fix for CVE-2011-3368 (released via
RHSA-2011:1392) did not completely address the problem. An attacker could
bypass the fix and make a reverse proxy connect to an arbitrary server not
directly accessible to the attacker by sending an HTTP version 0.9 request.
(CVE-2011-3639)

The httpd server included the full HTTP header line in the default error
page generated when receiving an excessively long or malformed header.
Malicious JavaScript running in the server's domain context could use this
flaw to gain access to httpOnly cookies. (CVE-2012-0053)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way httpd performed substitutions in regular expressions. An
attacker able to set certain httpd settings, such as a user permitted to
override the httpd configuration for a specific directory using a
".htaccess" file, could use this flaw to crash the httpd child process or,
possibly, execute arbitrary code with the privileges of the "apache" user.
(CVE-2011-3607)

A flaw was found in the way httpd handled child process status information.
A malicious program running with httpd child process privileges (such as a
PHP or CGI script) could use this flaw to cause the parent httpd process to
crash during httpd service shutdown. (CVE-2012-0031)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3607</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3639</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0053</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120324" severity="medium">
    <xccdf:title>RHSA-2012:0324: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

It was found that the hashing routine used by libxml2 arrays was
susceptible to predictable hash collisions. Sending a specially-crafted
message to an XML service could result in longer processing time, which
could lead to a denial of service. To mitigate this issue, randomization
has been added to the hashing function to reduce the chance of an attacker
successfully causing intentional collisions. (CVE-2012-0841)

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120324"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120332" severity="high">
    <xccdf:title>RHSA-2012:0332: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is a suite of programs used by machines to share files, printers, and
other information.

An input validation flaw was found in the way Samba handled Any Batched
(AndX) requests. A remote, unauthenticated attacker could send a
specially-crafted SMB packet to the Samba server, possibly resulting in
arbitrary code execution with the privileges of the Samba server (root).
(CVE-2012-0870)

Red Hat would like to thank the Samba team for reporting this issue.
Upstream acknowledges Andy Davis of NGS Secure as the original reporter.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0332</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0870</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120332"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120349" severity="low">
    <xccdf:title>RHSA-2012:0349: Red Hat Enterprise Linux 4 - Transition to Extended Life Phase Notice (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>On March 01, 2012, all Red Hat Enterprise Linux 4-based products listed
below transition from the Production Phase to the Extended Life Phase:

Red Hat Enterprise Linux AS 4
Red Hat Enterprise Linux ES 4
Red Hat Enterprise Linux WS 4
Red Hat Desktop 4
Red Hat Global File System 4
Red Hat Cluster Suite 4

Red Hat offers support and services for each major release of Red Hat
Enterprise Linux throughout four phases – Production 1, 2, and 3, and
Extended Life Phase. For Red Hat Enterprise Linux 4, the Production Phase
spans seven years, followed by a three-year Extended Life Phase. Together,
these four phases constitute the "life cycle". The specific support and
services provided during each phase is described in detail at:
http://redhat.com/rhel/lifecycle

On March 01, 2012, Red Hat Enterprise Linux 4 systems continue to be
subscribed to Red Hat Enterprise Linux 4 channels on Red Hat Network
(RHN), continue to require a Red Hat Enterprise Linux entitlement, and
continue to have access to:

* Limited technical support for existing Red Hat Enterprise Linux 4
  deployments (for customers with Basic, Premium, or Standard support).

* Previously released bug fixes (RHBAs), security errata (RHSAs), and
  product enhancements (RHEAs) via RHN. Software maintenance (new bug fix
  and security errata) are no longer provided for the Red Hat Enterprise
  Linux 4 product family.

* Red Hat Knowledgebase and other content (white papers, reference
  architectures, etc.) found in the Red Hat Customer Portal.

* Red Hat Enterprise Linux 4 documentation.

Please also note that new bug fix, security, or product enhancements
advisories (RHBAs, RHSAs, and RHEAs) are no longer provided for the Red
Hat Enterprise Linux 4 Add-Ons after March 01.

After March 01, you have several options. Your Red Hat subscription gives
you continuous access to all active versions of the Red Hat software in
both binary and source form, including all security updates and bug fixes.
As Red Hat Enterprise Linux 4 transitions out of the Production Phase, we
strongly recommend that you take full advantage of your subscription
services and upgrade to Red Hat Enterprise Linux 5 or 6, which contain
compelling new features and enablement for modern hardware platforms and
ISV applications.

If you must remain on Red Hat Enterprise Linux 4, we recommend that you
add the Red Hat Enterprise Linux Extended Life Cycle Support (ELS) Add-On
subscription to your current Red Hat Enterprise Linux subscription. The
ELS Add-On complements your Red Hat Enterprise Linux subscription and
provides software maintenance services not otherwise available in the
Extended Life Phase. Customers who purchase the ELS Add-On continue to
receive software maintenance (critical impact security and urgent priority
bug fixes) and technical support as provided in the Production 3 Phase.
ELS is available for up to three years and requires that you have an
existing Red Hat Enterprise Linux subscription with equivalent
subscription terms and support level.

For more information on the Red Hat Enterprise Linux ELS Add-On, visit:
http://www.redhat.com/products/enterprise-linux-add-ons/extended-lifecycle-support/</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0349</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120349"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120350" severity="medium">
    <xccdf:title>RHSA-2012:0350: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the way the Linux kernel's XFS file
system implementation handled links with overly long path names. A local,
unprivileged user could use this flaw to cause a denial of service or
escalate their privileges by mounting a specially-crafted disk.
(CVE-2011-4077, Moderate)

* Flaws in ghash_update() and ghash_final() could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-4081, Moderate)

* A flaw was found in the Linux kernel's Journaling Block Device (JBD). A
local, unprivileged user could use this flaw to crash the system by
mounting a specially-crafted ext3 or ext4 disk. (CVE-2011-4132, Moderate)

* It was found that the kvm_vm_ioctl_assign_device() function in the KVM
(Kernel-based Virtual Machine) subsystem of a Linux kernel did not check if
the user requesting device assignment was privileged or not. A local,
unprivileged user on the host could assign unused PCI devices, or even
devices that were in use and whose resources were not properly claimed by
the respective drivers, which could result in the host crashing.
(CVE-2011-4347, Moderate)

* Two flaws were found in the way the Linux kernel's __sys_sendmsg()
function, when invoked via the sendmmsg() system call, accessed user-space
memory. A local, unprivileged user could use these flaws to cause a denial
of service. (CVE-2011-4594, Moderate)

* The RHSA-2011:1530 kernel update introduced an integer overflow flaw in
the Linux kernel. On PowerPC systems, a local, unprivileged user could use
this flaw to cause a denial of service. (CVE-2011-4611, Moderate)

* A flaw was found in the way the KVM subsystem of a Linux kernel handled
PIT (Programmable Interval Timer) IRQs (interrupt requests) when there was
no virtual interrupt controller set up. A local, unprivileged user on the
host could force this situation to occur, resulting in the host crashing.
(CVE-2011-4622, Moderate)

* A flaw was found in the way the Linux kernel's XFS file system
implementation handled on-disk Access Control Lists (ACLs). A local,
unprivileged user could use this flaw to cause a denial of service or
escalate their privileges by mounting a specially-crafted disk.
(CVE-2012-0038, Moderate)

* A flaw was found in the way the Linux kernel's KVM hypervisor
implementation emulated the syscall instruction for 32-bit guests. An
unprivileged guest user could trigger this flaw to crash the guest.
(CVE-2012-0045, Moderate)

* A divide-by-zero flaw was found in the Linux kernel's igmp_heard_query()
function. An attacker able to send certain IGMP (Internet Group Management
Protocol) packets to a target system could use this flaw to cause a denial
of service. (CVE-2012-0207, Moderate)

Red Hat would like to thank Nick Bowler for reporting CVE-2011-4081; Sasha
Levin for reporting CVE-2011-4347; Tetsuo Handa for reporting
CVE-2011-4594; Maynard Johnson for reporting CVE-2011-4611; Wang Xi for
reporting CVE-2012-0038; Stephan Bärwolf for reporting CVE-2012-0045; and
Simon McVittie for reporting CVE-2012-0207. Upstream acknowledges Mathieu
Desnoyers as the original reporter of CVE-2011-4594.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0350</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4594</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4611</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4622</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0207</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120350"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120369" severity="medium">
    <xccdf:title>RHSA-2012:0369: python-sqlalchemy security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible,
high-level interface to SQL databases.

It was discovered that SQLAlchemy did not sanitize values for the limit and
offset keywords for SQL select statements. If an application using
SQLAlchemy accepted values for these keywords, and did not filter or
sanitize them before passing them to SQLAlchemy, it could allow an attacker
to perform an SQL injection attack against the application. (CVE-2012-0805)

All users of python-sqlalchemy are advised to upgrade to this updated
package, which contains a patch to correct this issue. All running
applications using SQLAlchemy must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0369</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0805</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120369"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120370" severity="high">
    <xccdf:title>RHSA-2012:0370: xen security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A heap overflow flaw was found in the way QEMU emulated the e1000 network
interface card. A privileged guest user in a virtual machine whose network
interface is configured to use the e1000 emulated driver could use this
flaw to crash QEMU or, possibly, escalate their privileges on the host.
(CVE-2012-0029)

Red Hat would like to thank Nicolae Mogoreanu for reporting this issue.

This update also fixes the following bugs:

* Adding support for jumbo frames introduced incorrect network device
expansion when a bridge is created. The expansion worked correctly with the
default configuration, but could have caused network setup failures when a
user-defined network script was used. This update changes the expansion so
network setup will not fail, even when a user-defined network script is
used. (BZ#797191)

* A bug was found in xenconsoled, the Xen hypervisor console daemon. If
timestamp logging for this daemon was enabled (using both the
XENCONSOLED_TIMESTAMP_HYPERVISOR_LOG and XENCONSOLED_TIMESTAMP_GUEST_LOG
options in "/etc/sysconfig/xend"), xenconsoled could crash if the guest
emitted a lot of information to its serial console in a short period of
time. Eventually, the guest would freeze after the console buffer was
filled due to the crashed xenconsoled. Timestamp logging is disabled by
default. (BZ#797836)

All xen users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120370"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120376" severity="medium">
    <xccdf:title>RHSA-2012:0376: systemtap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

An invalid pointer read flaw was found in the way SystemTap handled
malformed debugging information in DWARF format. When SystemTap
unprivileged mode was enabled, an unprivileged user in the stapusr group
could use this flaw to crash the system or, potentially, read arbitrary
kernel memory. Additionally, a privileged user (root, or a member of the
stapdev group) could trigger this flaw when tricked into instrumenting a
specially-crafted ELF binary, even when unprivileged mode was not enabled.
(CVE-2012-0875)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0875</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120387" severity="high">
    <xccdf:title>RHSA-2012:0387: firefox security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user
running Firefox. (CVE-2012-0461, CVE-2012-0462, CVE-2012-0464)

Two flaws were found in the way Firefox parsed certain Scalable Vector
Graphics (SVG) image files. A web page containing a malicious SVG image
file could cause an information leak, or cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-0456, CVE-2012-0457)

A flaw could allow a malicious site to bypass intended restrictions,
possibly leading to a cross-site scripting (XSS) attack if a user were
tricked into dropping a "javascript:" link onto a frame. (CVE-2012-0455)

It was found that the home page could be set to a "javascript:" link. If a
user were tricked into setting such a home page by dragging a link to the
home button, it could cause Firefox to repeatedly crash, eventually
leading to arbitrary code execution with the privileges of the user
running Firefox. (CVE-2012-0458)

A flaw was found in the way Firefox parsed certain web content containing
"cssText". A web page containing malicious content could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2012-0459)

It was found that by using the DOM fullscreen API, untrusted content could
bypass the mozRequestFullscreen security protections. A web page containing
malicious web content could exploit this API flaw to cause user interface
spoofing. (CVE-2012-0460)

A flaw was found in the way Firefox handled pages with multiple Content
Security Policy (CSP) headers. This could lead to a cross-site scripting
attack if used in conjunction with a website that has a header injection
flaw. (CVE-2012-0451)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.3 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bugs:

* When using the Traditional Chinese locale (zh-TW), a segmentation fault
sometimes occurred when closing Firefox. (BZ#729632)

* Inputting any text in the Web Console (Tools -&gt; Web Developer -&gt;
Web Console) caused Firefox to crash. (BZ#784048)

* The java-1.6.0-ibm-plugin and java-1.6.0-sun-plugin packages require the
"/usr/lib/mozilla/plugins/" directory on 32-bit systems, and the
"/usr/lib64/mozilla/plugins/" directory on 64-bit systems. These
directories are created by the xulrunner package; however, they were
missing from the xulrunner package provided by the RHEA-2012:0327 update.
Therefore, upgrading to RHEA-2012:0327 removed those directories, causing
dependency errors when attempting to install the java-1.6.0-ibm-plugin or
java-1.6.0-sun-plugin package. With this update, xulrunner once again
creates the plugins directory. This issue did not affect users of Red Hat
Enterprise Linux 6. (BZ#799042)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.3 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0387</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0464</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120387"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120388" severity="high">
    <xccdf:title>RHSA-2012:0388: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2012-0461,
CVE-2012-0462, CVE-2012-0464)

Two flaws were found in the way Thunderbird parsed certain Scalable Vector
Graphics (SVG) image files. An HTML mail message containing a malicious SVG
image file could cause an information leak, or cause Thunderbird to crash
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2012-0456, CVE-2012-0457)

A flaw could allow malicious content to bypass intended restrictions,
possibly leading to a cross-site scripting (XSS) attack if a user were
tricked into dropping a "javascript:" link onto a frame. (CVE-2012-0455)

It was found that the home page could be set to a "javascript:" link. If a
user were tricked into setting such a home page by dragging a link to the
home button, it could cause Firefox to repeatedly crash, eventually leading
to arbitrary code execution with the privileges of the user running
Firefox. A similar flaw was found and fixed in Thunderbird. (CVE-2012-0458)

A flaw was found in the way Thunderbird parsed certain, remote content
containing "cssText". Malicious, remote content could cause Thunderbird to
crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2012-0459)

It was found that by using the DOM fullscreen API, untrusted content could
bypass the mozRequestFullscreen security protections. Malicious content
could exploit this API flaw to cause user interface spoofing.
(CVE-2012-0460)

A flaw was found in the way Thunderbird handled content with multiple
Content Security Policy (CSP) headers. This could lead to a cross-site
scripting attack if used in conjunction with a website that has a header
injection flaw. (CVE-2012-0451)

Note: All issues except CVE-2012-0456 and CVE-2012-0457 cannot be exploited
by a specially-crafted HTML mail message as JavaScript is disabled by
default for mail messages. It could be exploited another way in
Thunderbird, for example, when viewing the full remote content of an RSS
feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.3 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0388</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0464</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120388"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120393" severity="medium">
    <xccdf:title>RHSA-2012:0393: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function correctly.

An integer overflow flaw was found in the implementation of the printf
functions family. This could allow an attacker to bypass FORTIFY_SOURCE
protections and execute arbitrary code using a format string flaw in
an application, even though these protections are expected to limit the
impact of such flaws to an application abort. (CVE-2012-0864)

This update also fixes the following bugs:

* Previously, the dynamic loader generated an incorrect ordering for
initialization according to the ELF specification. This could result in
incorrect ordering of DSO constructors and destructors. With this update,
dependency resolution has been fixed. (BZ#783999)

* Previously, locking of the main malloc arena was incorrect in the retry
path. This could result in a deadlock if an sbrk request failed. With this
update, locking of the main arena in the retry path has been fixed. This
issue was exposed by a bug fix provided in the RHSA-2012:0058 update.
(BZ#795328)

* Calling memcpy with overlapping arguments on certain processors would
generate unexpected results. While such code is a clear violation of
ANSI/ISO standards, this update restores prior memcpy behavior. (BZ#799259)

All users of glibc are advised to upgrade to these updated packages, which
contain patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0864</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120393"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120397" severity="medium">
    <xccdf:title>RHSA-2012:0397: glibc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function correctly.

An integer overflow flaw was found in the implementation of the printf
functions family. This could allow an attacker to bypass FORTIFY_SOURCE
protections and execute arbitrary code using a format string flaw in an
application, even though these protections are expected to limit the impact
of such flaws to an application abort. (CVE-2012-0864)

All users of glibc are advised to upgrade to these updated packages, which
contain a patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0864</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120397"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120407" severity="medium">
    <xccdf:title>RHSA-2012:0407: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap-based buffer overflow flaw was found in the way libpng processed
compressed chunks in PNG image files. An attacker could create a
specially-crafted PNG image file that, when opened, could cause an
application using libpng to crash or, possibly, execute arbitrary code with
the privileges of the user running the application. (CVE-2011-3045)

Users of libpng should upgrade to these updated packages, which correct
this issue. For Red Hat Enterprise Linux 5, they contain a backported
patch. For Red Hat Enterprise Linux 6, they upgrade libpng to version
1.2.48. All running applications using libpng must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3045</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120407"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120410" severity="high">
    <xccdf:title>RHSA-2012:0410: raptor security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Raptor provides parsers for Resource Description Framework (RDF) files.

An XML External Entity expansion flaw was found in the way Raptor processed
RDF files. If an application linked against Raptor were to open a 
specially-crafted RDF file, it could possibly allow a remote attacker to 
obtain a copy of an arbitrary local file that the user running the
application had access to. A bug in the way Raptor handled external
entities could cause that application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-0037)

Red Hat would like to thank Timothy D. Morgan of VSR for reporting this
issue.

All Raptor users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against Raptor must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0037</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120410"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120411" severity="high">
    <xccdf:title>RHSA-2012:0411: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program. OpenOffice.org
embeds a copy of Raptor, which provides parsers for Resource Description
Framework (RDF) files.

An XML External Entity expansion flaw was found in the way Raptor processed
RDF files. If OpenOffice.org were to open a specially-crafted file (such
as an OpenDocument Format or OpenDocument Presentation file), it could
possibly allow a remote attacker to obtain a copy of an arbitrary local
file that the user running OpenOffice.org had access to. A bug in the way
Raptor handled external entities could cause OpenOffice.org to crash or,
possibly, execute arbitrary code with the privileges of the user running 
OpenOffice.org. (CVE-2012-0037)

Red Hat would like to thank Timothy D. Morgan of VSR for reporting this
issue.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct this issue. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0037</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120411"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120426" severity="medium">
    <xccdf:title>RHSA-2012:0426: openssl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A NULL pointer dereference flaw was found in the way OpenSSL parsed
Secure/Multipurpose Internet Mail Extensions (S/MIME) messages. An attacker
could use this flaw to crash an application that uses OpenSSL to decrypt or
verify S/MIME messages. (CVE-2012-1165)

A flaw was found in the PKCS#7 and Cryptographic Message Syntax (CMS)
implementations in OpenSSL. An attacker could possibly use this flaw to
perform a Bleichenbacher attack to decrypt an encrypted CMS, PKCS#7, or
S/MIME message by sending a large number of chosen ciphertext messages to
a service using OpenSSL and measuring error response times. (CVE-2012-0884)

This update also fixes a regression caused by the fix for CVE-2011-4619,
released via RHSA-2012:0060 and RHSA-2012:0059, which caused Server Gated
Cryptography (SGC) handshakes to fail.

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1165</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120426"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120427" severity="high">
    <xccdf:title>RHSA-2012:0427: libtasn1 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libtasn1 is a library developed for ASN.1 (Abstract Syntax Notation One)
structures management that includes DER (Distinguished Encoding Rules)
encoding and decoding.

A flaw was found in the way libtasn1 decoded DER data. An attacker could
create carefully-crafted DER encoded input (such as an X.509 certificate)
that, when parsed by an application that uses libtasn1 (such as
applications using GnuTLS), could cause the application to crash.
(CVE-2012-1569)

Red Hat would like to thank Matthew Hall of Mu Dynamics for reporting this
issue.

Users of libtasn1 are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the libtasn1 library must be restarted,
or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1569</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120427"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120428" severity="high">
    <xccdf:title>RHSA-2012:0428: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). GnuTLS includes libtasn1,
a library developed for ASN.1 (Abstract Syntax Notation One) structures
management that includes DER (Distinguished Encoding Rules) encoding and
decoding.

A flaw was found in the way GnuTLS decrypted malformed TLS records. This
could cause a TLS/SSL client or server to crash when processing a
specially-crafted TLS record from a remote TLS/SSL connection peer.
(CVE-2012-1573)

A flaw was found in the way libtasn1 decoded DER data. An attacker could
create a carefully-crafted X.509 certificate that, when parsed by an
application that uses GnuTLS, could cause the application to crash.
(CVE-2012-1569)

A boundary error was found in the gnutls_session_get_data() function. A
malicious TLS/SSL server could use this flaw to crash a TLS/SSL client or,
possibly, execute arbitrary code as the client, if the client passed a
fixed-sized buffer to gnutls_session_get_data() before checking the real
size of the session data provided by the server. (CVE-2011-4128)

Red Hat would like to thank Matthew Hall of Mu Dynamics for reporting
CVE-2012-1573 and CVE-2012-1569.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all applications linked to the GnuTLS library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1573</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120428"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120429" severity="high">
    <xccdf:title>RHSA-2012:0429: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way GnuTLS decrypted malformed TLS records. This
could cause a TLS/SSL client or server to crash when processing a
specially-crafted TLS record from a remote TLS/SSL connection peer.
(CVE-2012-1573)

A boundary error was found in the gnutls_session_get_data() function. A
malicious TLS/SSL server could use this flaw to crash a TLS/SSL client or,
possibly, execute arbitrary code as the client, if the client passed a
fixed-sized buffer to gnutls_session_get_data() before checking the real
size of the session data provided by the server. (CVE-2011-4128)

Red Hat would like to thank Matthew Hall of Mu Dynamics for reporting
CVE-2012-1573.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all applications linked to the GnuTLS library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1573</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120429"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120451" severity="high">
    <xccdf:title>RHSA-2012:0451: rpm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a command-line driven package management
system capable of installing, uninstalling, verifying, querying, and
updating software packages.

Multiple flaws were found in the way RPM parsed package file headers. An
attacker could create a specially-crafted RPM package that, when its
package header was accessed, or during package signature verification,
could cause an application using the RPM library (such as the rpm command
line tool, or the yum and up2date package managers) to crash or,
potentially, execute arbitrary code. (CVE-2012-0060, CVE-2012-0061,
CVE-2012-0815)

Note: Although an RPM package can, by design, execute arbitrary code when
installed, this issue would allow a specially-crafted RPM package to
execute arbitrary code before its digital signature has been verified.
Package downloads from the Red Hat Network are protected by the use of a
secure HTTPS connection in addition to the RPM package signature checks.

All RPM users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running applications linked
against the RPM library must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0815</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120451"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120465" severity="high">
    <xccdf:title>RHSA-2012:0465: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A flaw in the Samba suite's Perl-based DCE/RPC IDL (PIDL) compiler, used
to generate code to handle RPC calls, resulted in multiple buffer overflows
in Samba. A remote, unauthenticated attacker could send a specially-crafted
RPC request that would cause the Samba daemon (smbd) to crash or, possibly,
execute arbitrary code with the privileges of the root user.
(CVE-2012-1182)

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120465"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120466" severity="high">
    <xccdf:title>RHSA-2012:0466: samba3x security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A flaw in the Samba suite's Perl-based DCE/RPC IDL (PIDL) compiler, used
to generate code to handle RPC calls, resulted in multiple buffer overflows
in Samba. A remote, unauthenticated attacker could send a specially-crafted
RPC request that would cause the Samba daemon (smbd) to crash or, possibly,
execute arbitrary code with the privileges of the root user.
(CVE-2012-1182)

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120466"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120467" severity="high">
    <xccdf:title>RHSA-2012:0467: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently.

Multiple flaws were found in the way FreeType handled TrueType Font (TTF),
Glyph Bitmap Distribution Format (BDF), Windows .fnt and .fon, and
PostScript Type 1 fonts. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2012-1134, CVE-2012-1136, CVE-2012-1142,
CVE-2012-1144)

Multiple flaws were found in the way FreeType handled fonts in various
formats. If a specially-crafted font file was loaded by an application
linked against FreeType, it could cause the application to crash.
(CVE-2012-1126, CVE-2012-1127, CVE-2012-1130, CVE-2012-1131, CVE-2012-1132,
CVE-2012-1137, CVE-2012-1139, CVE-2012-1140, CVE-2012-1141, CVE-2012-1143)

Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for
reporting these issues.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1144</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120467"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120468" severity="high">
    <xccdf:title>RHSA-2012:0468: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Two integer overflow flaws, leading to heap-based buffer overflows, were
found in the way libtiff attempted to allocate space for a tile in a TIFF
image file. An attacker could use these flaws to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2012-1173)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1173</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120468"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120474" severity="medium">
    <xccdf:title>RHSA-2012:0474: tomcat5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that the Java hashCode() method implementation was susceptible
to predictable hash collisions. A remote attacker could use this flaw to
cause Tomcat to use an excessive amount of CPU time by sending an HTTP
request with a large number of parameters whose names map to the same hash
value. This update introduces a limit on the number of parameters processed
per request to mitigate this issue. The default limit is 512 for
parameters and 128 for headers. These defaults can be changed by setting
the org.apache.tomcat.util.http.Parameters.MAX_COUNT and
org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties.
(CVE-2011-4858)

It was found that Tomcat did not handle large numbers of parameters and
large parameter values efficiently. A remote attacker could make Tomcat
use an excessive amount of CPU time by sending an HTTP request containing a
large number of parameters or large parameter values. This update
introduces limits on the number of parameters and headers processed per
request to address this issue. Refer to the CVE-2011-4858 description for
information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and
org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties.
(CVE-2012-0022) 

Red Hat would like to thank oCERT for reporting CVE-2011-4858. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4858.

Users of Tomcat should upgrade to these updated packages, which correct
these issues. Tomcat must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120475" severity="medium">
    <xccdf:title>RHSA-2012:0475: tomcat6 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that the Java hashCode() method implementation was susceptible
to predictable hash collisions. A remote attacker could use this flaw to
cause Tomcat to use an excessive amount of CPU time by sending an HTTP
request with a large number of parameters whose names map to the same hash
value. This update introduces a limit on the number of parameters processed
per request to mitigate this issue. The default limit is 512 for
parameters and 128 for headers. These defaults can be changed by setting
the org.apache.tomcat.util.http.Parameters.MAX_COUNT and
org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties.
(CVE-2011-4858)

It was found that Tomcat did not handle large numbers of parameters and
large parameter values efficiently. A remote attacker could make Tomcat
use an excessive amount of CPU time by sending an HTTP request containing a
large number of parameters or large parameter values. This update
introduces limits on the number of parameters and headers processed per
request to address this issue. Refer to the CVE-2011-4858 description for
information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and
org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties.
(CVE-2012-0022) 

Red Hat would like to thank oCERT for reporting CVE-2011-4858. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2011-4858.

Users of Tomcat should upgrade to these updated packages, which correct
these issues. Tomcat must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120475"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120480" severity="high">
    <xccdf:title>RHSA-2012:0480: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw in the xfrm6_tunnel_rcv() function in the Linux kernel's IPv6
implementation could lead to a use-after-free or double free flaw in
tunnel6_rcv(). A remote attacker could use this flaw to send
specially-crafted packets to a target system that is using IPv6 and also
has the xfrm6_tunnel kernel module loaded, causing it to crash.
(CVE-2012-1583, Important)

If you do not run applications that use xfrm6_tunnel, you can prevent the
xfrm6_tunnel module from being loaded by creating (as the root user) a
"/etc/modprobe.d/xfrm6_tunnel.conf" file, and adding the following line to
it:

blacklist xfrm6_tunnel

This way, the xfrm6_tunnel module cannot be loaded accidentally. A reboot
is not necessary for this change to take effect.

This update also fixes various bugs and adds an enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1583</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120480"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120481" severity="medium">
    <xccdf:title>RHSA-2012:0481: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Numerous reference count leaks were found in the Linux kernel's block
layer I/O context handling implementation. This could allow a local,
unprivileged user to cause a denial of service. (CVE-2012-0879,
Moderate)

* A flaw was found in the Linux kernel's cifs_lookup() implementation.
POSIX open during lookup should only be supported for regular files. When
non-regular files (for example, a named (FIFO) pipe or other special files)
are opened on lookup, it could cause a denial of service. (CVE-2012-1090,
Moderate)

* It was found that the Linux kernel's register set (regset) common
infrastructure implementation did not check if the required get and set
handlers were initialized. A local, unprivileged user could use this flaw
to cause a denial of service by performing a register set operation with a
ptrace() PTRACE_SETREGSET or PTRACE_GETREGSET request. (CVE-2012-1097,
Moderate)

Red Hat would like to thank H. Peter Anvin for reporting CVE-2012-1097.

This update also fixes several bugs and adds various enhancements.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancements
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0879</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1097</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120481"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120509" severity="medium">
    <xccdf:title>RHSA-2012:0509: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Several flaws were found in Wireshark. If Wireshark read a malformed packet
off a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2011-1590,
CVE-2011-4102, CVE-2012-1595)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2011-1143, CVE-2011-1957, CVE-2011-1958,
CVE-2011-1959, CVE-2011-2174, CVE-2011-2175, CVE-2011-2597, CVE-2011-2698,
CVE-2012-0041, CVE-2012-0042, CVE-2012-0067, CVE-2012-0066)

Users of Wireshark should upgrade to these updated packages, which contain
backported patches to correct these issues. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0041</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1595</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120509"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120515" severity="high">
    <xccdf:title>RHSA-2012:0515: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in Sanitiser for OpenType (OTS), used by Firefox to help
prevent potential exploits in malformed OpenType fonts. A web page
containing malicious content could cause Firefox to crash or, under certain
conditions, possibly execute arbitrary code with the privileges of the user
running Firefox. (CVE-2011-3062)

A web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-0467, CVE-2012-0468, CVE-2012-0469)

A web page containing a malicious Scalable Vector Graphics (SVG) image file
could cause Firefox to crash or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2012-0470)

A flaw was found in the way Firefox used its embedded Cairo library to
render certain fonts. A web page containing malicious content could cause
Firefox to crash or, under certain conditions, possibly execute arbitrary
code with the privileges of the user running Firefox. (CVE-2012-0472)

A flaw was found in the way Firefox rendered certain images using WebGL. A
web page containing malicious content could cause Firefox to crash or,
under certain conditions, possibly execute arbitrary code with the
privileges of the user running Firefox. (CVE-2012-0478)

A cross-site scripting (XSS) flaw was found in the way Firefox handled
certain multibyte character sets. A web page containing malicious content
could cause Firefox to run JavaScript code with the permissions of a
different website. (CVE-2012-0471)

A flaw was found in the way Firefox rendered certain graphics using WebGL.
A web page containing malicious content could cause Firefox to crash.
(CVE-2012-0473)

A flaw in Firefox allowed the address bar to display a different website
than the one the user was visiting. An attacker could use this flaw to
conceal a malicious URL, possibly tricking a user into believing they are
viewing a trusted site, or allowing scripts to be loaded from the
attacker's site, possibly leading to cross-site scripting (XSS) attacks.
(CVE-2012-0474)

A flaw was found in the way Firefox decoded the ISO-2022-KR and ISO-2022-CN
character sets. A web page containing malicious content could cause Firefox
to run JavaScript code with the permissions of a different website.
(CVE-2012-0477)

A flaw was found in the way Firefox handled RSS and Atom feeds. Invalid
RSS or Atom content loaded over HTTPS caused Firefox to display the
address of said content in the location bar, but not the content in the
main window. The previous content continued to be displayed. An attacker
could use this flaw to perform phishing attacks, or trick users into
thinking they are visiting the site reported by the location bar, when the
page is actually content controlled by an attacker. (CVE-2012-0479)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.4 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Mateusz Jurczyk of the Google Security Team as the
original reporter of CVE-2011-3062; Aki Helin from OUSPG as the original
reporter of CVE-2012-0469; Atte Kettunen from OUSPG as the original
reporter of CVE-2012-0470; wushi of team509 via iDefense as the original
reporter of CVE-2012-0472; Ms2ger as the original reporter of
CVE-2012-0478; Anne van Kesteren of Opera Software as the original reporter
of CVE-2012-0471; Matias Juntunen as the original reporter of
CVE-2012-0473; Jordi Chancel and Eddy Bordi, and Chris McGowen as the
original reporters of CVE-2012-0474; Masato Kinugawa as the original
reporter of CVE-2012-0477; and Jeroen van der Gun as the original reporter
of CVE-2012-0479.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0479</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120515"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120516" severity="high">
    <xccdf:title>RHSA-2012:0516: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in Sanitiser for OpenType (OTS), used by Thunderbird to
help prevent potential exploits in malformed OpenType fonts. Malicious
content could cause Thunderbird to crash or, under certain conditions,
possibly execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2011-3062)

Malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2012-0467, CVE-2012-0468, CVE-2012-0469)

Content containing a malicious Scalable Vector Graphics (SVG) image file
could cause Thunderbird to crash or, potentially, execute arbitrary code
with the privileges of the user running Thunderbird. (CVE-2012-0470)

A flaw was found in the way Thunderbird used its embedded Cairo library to
render certain fonts. Malicious content could cause Thunderbird to crash
or, under certain conditions, possibly execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2012-0472)

A flaw was found in the way Thunderbird rendered certain images using
WebGL. Malicious content could cause Thunderbird to crash or, under certain
conditions, possibly execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2012-0478)

A cross-site scripting (XSS) flaw was found in the way Thunderbird handled
certain multibyte character sets. Malicious content could cause Thunderbird
to run JavaScript code with the permissions of different content.
(CVE-2012-0471)

A flaw was found in the way Thunderbird rendered certain graphics using
WebGL. Malicious content could cause Thunderbird to crash. (CVE-2012-0473)

A flaw in the built-in feed reader in Thunderbird allowed the Website field
to display the address of different content than the content the user was
visiting. An attacker could use this flaw to conceal a malicious URL,
possibly tricking a user into believing they are viewing a trusted site, or
allowing scripts to be loaded from the attacker's site, possibly leading to
cross-site scripting (XSS) attacks. (CVE-2012-0474)

A flaw was found in the way Thunderbird decoded the ISO-2022-KR and
ISO-2022-CN character sets. Malicious content could cause Thunderbird
to run JavaScript code with the permissions of different content.
(CVE-2012-0477)

A flaw was found in the way the built-in feed reader in Thunderbird handled
RSS and Atom feeds. Invalid RSS or Atom content loaded over HTTPS caused
Thunderbird to display the address of said content, but not the content.
The previous content continued to be displayed. An attacker could use this
flaw to perform phishing attacks, or trick users into thinking they are
visiting the site reported by the Website field, when the page is actually
content controlled by an attacker. (CVE-2012-0479)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Mateusz Jurczyk of the Google Security Team as the
original reporter of CVE-2011-3062; Aki Helin from OUSPG as the original
reporter of CVE-2012-0469; Atte Kettunen from OUSPG as the original
reporter of CVE-2012-0470; wushi of team509 via iDefense as the original
reporter of CVE-2012-0472; Ms2ger as the original reporter of
CVE-2012-0478; Anne van Kesteren of Opera Software as the original reporter
of CVE-2012-0471; Matias Juntunen as the original reporter of
CVE-2012-0473; Jordi Chancel and Eddy Bordi, and Chris McGowen as the
original reporters of CVE-2012-0474; Masato Kinugawa as the original
reporter of CVE-2012-0477; and Jeroen van der Gun as the original reporter
of CVE-2012-0479.

Note: All issues except CVE-2012-0470, CVE-2012-0472, and CVE-2011-3062
cannot be exploited by a specially-crafted HTML mail message as JavaScript
is disabled by default for mail messages. It could be exploited another way
in Thunderbird, for example, when viewing the full remote content of an
RSS feed.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0479</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120516"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120518" severity="high">
    <xccdf:title>RHSA-2012:0518: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

Multiple numeric conversion errors, leading to a buffer overflow, were
found in the way OpenSSL parsed ASN.1 (Abstract Syntax Notation One) data
from BIO (OpenSSL's I/O abstraction) inputs. Specially-crafted DER
(Distinguished Encoding Rules) encoded data read from a file or other BIO
input could cause an application using the OpenSSL library to crash or,
potentially, execute arbitrary code. (CVE-2012-2110)

All OpenSSL users should upgrade to these updated packages, which contain
a backported patch to resolve this issue. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2110</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120518"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120523" severity="medium">
    <xccdf:title>RHSA-2012:0523: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap-based buffer overflow flaw was found in the way libpng processed
tEXt chunks in PNG image files. An attacker could create a
specially-crafted PNG image file that, when opened, could cause an
application using libpng to crash or, possibly, execute arbitrary code with
the privileges of the user running the application. (CVE-2011-3048)

Users of libpng should upgrade to these updated packages, which correct
this issue. For Red Hat Enterprise Linux 5, they contain a backported
patch. For Red Hat Enterprise Linux 6, they upgrade libpng to version
1.2.49. All running applications using libpng must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0523</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3048</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120523"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120533" severity="high">
    <xccdf:title>RHSA-2012:0533: samba and samba3x security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A flaw was found in the way Samba handled certain Local Security Authority
(LSA) Remote Procedure Calls (RPC). An authenticated user could use this
flaw to issue an RPC call that would modify the privileges database on the
Samba server, allowing them to steal the ownership of files and directories
that are being shared by the Samba server, and create, delete, and modify
user accounts, as well as other Samba server administration tasks.
(CVE-2012-2111)

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Ivano Cristofolini as the original reporter.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2111</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120533"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120544" severity="medium">
    <xccdf:title>RHSA-2012:0544: ImageMagick security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A flaw was found in the way ImageMagick processed images with malformed
Exchangeable image file format (Exif) metadata. An attacker could create a
specially-crafted image file that, when opened by a victim, would cause
ImageMagick to crash or, potentially, execute arbitrary code.
(CVE-2012-0247)

A denial of service flaw was found in the way ImageMagick processed images
with malformed Exif metadata. An attacker could create a specially-crafted
image file that, when opened by a victim, could cause ImageMagick to enter
an infinite loop. (CVE-2012-0248)

It was found that ImageMagick utilities tried to load ImageMagick
configuration files from the current working directory. If a user ran an
ImageMagick utility in an attacker-controlled directory containing a
specially-crafted ImageMagick configuration file, it could cause the
utility to execute arbitrary code. (CVE-2010-4167)

An integer overflow flaw was found in the way ImageMagick processed
certain Exif tags with a large components count. An attacker could create
a specially-crafted image file that, when opened by a victim, could cause
ImageMagick to access invalid memory and crash. (CVE-2012-0259)

A denial of service flaw was found in the way ImageMagick decoded certain
JPEG images. A remote attacker could provide a JPEG image with
specially-crafted sequences of RST0 up to RST7 restart markers (used to
indicate the input stream to be corrupted), which once processed by
ImageMagick, would cause it to consume excessive amounts of memory and CPU
time. (CVE-2012-0260)

An out-of-bounds buffer read flaw was found in the way ImageMagick
processed certain TIFF image files. A remote attacker could provide a TIFF
image with a specially-crafted Exif IFD value (the set of tags for
recording Exif-specific attribute information), which once opened by
ImageMagick, would cause it to crash. (CVE-2012-1798)

Red Hat would like to thank CERT-FI for reporting CVE-2012-0259,
CVE-2012-0260, and CVE-2012-1798. CERT-FI acknowledges Aleksis Kauppinen,
Joonas Kuorilehto, Tuomas Parttimaa and Lasse Ylivainio of Codenomicon's
CROSS project as the original reporters.

Users of ImageMagick are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of ImageMagick must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0259</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120544"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120545" severity="medium">
    <xccdf:title>RHSA-2012:0545: ImageMagick security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A flaw was found in the way ImageMagick processed images with malformed
Exchangeable image file format (Exif) metadata. An attacker could create a
specially-crafted image file that, when opened by a victim, would cause
ImageMagick to crash or, potentially, execute arbitrary code.
(CVE-2012-0247)

A denial of service flaw was found in the way ImageMagick processed images
with malformed Exif metadata. An attacker could create a specially-crafted
image file that, when opened by a victim, could cause ImageMagick to enter
an infinite loop. (CVE-2012-0248)

A denial of service flaw was found in the way ImageMagick decoded certain
JPEG images. A remote attacker could provide a JPEG image with
specially-crafted sequences of RST0 up to RST7 restart markers (used to
indicate the input stream to be corrupted), which once processed by
ImageMagick, would cause it to consume excessive amounts of memory and CPU
time. (CVE-2012-0260)

Red Hat would like to thank CERT-FI for reporting CVE-2012-0260. CERT-FI
acknowledges Aleksis Kauppinen, Joonas Kuorilehto, Tuomas Parttimaa and
Lasse Ylivainio of Codenomicon's CROSS project as the original reporters.

This update also fixes the following bug:

* The fix for Red Hat Bugzilla bug 694922, provided by the RHSA-2012:0301
ImageMagick update, introduced a regression. Attempting to use the
"convert" utility to convert a PostScript document could fail with a
"/undefinedfilename" error. With this update, conversion works as expected.
(BZ#804546)

Users of ImageMagick are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of ImageMagick must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0260</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120545"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120546" severity="high">
    <xccdf:title>RHSA-2012:0546: php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way the php-cgi executable processed command line
arguments when running in CGI mode. A remote attacker could send a
specially-crafted request to a PHP script that would result in the query
string being parsed by php-cgi as command line options and arguments. This
could lead to the disclosure of the script's source code or arbitrary code
execution with the privileges of the PHP interpreter. (CVE-2012-1823)

Red Hat is aware that a public exploit for this issue is available that
allows remote code execution in affected PHP CGI configurations. This flaw
does not affect the default configuration in Red Hat Enterprise Linux 5 and
6 using the PHP module for Apache httpd to handle PHP scripts.

All php users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1823</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120546"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120547" severity="high">
    <xccdf:title>RHSA-2012:0547: php53 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way the php-cgi executable processed command line
arguments when running in CGI mode. A remote attacker could send a 
specially-crafted request to a PHP script that would result in the query
string being parsed by php-cgi as command line options and arguments. This 
could lead to the disclosure of the script's source code or arbitrary code 
execution with the privileges of the PHP interpreter. (CVE-2012-1823) 

Red Hat is aware that a public exploit for this issue is available that 
allows remote code execution in affected PHP CGI configurations. This flaw 
does not affect the default configuration using the PHP module for Apache 
httpd to handle PHP scripts.

All php53 users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1823</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120547"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120571" severity="medium">
    <xccdf:title>RHSA-2012:0571: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Linux kernel's journal_unmap_buffer()
function handled buffer head states. On systems that have an ext4 file
system with a journal mounted, a local, unprivileged user could use this
flaw to cause a denial of service. (CVE-2011-4086, Moderate)

* A flaw was found in the way the KVM_CREATE_IRQCHIP ioctl was handled.
Calling this ioctl when at least one virtual CPU (VCPU) already existed
could lead to a NULL pointer dereference later when the VCPU is scheduled
to run. A local, unprivileged user on a KVM host could use this flaw to
crash the host. (CVE-2012-1601, Moderate)

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1601</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120571"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120676" severity="medium">
    <xccdf:title>RHSA-2012:0676: kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way the KVM_CREATE_IRQCHIP ioctl was handled.
Calling this ioctl when at least one virtual CPU (VCPU) already existed
could lead to a NULL pointer dereference later when the VCPU is scheduled
to run. A malicious user in the kvm group on the host could use this flaw
to crash the host. (CVE-2012-1601)

A flaw was found in the way device memory was handled during guest device
removal. Upon successful device removal, memory used by the device was not
properly unmapped from the corresponding IOMMU or properly released from
the kernel, leading to a memory leak. A malicious user in the kvm group on
the host who has the ability to assign a device to a guest could use this
flaw to crash the host. (CVE-2012-2121)

This update also fixes the following bug:

* An off-by-one error in the QEMU guest's memory management could, in rare
cases, cause QEMU-KVM to crash due to a segmentation fault in
tb_invalidate_phys_page_range() if a device initiated DMA into a specific
guest address. In a reported case, this issue presented on a system that
had a guest using the 8139cp network driver. (BZ#816207)

All users of kvm are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Note that the procedure
in the Solution section must be performed before this update will take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2121</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120676"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120677" severity="medium">
    <xccdf:title>RHSA-2012:0677: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

The pg_dump utility inserted object names literally into comments in the
SQL script it produces. An unprivileged database user could create an
object whose name includes a newline followed by an SQL command. This SQL
command might then be executed by a privileged user during later restore of
the backup dump, allowing privilege escalation. (CVE-2012-0868)

CREATE TRIGGER did not do a permissions check on the trigger function to
be called. This could possibly allow an authenticated database user to
call a privileged trigger function on data of their choosing.
(CVE-2012-0866)

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0866</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0868</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120677"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120678" severity="medium">
    <xccdf:title>RHSA-2012:0678: postgresql and postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

The pg_dump utility inserted object names literally into comments in the
SQL script it produces. An unprivileged database user could create an
object whose name includes a newline followed by an SQL command. This SQL
command might then be executed by a privileged user during later restore of
the backup dump, allowing privilege escalation. (CVE-2012-0868)

When configured to do SSL certificate verification, PostgreSQL only checked
the first 31 characters of the certificate's Common Name field. Depending
on the configuration, this could allow an attacker to impersonate a server
or a client using a certificate from a trusted Certificate Authority issued
for a different name. (CVE-2012-0867)

CREATE TRIGGER did not do a permissions check on the trigger function to
be called. This could possibly allow an authenticated database user to
call a privileged trigger function on data of their choosing.
(CVE-2012-0866)

These updated packages upgrade PostgreSQL to version 8.4.11, which fixes
these issues as well as several data-corruption issues and lesser
non-security issues. Refer to the PostgreSQL Release Notes for a full list
of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0866</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0868</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120678"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120683" severity="high">
    <xccdf:title>RHSA-2012:0683: bind-dyndb-ldap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dynamic LDAP back end is a plug-in for BIND that provides back-end
capabilities to LDAP databases. It features support for dynamic updates
and internal caching that help to reduce the load on LDAP servers.

A flaw was found in the way bind-dyndb-ldap handled LDAP query errors. If a
remote attacker were able to send DNS queries to a named server that is
configured to use bind-dyndb-ldap, they could trigger such an error with a
DNS query leveraging bind-dyndb-ldap's insufficient escaping of the LDAP
base DN (distinguished name). This would result in an invalid LDAP query
that named would retry in a loop, preventing it from responding to other
DNS queries. With this update, bind-dyndb-ldap only attempts to retry one
time when an LDAP search returns an unexpected error. (CVE-2012-2134)

Red Hat would like to thank Ronald van Zantvoort for reporting this issue.

All bind-dyndb-ldap users should upgrade to this updated package, which
contains a backported patch to correct this issue. For the update to take
effect, the named service must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2134</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120683"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120690" severity="high">
    <xccdf:title>RHSA-2012:0690: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that the data_len parameter of the sock_alloc_send_pskb()
function in the Linux kernel's networking implementation was not validated
before use. A local user with access to a TUN/TAP virtual interface could
use this flaw to crash the system or, potentially, escalate their
privileges. Note that unprivileged users cannot access TUN/TAP devices
until the root user grants them access. (CVE-2012-2136, Important)

This update also fixes various bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2136</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120690"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120699" severity="medium">
    <xccdf:title>RHSA-2012:0699: openssl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An integer underflow flaw, leading to a buffer over-read, was found in the
way OpenSSL handled DTLS (Datagram Transport Layer Security) application
data record lengths when using a block cipher in CBC (cipher-block
chaining) mode. A malicious DTLS client or server could use this flaw to
crash its DTLS connection peer. (CVE-2012-2333)

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Codenomicon as the original reporter.

On Red Hat Enterprise Linux 6, this update also fixes an uninitialized
variable use bug, introduced by the fix for CVE-2012-0884 (released via
RHSA-2012:0426). This bug could possibly cause an attempt to create an
encrypted message in the CMS (Cryptographic Message Syntax) format to fail.

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2333</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120699"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120705" severity="high">
    <xccdf:title>RHSA-2012:0705: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An integer overflow flaw, leading to a buffer overflow, was found in the
way OpenOffice.org processed an invalid Escher graphics records length in
Microsoft Office PowerPoint documents. An attacker could provide a
specially-crafted Microsoft Office PowerPoint document that, when opened,
would cause OpenOffice.org to crash or, potentially, execute arbitrary code
with the privileges of the user running OpenOffice.org. (CVE-2012-2334)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the JPEG, PNG, and BMP image file reader implementations in
OpenOffice.org. An attacker could provide a specially-crafted JPEG, PNG,
or BMP image file that, when opened in an OpenOffice.org application, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-1149)

Upstream acknowledges Sven Jacobi as the original reporter of
CVE-2012-2334, and Tielei Wang via Secunia SVCRP as the original reporter
of CVE-2012-1149.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1149</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2334</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120705"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120710" severity="high">
    <xccdf:title>RHSA-2012:0710: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-3101, CVE-2012-1937, CVE-2012-1938, CVE-2012-1939,
CVE-2012-1940, CVE-2012-1941, CVE-2012-1946, CVE-2012-1947)

Note: CVE-2011-3101 only affected users of certain NVIDIA display drivers
with graphics cards that have hardware acceleration enabled.

It was found that the Content Security Policy (CSP) implementation in
Firefox no longer blocked Firefox inline event handlers. A remote attacker
could use this flaw to possibly bypass a web application's intended
restrictions, if that application relied on CSP to protect against flaws
such as cross-site scripting (XSS). (CVE-2012-1944)

If a web server hosted HTML files that are stored on a Microsoft Windows
share, or a Samba share, loading such files with Firefox could result in
Windows shortcut files (.lnk) in the same share also being loaded. An
attacker could use this flaw to view the contents of local files and
directories on the victim's system. This issue also affected users opening
HTML files from Microsoft Windows shares, or Samba shares, that are mounted
on their systems. (CVE-2012-1945)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.5 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Ken Russell of Google as the original reporter of
CVE-2011-3101; Igor Bukanov, Olli Pettay, Boris Zbarsky, and Jesse Ruderman
as the original reporters of CVE-2012-1937; Jesse Ruderman, Igor Bukanov,
Bill McCloskey, Christian Holler, Andrew McCreight, and Brian Bondy as the
original reporters of CVE-2012-1938; Christian Holler as the original
reporter of CVE-2012-1939; security researcher Abhishek Arya of Google as
the original reporter of CVE-2012-1940, CVE-2012-1941, and CVE-2012-1947;
security researcher Arthur Gerkis as the original reporter of
CVE-2012-1946; security researcher Adam Barth as the original reporter of
CVE-2012-1944; and security researcher Paul Stone as the original reporter
of CVE-2012-1945.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.5 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1938</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1941</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1945</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1946</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3105</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120710"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120715" severity="high">
    <xccdf:title>RHSA-2012:0715: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-3101,
CVE-2012-1937, CVE-2012-1938, CVE-2012-1939, CVE-2012-1940, CVE-2012-1941,
CVE-2012-1946, CVE-2012-1947)

Note: CVE-2011-3101 only affected users of certain NVIDIA display drivers
with graphics cards that have hardware acceleration enabled.

It was found that the Content Security Policy (CSP) implementation in
Thunderbird no longer blocked Thunderbird inline event handlers. Malicious
content could possibly bypass intended restrictions if that content relied
on CSP to protect against flaws such as cross-site scripting (XSS).
(CVE-2012-1944)

If a web server hosted content that is stored on a Microsoft Windows share,
or a Samba share, loading such content with Thunderbird could result in
Windows shortcut files (.lnk) in the same share also being loaded. An
attacker could use this flaw to view the contents of local files and
directories on the victim's system. This issue also affected users opening
content from Microsoft Windows shares, or Samba shares, that are mounted
on their systems. (CVE-2012-1945)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Ken Russell of Google as the original reporter of
CVE-2011-3101; Igor Bukanov, Olli Pettay, Boris Zbarsky, and Jesse Ruderman
as the original reporters of CVE-2012-1937; Jesse Ruderman, Igor Bukanov,
Bill McCloskey, Christian Holler, Andrew McCreight, and Brian Bondy as the
original reporters of CVE-2012-1938; Christian Holler as the original
reporter of CVE-2012-1939; security researcher Abhishek Arya of Google as
the original reporter of CVE-2012-1940, CVE-2012-1941, and CVE-2012-1947;
security researcher Arthur Gerkis as the original reporter of
CVE-2012-1946; security researcher Adam Barth as the original reporter of
CVE-2012-1944; and security researcher Paul Stone as the original reporter
of CVE-2012-1945.

Note: None of the issues in this advisory can be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.5 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1937</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1938</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1941</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1945</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1946</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1947</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3105</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120715"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120716" severity="high">
    <xccdf:title>RHSA-2012:0716: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled zero length resource data records.
A malicious owner of a DNS domain could use this flaw to create
specially-crafted DNS resource records that would cause a recursive
resolver or secondary server to crash or, possibly, disclose portions of
its memory. (CVE-2012-1667)

A flaw was found in the way BIND handled the updating of cached name server
(NS) resource records. A malicious owner of a DNS domain could use this
flaw to keep the domain resolvable by the BIND server even after the
delegation was removed from the parent DNS zone. With this update, BIND
limits the time-to-live of the replacement record to that of the
time-to-live of the record being replaced. (CVE-2012-1033)

Users of bind are advised to upgrade to these updated packages, which
correct these issues. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120716"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120717" severity="high">
    <xccdf:title>RHSA-2012:0717: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled zero length resource data records.
A malicious owner of a DNS domain could use this flaw to create
specially-crafted DNS resource records that would cause a recursive
resolver or secondary server to crash or, possibly, disclose portions of
its memory. (CVE-2012-1667)

A flaw was found in the way BIND handled the updating of cached name server
(NS) resource records. A malicious owner of a DNS domain could use this
flaw to keep the domain resolvable by the BIND server even after the
delegation was removed from the parent DNS zone. With this update, BIND
limits the time-to-live of the replacement record to that of the
time-to-live of the record being replaced. (CVE-2012-1033)

Users of bind97 are advised to upgrade to these updated packages, which
correct these issues. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0717</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1033</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120717"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120721" severity="high">
    <xccdf:title>RHSA-2012:0721: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the Xen hypervisor implementation as shipped with Red
Hat Enterprise Linux 5 did not properly restrict the syscall return
addresses in the sysret return path to canonical addresses. An unprivileged
user in a 64-bit para-virtualized guest, that is running on a 64-bit host
that has an Intel CPU, could use this flaw to crash the host or,
potentially, escalate their privileges, allowing them to execute arbitrary
code at the hypervisor level. (CVE-2012-0217, Important)

* It was found that guests could trigger a bug in earlier AMD CPUs, leading
to a CPU hard lockup, when running on the Xen hypervisor implementation. An
unprivileged user in a 64-bit para-virtualized guest could use this flaw to
crash the host. Warning: After installing this update, hosts that are using
an affected AMD CPU (refer to Red Hat Bugzilla bug #824966 for a list) will
fail to boot. In order to boot such hosts, the new kernel parameter,
allow_unsafe, can be used ("allow_unsafe=on"). This option should only be
used with hosts that are running trusted guests, as setting it to "on"
reintroduces the flaw (allowing guests to crash the host). (CVE-2012-2934,
Moderate)

Note: For Red Hat Enterprise Linux guests, only privileged guest users can
exploit the CVE-2012-0217 and CVE-2012-2934 issues.

Red Hat would like to thank the Xen project for reporting these issues.
Upstream acknowledges Rafal Wojtczuk as the original reporter of
CVE-2012-0217.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0217</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2934</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120721"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120729" severity="high">
    <xccdf:title>RHSA-2012:0729: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple flaws were discovered in the CORBA (Common Object Request Broker
Architecture) implementation in Java. A malicious Java application or
applet could use these flaws to bypass Java sandbox restrictions or modify
immutable object data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that the SynthLookAndFeel class from Swing did not
properly prevent access to certain UI elements from outside the current
application context. A malicious Java application or applet could use this
flaw to crash the Java Virtual Machine, or bypass Java sandbox
restrictions. (CVE-2012-1716)

Multiple flaws were discovered in the font manager's layout lookup
implementation. A specially-crafted font file could cause the Java Virtual
Machine to crash or, possibly, execute arbitrary code with the privileges
of the user running the virtual machine. (CVE-2012-1713)

Multiple flaws were found in the way the Java HotSpot Virtual Machine
verified the bytecode of the class file to be executed. A specially-crafted
Java application or applet could use these flaws to crash the Java Virtual
Machine, or bypass Java sandbox restrictions. (CVE-2012-1723,
CVE-2012-1725)

It was discovered that the Java XML parser did not properly handle certain
XML documents. An attacker able to make a Java application parse a
specially-crafted XML file could use this flaw to make the XML parser enter
an infinite loop. (CVE-2012-1724)

It was discovered that the Java security classes did not properly handle
Certificate Revocation Lists (CRL). CRL containing entries with duplicate
certificate serial numbers could have been ignored. (CVE-2012-1718)

It was discovered that various classes of the Java Runtime library could
create temporary files with insecure permissions. A local attacker could
use this flaw to gain access to the content of such temporary files.
(CVE-2012-1717)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.3. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1717</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1719</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1725</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120729"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120730" severity="high">
    <xccdf:title>RHSA-2012:0730: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple flaws were discovered in the CORBA (Common Object Request Broker
Architecture) implementation in Java. A malicious Java application or
applet could use these flaws to bypass Java sandbox restrictions or modify
immutable object data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that the SynthLookAndFeel class from Swing did not
properly prevent access to certain UI elements from outside the current
application context. A malicious Java application or applet could use this
flaw to crash the Java Virtual Machine, or bypass Java sandbox
restrictions. (CVE-2012-1716)

Multiple flaws were discovered in the font manager's layout lookup
implementation. A specially-crafted font file could cause the Java Virtual
Machine to crash or, possibly, execute arbitrary code with the privileges
of the user running the virtual machine. (CVE-2012-1713)

Multiple flaws were found in the way the Java HotSpot Virtual Machine
verified the bytecode of the class file to be executed. A specially-crafted
Java application or applet could use these flaws to crash the Java Virtual
Machine, or bypass Java sandbox restrictions. (CVE-2012-1723,
CVE-2012-1725)

It was discovered that the Java XML parser did not properly handle certain
XML documents. An attacker able to make a Java application parse a
specially-crafted XML file could use this flaw to make the XML parser enter
an infinite loop. (CVE-2012-1724)

It was discovered that the Java security classes did not properly handle
Certificate Revocation Lists (CRL). CRL containing entries with duplicate
certificate serial numbers could have been ignored. (CVE-2012-1718)

It was discovered that various classes of the Java Runtime library could
create temporary files with insecure permissions. A local attacker could
use this flaw to gain access to the content of such temporary files.
(CVE-2012-1717)

This erratum also upgrades the OpenJDK package to IcedTea6 1.10.8. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1717</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1719</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1725</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120730"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120731" severity="medium">
    <xccdf:title>RHSA-2012:0731: expat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Expat is a C library written by James Clark for parsing XML documents.

A denial of service flaw was found in the implementation of hash arrays in
Expat. An attacker could use this flaw to make an application using Expat
consume an excessive amount of CPU time by providing a specially-crafted
XML file that triggers multiple hash function collisions. To mitigate
this issue, randomization has been added to the hash function to reduce the
chance of an attacker successfully causing intentional collisions.
(CVE-2012-0876)

A memory leak flaw was found in Expat. If an XML file processed by an
application linked against Expat triggered a memory re-allocation failure,
Expat failed to free the previously allocated memory. This could cause the
application to exit unexpectedly or crash when all available memory is
exhausted. (CVE-2012-1148)

All Expat users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, applications using the Expat library must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1148</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120731"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120743" severity="high">
    <xccdf:title>RHSA-2012:0743: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A local, unprivileged user could use an integer overflow flaw in
drm_mode_dirtyfb_ioctl() to cause a denial of service or escalate their
privileges. (CVE-2012-0044, Important)

* A buffer overflow flaw was found in the macvtap device driver, used for
creating a bridged network between the guest and the host in KVM
(Kernel-based Virtual Machine) environments. A privileged guest user in a
KVM guest could use this flaw to crash the host. Note: This issue only
affected hosts that have the vhost_net module loaded with the
experimental_zcopytx module option enabled (it is not enabled by default),
and that also have macvtap configured for at least one guest.
(CVE-2012-2119, Important)

* When a set user ID (setuid) application is executed, certain personality
flags for controlling the application's behavior are cleared (that is, a
privileged application will not be affected by those flags). It was found
that those flags were not cleared if the application was made privileged
via file system capabilities. A local, unprivileged user could use this
flaw to change the behavior of such applications, allowing them to bypass
intended restrictions. Note that for default installations, no application
shipped by Red Hat for Red Hat Enterprise Linux is made privileged via file
system capabilities. (CVE-2012-2123, Important)

* It was found that the data_len parameter of the sock_alloc_send_pskb()
function in the Linux kernel's networking implementation was not validated
before use. A privileged guest user in a KVM guest could use this flaw to
crash the host or, possibly, escalate their privileges on the host.
(CVE-2012-2136, Important)

* A buffer overflow flaw was found in the setup_routing_entry() function in
the KVM subsystem of the Linux kernel in the way the Message Signaled
Interrupts (MSI) routing entry was handled. A local, unprivileged user
could use this flaw to cause a denial of service or, possibly, escalate
their privileges. (CVE-2012-2137, Important)

* A race condition was found in the Linux kernel's memory management
subsystem in the way pmd_none_or_clear_bad(), when called with mmap_sem in
read mode, and Transparent Huge Pages (THP) page faults interacted. A
privileged user in a KVM guest with the ballooning functionality enabled
could potentially use this flaw to crash the host. A local, unprivileged
user could use this flaw to crash the system. (CVE-2012-1179, Moderate)

* A flaw was found in the way device memory was handled during guest device
removal. Upon successful device removal, memory used by the device was not
properly unmapped from the corresponding IOMMU or properly released from
the kernel, leading to a memory leak. A malicious user on a KVM host who
has the ability to assign a device to a guest could use this flaw to crash
the host. (CVE-2012-2121, Moderate)

* A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372, Moderate)

* A race condition was found in the Linux kernel's memory management
subsystem in the way pmd_populate() and pte_offset_map_lock() interacted on
32-bit x86 systems with more than 4GB of RAM. A local, unprivileged user
could use this flaw to cause a denial of service. (CVE-2012-2373, Moderate)

Red Hat would like to thank Chen Haogang for reporting CVE-2012-0044.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0743</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2119</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2373</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120743"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120744" severity="medium">
    <xccdf:title>RHSA-2012:0744: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A denial of service flaw was found in the implementation of associative
arrays (dictionaries) in Python. An attacker able to supply a large number
of inputs to a Python application (such as HTTP POST request parameters
sent to a web application) that are used as keys when inserting data into
an array could trigger multiple hash function collisions, making array
operations take an excessive amount of CPU time. To mitigate this issue,
randomization has been added to the hash function to reduce the chance of
an attacker successfully causing intentional collisions. (CVE-2012-1150)

Note: The hash randomization is not enabled by default as it may break
applications that incorrectly depend on dictionary ordering. To enable the
protection, the new "PYTHONHASHSEED" environment variable or the Python
interpreter's "-R" command line option can be used. Refer to the python(1)
manual page for details.

The RHSA-2012:0731 expat erratum must be installed with this update, which
adds hash randomization to the Expat library used by the Python pyexpat
module.

A flaw was found in the way the Python SimpleXMLRPCServer module handled
clients disconnecting prematurely. A remote attacker could use this flaw to
cause excessive CPU consumption on a server using SimpleXMLRPCServer.
(CVE-2012-0845)

A flaw was found in the way the Python SimpleHTTPServer module generated
directory listings. An attacker able to upload a file with a
specially-crafted name to a server could possibly perform a cross-site
scripting (XSS) attack against victims visiting a listing page generated by
SimpleHTTPServer, for a directory containing the crafted file (if the
victims were using certain web browsers). (CVE-2011-4940)

A race condition was found in the way the Python distutils module set file
permissions during the creation of the .pypirc file. If a local user had
access to the home directory of another user who is running distutils, they
could use this flaw to gain access to that user's .pypirc file, which can
contain usernames and passwords for code repositories. (CVE-2011-4944)

Red Hat would like to thank oCERT for reporting CVE-2012-1150. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2012-1150.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1150</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120744"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120745" severity="medium">
    <xccdf:title>RHSA-2012:0745: python security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A denial of service flaw was found in the implementation of associative
arrays (dictionaries) in Python. An attacker able to supply a large number
of inputs to a Python application (such as HTTP POST request parameters
sent to a web application) that are used as keys when inserting data into
an array could trigger multiple hash function collisions, making array
operations take an excessive amount of CPU time. To mitigate this issue,
randomization has been added to the hash function to reduce the chance of
an attacker successfully causing intentional collisions. (CVE-2012-1150)

Note: The hash randomization is not enabled by default as it may break
applications that incorrectly depend on dictionary ordering. To enable the
protection, the new "PYTHONHASHSEED" environment variable or the Python
interpreter's "-R" command line option can be used. Refer to the python(1)
manual page for details.

The RHSA-2012:0731 expat erratum must be installed with this update, which
adds hash randomization to the Expat library used by the Python pyexpat
module.

A flaw was found in the way the Python SimpleHTTPServer module generated
directory listings. An attacker able to upload a file with a
specially-crafted name to a server could possibly perform a cross-site
scripting (XSS) attack against victims visiting a listing page generated by
SimpleHTTPServer, for a directory containing the crafted file (if the
victims were using certain web browsers). (CVE-2011-4940)

A race condition was found in the way the Python distutils module set file
permissions during the creation of the .pypirc file. If a local user had
access to the home directory of another user who is running distutils, they
could use this flaw to gain access to that user's .pypirc file, which can
contain usernames and passwords for code repositories. (CVE-2011-4944)

Red Hat would like to thank oCERT for reporting CVE-2012-1150. oCERT
acknowledges Julian Wälde and Alexander Klink as the original reporters of
CVE-2012-1150.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0745</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1150</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120745"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120748" severity="low">
    <xccdf:title>RHSA-2012:0748: libvirt security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

Bus and device IDs were ignored when attempting to attach multiple USB
devices with identical vendor or product IDs to a guest. This could result
in the wrong device being attached to a guest, giving that guest root
access to the device. (CVE-2012-2693)

These updated libvirt packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 6.3 Technical Notes for
information on the most significant of these changes.

All users of libvirt are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120748"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120774" severity="low">
    <xccdf:title>RHSA-2012:0774: libguestfs security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libguestfs is a library for accessing and modifying guest disk images.

It was found that editing files with virt-edit left said files in a
world-readable state (and did not preserve the file owner or
Security-Enhanced Linux context). If an administrator on the host used
virt-edit to edit a file inside a guest, the file would be left with
world-readable permissions. This could lead to unprivileged guest users
accessing files they would otherwise be unable to. (CVE-2012-2690)

These updated libguestfs packages include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.3 Technical
Notes for information on the most significant of these changes.

Users of libguestfs are advised to upgrade to these updated packages, which
fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2690</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120774"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120796" severity="medium">
    <xccdf:title>RHSA-2012:0796: rsyslog security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rsyslog packages provide an enhanced, multi-threaded syslog daemon.

A numeric truncation error, leading to a heap-based buffer overflow, was
found in the way the rsyslog imfile module processed text files containing
long lines. An attacker could use this flaw to crash the rsyslogd daemon
or, possibly, execute arbitrary code with the privileges of rsyslogd, if
they are able to cause a long line to be written to a log file that
rsyslogd monitors with imfile. The imfile module is not enabled by default.
(CVE-2011-4623)

Bug fixes:

* Several variables were incorrectly deinitialized with Transport Layer
Security (TLS) transport and keys in PKCS#8 format. The rsyslogd daemon
aborted with a segmentation fault when keys in this format were provided.
Now, the variables are correctly deinitialized. (BZ#727380)

* Previously, the imgssapi plug-in initialization was incomplete. As a
result, the rsyslogd daemon aborted when configured to provide a GSSAPI
listener. Now, the plug-in is correctly initialized. (BZ#756664)

* The fully qualified domain name (FQDN) for the localhost used in messages
was the first alias found. This did not always produce the expected result
on multihomed hosts. With this update, the algorithm uses the alias that
corresponds to the hostname. (BZ#767527)

* The gtls module leaked a file descriptor every time it was loaded due to
an error in the GnuTLS library. No new files or network connections could
be opened when the limit for the file descriptor count was reached. This
update modifies the gtls module so that it is not unloaded during the
process lifetime. (BZ#803550)

* rsyslog could not override the hostname to set an alternative hostname
for locally generated messages. Now, the local hostname can be overridden.
(BZ#805424)

* The rsyslogd init script did not pass the lock file path to the 'status'
action. As a result, the lock file was ignored and a wrong exit code was
returned. This update modifies the init script to pass the lock file to
the 'status' action. Now, the correct exit code is returned. (BZ#807608)

* Data could be incorrectly deinitialized when rsyslogd was supplied with
malformed spool files. The rsyslogd daemon could be aborted with a
segmentation fault. This update modifies the underlying code to correctly
deinitialize the data. (BZ#813079)

* Previously, deinitialization of non-existent data could, in certain error
cases, occur. As a result, rsyslogd could abort with a segmentation fault
when rsyslog was configured to use a disk assisted queue without specifying
a spool file. With this update, the error cases are handled gracefully.
(BZ#813084)

* The manual page wrongly stated that the '-d' option to turn on debugging
caused the daemon to run in the foreground, which was misleading as the
current behavior is to run in the background. Now, the manual page reflects
the correct behavior. (BZ#820311)

* rsyslog attempted to write debugging messages to standard output even
when run in the background. This resulted in the debugging information
being written to some other output. This was corrected and the debug
messages are no longer written to standard output when run in the
background. (BZ#820996)

* The string buffer to hold the distinguished name (DN) of a certificate
was too small. DNs with more than 128 characters were not displayed. This
update enlarges the buffer to process longer DNs. (BZ#822118)

Enhancements:

* Support for rate limiting and multi-line message capability. Now,
rsyslogd can limit the number of messages it accepts through a UNIX socket.
(BZ#672182)

* The addition of the "/etc/rsyslog.d/" configuration directory to supply
syslog configuration files. (BZ#740420)

All users of rsyslog are advised to upgrade to these updated packages,
which upgrade rsyslog to version 5.8.10 and correct these issues and add
these enhancements. After installing this update, the rsyslog daemon will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0796</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4623</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120796"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120810" severity="low">
    <xccdf:title>RHSA-2012:0810: busybox security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>BusyBox provides a single binary that includes versions of a large number
of system commands, including a shell. This can be very useful for
recovering from certain types of system failures, particularly those
involving broken shared libraries.

A buffer underflow flaw was found in the way the uncompress utility of
BusyBox expanded certain archive files compressed using Lempel-Ziv
compression. If a user were tricked into expanding a specially-crafted
archive file with uncompress, it could cause BusyBox to crash or,
potentially, execute arbitrary code with the privileges of the user
running BusyBox. (CVE-2006-1168)

The BusyBox DHCP client, udhcpc, did not sufficiently sanitize certain
options provided in DHCP server replies, such as the client hostname. A
malicious DHCP server could send such an option with a specially-crafted
value to a DHCP client. If this option's value was saved on the client
system, and then later insecurely evaluated by a process that assumes the
option is trusted, it could lead to arbitrary code execution with the
privileges of that process. Note: udhcpc is not used on Red Hat Enterprise
Linux by default, and no DHCP client script is provided with the busybox
packages. (CVE-2011-2716)

This update also fixes the following bugs:

* Prior to this update, the "findfs" command did not recognize Btrfs
partitions. As a consequence, an error message could occur when dumping a
core file. This update adds support for recognizing such partitions so
the problem no longer occurs. (BZ#751927)

* If the "grep" command was used with the "-F" and "-i" options at the
same time, the "-i" option was ignored. As a consequence, the "grep -iF"
command incorrectly performed a case-sensitive search instead of an
insensitive search. A patch has been applied to ensure that the combination
of the "-F" and "-i" options works as expected. (BZ#752134)

* Prior to this update, the msh shell did not support the "set -o pipefail"
command. This update adds support for this command. (BZ#782018)

* Previously, the msh shell could terminate unexpectedly with a
segmentation fault when attempting to execute an empty command as a result
of variable substitution (for example msh -c '$nonexistent_variable').
With this update, msh has been modified to correctly interpret such
commands and no longer crashes in this scenario. (BZ#809092)

* Previously, the msh shell incorrectly executed empty loops. As a
consequence, msh never exited such a loop even if the loop condition was
false, which could cause scripts using the loop to become unresponsive.
With this update, msh has been modified to execute and exit empty loops
correctly, so that hangs no longer occur. (BZ#752132)

All users of busybox are advised to upgrade to these updated packages,
which contain backported patches to fix these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-1168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2716</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120810"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120811" severity="low">
    <xccdf:title>RHSA-2012:0811: php-pecl-apc security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The php-pecl-apc packages contain APC (Alternative PHP Cache), the
framework for caching and optimization of intermediate PHP code.

A cross-site scripting (XSS) flaw was found in the "apc.php" script, which
provides a detailed analysis of the internal workings of APC and is shipped
as part of the APC extension documentation. A remote attacker could
possibly use this flaw to conduct a cross-site scripting attack.
(CVE-2010-3294)

Note: The administrative script is not deployed upon package installation.
It must manually be copied to the web root (the default is
"/var/www/html/", for example).

In addition, the php-pecl-apc packages have been upgraded to upstream
version 3.1.9, which provides a number of bug fixes and enhancements over
the previous version. (BZ#662655)

All users of php-pecl-apc are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. If the "apc.php" script
was previously deployed in the web root, it must manually be re-deployed to
replace the vulnerable version to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3294</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120811"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120813" severity="low">
    <xccdf:title>RHSA-2012:0813: 389-ds-base security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

A flaw was found in the way the 389 Directory Server daemon (ns-slapd)
handled access control instructions (ACIs) using certificate groups. If an
LDAP user that had a certificate group defined attempted to bind to the
directory server, it would cause ns-slapd to enter an infinite loop and
consume an excessive amount of CPU time. (CVE-2012-0833)

Red Hat would like to thank Graham Leggett for reporting this issue.

These updated 389-ds-base packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.3 Technical
Notes for information on the most significant of these changes.

Users are advised to upgrade to these updated 389-ds-base packages, which
resolve these issues and add these enhancements. After installing this
update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0833</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120813"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120841" severity="low">
    <xccdf:title>RHSA-2012:0841: abrt, libreport, btparser, and python-meh security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. libreport provides an API for reporting different problems
in applications to different bug targets, such as Bugzilla, FTP, and Trac.

The btparser utility is a backtrace parser and analyzer library, which
works with backtraces produced by the GNU Project Debugger. It can parse a
text file with a backtrace to a tree of C structures, allowing to analyze
the threads and frames of the backtrace and process them.

The python-meh package provides a python library for handling exceptions.

If the C handler plug-in in ABRT was enabled (the abrt-addon-ccpp package
installed and the abrt-ccpp service running), and the sysctl
fs.suid_dumpable option was set to "2" (it is "0" by default), core dumps
of set user ID (setuid) programs were created with insecure group ID
permissions. This could allow local, unprivileged users to obtain sensitive
information from the core dump files of setuid processes they would
otherwise not be able to access. (CVE-2012-1106)

ABRT did not allow users to easily search the collected crash information
for sensitive data prior to submitting it. This could lead to users
unintentionally exposing sensitive information via the submitted crash
reports. This update adds functionality to search across all the collected
data. Note that this fix does not apply to the default configuration, where
reports are sent to Red Hat Customer Support. It only takes effect for
users sending information to Red Hat Bugzilla. (CVE-2011-4088)

Red Hat would like to thank Jan Iven for reporting CVE-2011-4088.

These updated packages include numerous bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.3 Technical Notes for information on the
most significant of these changes.

All users of abrt, libreport, btparser, and python-meh are advised to
upgrade to these updated packages, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0841</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1106</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120841"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120862" severity="medium">
    <xccdf:title>RHSA-2012:0862: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Linux kernel's Event Poll (epoll)
subsystem handled large, nested epoll structures. A local, unprivileged
user could use this flaw to cause a denial of service. (CVE-2011-1083,
Moderate)

* A malicious Network File System version 4 (NFSv4) server could return a
crafted reply to a GETACL request, causing a denial of service on the
client. (CVE-2011-4131, Moderate)

Red Hat would like to thank Nelson Elhage for reporting CVE-2011-1083, and
Andy Adamson for reporting CVE-2011-4131.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.3 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.3 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0862</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4131</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120862"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120874" severity="low">
    <xccdf:title>RHSA-2012:0874: mysql security and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

A flaw was found in the way MySQL processed HANDLER READ NEXT statements
after deleting a record. A remote, authenticated attacker could use this
flaw to provide such requests, causing mysqld to crash. This issue only
caused a temporary denial of service, as mysqld was automatically restarted
after the crash. (CVE-2012-2102)

This update also adds the following enhancement:

* The InnoDB storage engine is built-in for all architectures. This update
adds InnoDB Plugin, the InnoDB storage engine as a plug-in for the 32-bit
x86, AMD64, and Intel 64 architectures. The plug-in offers additional
features and better performance than when using the built-in InnoDB storage
engine. Refer to the MySQL documentation, linked to in the References
section, for information about enabling the plug-in. (BZ#740224)

All MySQL users should upgrade to these updated packages, which add this
enhancement and contain a backported patch to correct this issue. After
installing this update, the MySQL server daemon (mysqld) will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0874</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120874"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120876" severity="medium">
    <xccdf:title>RHSA-2012:0876: net-snmp security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

An array index error, leading to an out-of-bounds buffer read flaw, was
found in the way the net-snmp agent looked up entries in the extension
table. A remote attacker with read privileges to a Management Information
Base (MIB) subtree handled by the "extend" directive (in
"/etc/snmp/snmpd.conf") could use this flaw to crash snmpd via a crafted
SNMP GET request. (CVE-2012-2141)

These updated net-snmp packages also include numerous bug fixes. Space
precludes documenting all of these changes in this advisory. Users are
directed to the Red Hat Enterprise Linux 6.3 Technical Notes for
information on the most significant of these changes.

All users of net-snmp are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues. After installing
the update, the snmpd and snmptrapd daemons will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2141</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120876"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120880" severity="medium">
    <xccdf:title>RHSA-2012:0880: qt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3922)

A flaw was found in the way Qt handled X.509 certificates with IP address
wildcards. An attacker able to obtain a certificate with a Common Name
containing an IP wildcard could possibly use this flaw to impersonate an
SSL server to client applications that are using Qt. This update also
introduces more strict handling for hostname wildcard certificates by
disallowing the wildcard character to match more than one hostname
component. (CVE-2010-5076)

This update also fixes the following bugs:

* The Phonon API allowed premature freeing of the media object.
Consequently, GStreamer could terminate unexpectedly as it failed to access
the released media object. This update modifies the underlying Phonon API
code and the problem no longer occurs. (BZ#694684)

* Previously, Qt could output the "Unrecognized OpenGL version" error and
fall back to OpenGL-version-1 compatibility mode. This happened because Qt
failed to recognize the version of OpenGL installed on the system if the
system was using a version of OpenGL released later than the Qt version in
use. This update adds the code for recognition of OpenGL versions to Qt and
if the OpenGL version is unknown, Qt assumes that the last-known version of
OpenGL is available. (BZ#757793)

* Previously Qt included a compiled-in list of trusted CA (Certificate
Authority) certificates, that could have been used if Qt failed to open a
system's ca-bundle.crt file. With this update, Qt no longer includes
compiled-in CA certificates and only uses the system bundle. (BZ#734444)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0880</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3922</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120880"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120884" severity="low">
    <xccdf:title>RHSA-2012:0884: openssh security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's Secure Shell (SSH) protocol implementation. These
packages include the core files necessary for the OpenSSH client and
server.

A denial of service flaw was found in the OpenSSH GSSAPI authentication
implementation. A remote, authenticated user could use this flaw to make
the OpenSSH server daemon (sshd) use an excessive amount of memory, leading
to a denial of service. GSSAPI authentication is enabled by default
("GSSAPIAuthentication yes" in "/etc/ssh/sshd_config"). (CVE-2011-5000)

These updated openssh packages also provide fixes for the following bugs:

* SSH X11 forwarding failed if IPv6 was enabled and the parameter
X11UseLocalhost was set to "no". Consequently, users could not set X
forwarding. This update fixes sshd and ssh to correctly bind the port for
the IPv6 protocol. As a result, X11 forwarding now works as expected with
IPv6. (BZ#732955)

* The sshd daemon was killed by the OOM killer when running a stress test.
Consequently, a user could not log in. With this update, the sshd daemon
sets its oom_adj value to -17. As a result, sshd is not chosen by OOM
killer and users are able to log in to solve problems with memory.
(BZ#744236)

* If the SSH server is configured with a banner that contains a backslash
character, then the client will escape it with another "\" character, so it
prints double backslashes. An upstream patch has been applied to correct
the problem and the SSH banner is now correctly displayed. (BZ#809619)

In addition, these updated openssh packages provide the following
enhancements:

* Previously, SSH allowed multiple ways of authentication of which only one
was required for a successful login. SSH can now be set up to require
multiple ways of authentication. For example, logging in to an SSH-enabled
machine requires both a passphrase and a public key to be entered. The
RequiredAuthentications1 and RequiredAuthentications2 options can be
configured in the /etc/ssh/sshd_config file to specify authentications that
are required for a successful login. For example, to set key and password
authentication for SSH version 2, type:

echo "RequiredAuthentications2 publickey,password" &gt;&gt; /etc/ssh/sshd_config

For more information on the aforementioned /etc/ssh/sshd_config options,
refer to the sshd_config man page. (BZ#657378)

* Previously, OpenSSH could use the Advanced Encryption Standard New
Instructions (AES-NI) instruction set only with the AES Cipher-block
chaining (CBC) cipher. This update adds support for Counter (CTR) mode
encryption in OpenSSH so the AES-NI instruction set can now be used
efficiently also with the AES CTR cipher. (BZ#756929)

* Prior to this update, an unprivileged slave sshd process was run as
the sshd_t context during privilege separation (privsep). sshd_t is the
SELinux context used for running the sshd daemon. Given that the
unprivileged slave process is run under the user's UID, it is fitting to
run this process under the user's SELinux context instead of the privileged
sshd_t context. With this update, the unprivileged slave process is now run
as the user's context instead of the sshd_t context in accordance with the
principle of privilege separation. The unprivileged process, which might be
potentially more sensitive to security threats, is now run under the user's
SELinux context. (BZ#798241)

Users are advised to upgrade to these updated openssh packages, which
contain backported patches to resolve these issues and add these
enhancements. After installing this update, the OpenSSH server daemon
(sshd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120884"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120899" severity="low">
    <xccdf:title>RHSA-2012:0899: openldap security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A denial of service flaw was found in the way the OpenLDAP server daemon
(slapd) processed certain search queries requesting only attributes and no
values. In certain configurations, a remote attacker could issue a
specially-crafted LDAP search query that, when processed by slapd, would
cause slapd to crash due to an assertion failure. (CVE-2012-1164)

These updated openldap packages include numerous bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.3 Technical Notes for information on the
most significant of these changes.

Users of OpenLDAP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0899</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1164</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120899"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120902" severity="low">
    <xccdf:title>RHSA-2012:0902: cifs-utils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cifs-utils package contains tools for mounting and managing shares on
Linux using the SMB/CIFS protocol. The CIFS shares can be used as standard
Linux file systems.

A file existence disclosure flaw was found in mount.cifs. If the tool was
installed with the setuid bit set, a local attacker could use this flaw to
determine the existence of files or directories in directories not
accessible to the attacker. (CVE-2012-1586)

Note: mount.cifs from the cifs-utils package distributed by Red Hat does
not have the setuid bit set. We recommend that administrators do not
manually set the setuid bit for mount.cifs.

This update also fixes the following bugs:

* The cifs.mount(8) manual page was previously missing documentation for
several mount options. With this update, the missing entries have been
added to the manual page. (BZ#769923)

* Previously, the mount.cifs utility did not properly update the
"/etc/mtab" system information file when remounting an existing CIFS
mount. Consequently, mount.cifs created a duplicate entry of the existing
mount entry. This update adds the del_mtab() function to cifs.mount, which
ensures that the old mount entry is removed from "/etc/mtab" before adding
the updated mount entry. (BZ#770004)

* The mount.cifs utility did not properly convert user and group names to
numeric UIDs and GIDs. Therefore, when the "uid", "gid" or "cruid" mount
options were specified with user or group names, CIFS shares were mounted
with default values. This caused shares to be inaccessible to the intended
users because UID and GID is set to "0" by default. With this update, user
and group names are properly converted so that CIFS shares are now mounted
with specified user and group ownership as expected. (BZ#796463)

* The cifs.upcall utility did not respect the "domain_realm" section in
the "krb5.conf" file and worked only with the default domain.
Consequently, an attempt to mount a CIFS share from a different than the
default domain failed with the following error message:

    mount error(126): Required key not available

This update modifies the underlying code so that cifs.upcall handles
multiple Kerberos domains correctly and CIFS shares can now be mounted as
expected in a multi-domain environment. (BZ#805490)

In addition, this update adds the following enhancements:

* The cifs.upcall utility previously always used the "/etc/krb5.conf" file
regardless of whether the user had specified a custom Kerberos
configuration file. This update adds the "--krb5conf" option to
cifs.upcall allowing the administrator to specify an alternate
krb5.conf file. For more information on this option, refer to the
cifs.upcall(8) manual page. (BZ#748756)

* The cifs.upcall utility did not optimally determine the correct service
principal name (SPN) used for Kerberos authentication, which occasionally
caused krb5 authentication to fail when mounting a server's unqualified
domain name. This update improves cifs.upcall so that the method used to
determine the SPN is now more versatile. (BZ#748757)

* This update adds the "backupuid" and "backupgid" mount options to the
mount.cifs utility. When specified, these options grant a user or a group
the right to access files with the backup intent. For more information on
these options, refer to the mount.cifs(8) manual page. (BZ#806337)

All users of cifs-utils are advised to upgrade to this updated package,
which contains backported patches to fix these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1586</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120902"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120939" severity="low">
    <xccdf:title>RHSA-2012:0939: xorg-x11-server security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way the X.Org server handled lock files. A local
user with access to the system console could use this flaw to determine the
existence of a file in a directory not accessible to the user, via a
symbolic link attack. (CVE-2011-4028)

A race condition was found in the way the X.Org server managed temporary
lock files. A local attacker could use this flaw to perform a symbolic link
attack, allowing them to make an arbitrary file world readable, leading to
the disclosure of sensitive information. (CVE-2011-4029)

Red Hat would like to thank the researcher with the nickname vladz for
reporting these issues.

This update also fixes the following bugs:

* Prior to this update, the KDE Display Manager (KDM) could pass invalid
24bpp pixmap formats to the X server. As a consequence, the X server could
unexpectedly abort. This update modifies the underlying code to pass the
correct formats. (BZ#651934, BZ#722860)

* Prior to this update, absolute input devices, like the stylus of a
graphic tablet, could become unresponsive in the right-most or bottom-most
screen if the X server was configured as a multi-screen setup through
multiple "Device" sections in the xorg.conf file. This update changes the
screen crossing behavior so that absolute devices are always mapped across
all screens. (BZ#732467)

* Prior to this update, the misleading message "Session active, not
inhibited, screen idle. If you see this test, your display server is broken
and you should notify your distributor." could be displayed after resuming
the system or re-enabling the display, and included a URL to an external
web page. This update removes this message. (BZ#748704)

* Prior to this update, the erroneous input handling code of the Xephyr
server disabled screens on a screen crossing event. The focus was only on
the screen where the mouse was located and only this screen was updated
when the Xephyr nested X server was configured in a multi-screen setup.
This update removes this code and Xephyr now correctly updates screens in
multi-screen setups. (BZ#757792)

* Prior to this update, raw events did not contain relative axis values. As
a consequence, clients which relied on relative values for functioning did
not behave as expected. This update sets the values to the original driver
values instead of the already transformed values. Now, raw events contain
relative axis values as expected. (BZ#805377)

All users of xorg-x11-server are advised to upgrade to these updated
packages, which correct these issues. All running X.Org server instances
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0939</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4028</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120939"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120958" severity="low">
    <xccdf:title>RHSA-2012:0958: sos security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sos package contains a set of tools that gather information from system
hardware, logs and configuration files. The information can then be used
for diagnostic purposes and debugging.

The sosreport utility collected the Kickstart configuration file
("/root/anaconda-ks.cfg"), but did not remove the root user's password from
it before adding the file to the resulting archive of debugging
information. An attacker able to access the archive could possibly use this
flaw to obtain the root user's password. "/root/anaconda-ks.cfg" usually
only contains a hash of the password, not the plain text password.
(CVE-2012-2664)

Note: This issue affected all installations, not only systems installed via
Kickstart. A "/root/anaconda-ks.cfg" file is created by all installation
types.

This updated sos package also includes numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 6.3 Technical Notes for
information on the most significant of these changes.

All users of sos are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2664</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120958"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120987" severity="low">
    <xccdf:title>RHSA-2012:0987: sblim-cim-client2 security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The SBLIM (Standards-Based Linux Instrumentation for Manageability) CIM
(Common Information Model) Client is a class library for Java applications
that provides access to CIM servers using the CIM Operations over HTTP
protocol defined by the DMTF (Distributed Management Task Force) standards.

It was found that the Java HashMap implementation was susceptible to
predictable hash collisions. SBLIM uses HashMap when parsing XML inputs. A
specially-crafted CIM-XML message from a WBEM (Web-Based Enterprise
Management) server could cause a SBLIM client to use an excessive amount of
CPU. Randomization has been added to help avoid collisions. (CVE-2012-2328)

All users of sblim-cim-client2 are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0987</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2328</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120987"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20120997" severity="medium">
    <xccdf:title>RHSA-2012:0997: 389-ds-base security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

A flaw was found in the way 389 Directory Server handled password changes.
If an LDAP user has changed their password, and the directory server has
not been restarted since that change, an attacker able to bind to the
directory server could obtain the plain text version of that user's
password via the "unhashed#user#password" attribute. (CVE-2012-2678)

It was found that when the password for an LDAP user was changed, and audit
logging was enabled (it is disabled by default), the new password was
written to the audit log in plain text form. This update introduces a new
configuration parameter, "nsslapd-auditlog-logging-hide-unhashed-pw", which
when set to "on" (the default option), prevents 389 Directory Server from
writing plain text passwords to the audit log. This option can be
configured in "/etc/dirsrv/slapd-[ID]/dse.ldif". (CVE-2012-2746)

All users of 389-ds-base are advised to upgrade to these updated packages,
which resolve these issues. After installing this update, the 389 server
service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:0997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2746</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20120997"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121009" severity="high">
    <xccdf:title>RHSA-2012:1009: java-1.7.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple flaws were discovered in the CORBA (Common Object Request Broker
Architecture) implementation in Java. A malicious Java application or
applet could use these flaws to bypass Java sandbox restrictions or modify
immutable object data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that the SynthLookAndFeel class from Swing did not
properly prevent access to certain UI elements from outside the current
application context. A malicious Java application or applet could use this
flaw to crash the Java Virtual Machine, or bypass Java sandbox
restrictions. (CVE-2012-1716)

Multiple flaws were discovered in the font manager's layout lookup
implementation. A specially-crafted font file could cause the Java Virtual
Machine to crash or, possibly, execute arbitrary code with the privileges
of the user running the virtual machine. (CVE-2012-1713)

Multiple flaws were found in the way the Java HotSpot Virtual Machine
verified the bytecode of the class file to be executed. A specially-crafted
Java application or applet could use these flaws to crash the Java Virtual
Machine, or bypass Java sandbox restrictions. (CVE-2012-1723,
CVE-2012-1725)

It was discovered that java.lang.invoke.MethodHandles.Lookup did not
properly honor access modes. An untrusted Java application or applet could
use this flaw to bypass Java sandbox restrictions. (CVE-2012-1726)

It was discovered that the Java XML parser did not properly handle certain
XML documents. An attacker able to make a Java application parse a
specially-crafted XML file could use this flaw to make the XML parser enter
an infinite loop. (CVE-2012-1724)

It was discovered that the Java security classes did not properly handle
Certificate Revocation Lists (CRL). CRL containing entries with duplicate
certificate serial numbers could have been ignored. (CVE-2012-1718)

It was discovered that various classes of the Java Runtime library could
create temporary files with insecure permissions. A local attacker could
use this flaw to gain access to the content of such temporary files.
(CVE-2012-1717)

This update also fixes the following bug:

* Attempting to compile a SystemTap script using the jstack tapset could
have failed with an error similar to the following:

error: the frame size of 272 bytes is larger than 256 bytes

This update corrects the jstack tapset and resolves this issue. (BZ#833035)

This erratum also upgrades the OpenJDK package to IcedTea7 2.2.1. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1717</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1719</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1723</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1726</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121009"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121036" severity="medium">
    <xccdf:title>RHSA-2012:1036: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A flaw was found in the way the crypt() password hashing function from the
optional PostgreSQL pgcrypto contrib module performed password
transformation when used with the DES algorithm. If the password string to
be hashed contained the 0x80 byte value, the remainder of the string was
ignored when calculating the hash, significantly reducing the password
strength. This made brute-force guessing more efficient as the whole
password was not required to gain access to protected resources.
(CVE-2012-2143)

Note: With this update, the rest of the string is properly included in the
DES hash; therefore, any previously stored password values that are
affected by this issue will no longer match. In such cases, it will be
necessary for those stored password hashes to be updated.

Upstream acknowledges Rubin Xu and Joseph Bonneau as the original reporters
of this issue.

All PostgreSQL users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1036</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2143</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121036"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121037" severity="medium">
    <xccdf:title>RHSA-2012:1037: postgresql and postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A flaw was found in the way the crypt() password hashing function from the
optional PostgreSQL pgcrypto contrib module performed password
transformation when used with the DES algorithm. If the password string to
be hashed contained the 0x80 byte value, the remainder of the string was
ignored when calculating the hash, significantly reducing the password
strength. This made brute-force guessing more efficient as the whole
password was not required to gain access to protected resources.
(CVE-2012-2143)

Note: With this update, the rest of the string is properly included in the
DES hash; therefore, any previously stored password values that are
affected by this issue will no longer match. In such cases, it will be
necessary for those stored password hashes to be updated.

A denial of service flaw was found in the way the PostgreSQL server
performed a user privileges check when applying SECURITY DEFINER or SET
attributes to a procedural language's (such as PL/Perl or PL/Python) call
handler function. A non-superuser database owner could use this flaw to
cause the PostgreSQL server to crash due to infinite recursion.
(CVE-2012-2655)

Upstream acknowledges Rubin Xu and Joseph Bonneau as the original reporters
of the CVE-2012-2143 issue.

These updated packages upgrade PostgreSQL to version 8.4.12, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1037</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2655</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121037"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121043" severity="high">
    <xccdf:title>RHSA-2012:1043: libwpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libwpd is a library for reading and converting Corel WordPerfect Office
documents.

A buffer overflow flaw was found in the way libwpd processed certain
Corel WordPerfect Office documents (.wpd files). An attacker could provide
a specially-crafted .wpd file that, when opened in an application linked
against libwpd, such as OpenOffice.org, would cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2012-2149)

All libwpd users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
that are linked against libwpd must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1043</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2149</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121043"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121045" severity="medium">
    <xccdf:title>RHSA-2012:1045: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was discovered that the PHP XSL extension did not restrict the file
writing capability of libxslt. A remote attacker could use this flaw to
create or overwrite an arbitrary file that is writable by the user running
PHP, if a PHP script processed untrusted eXtensible Style Sheet Language
Transformations (XSLT) content. (CVE-2012-0057)

Note: This update disables file writing by default. A new PHP configuration
directive, "xsl.security_prefs", can be used to enable file writing in
XSLT.

A flaw was found in the way PHP validated file names in file upload
requests. A remote attacker could possibly use this flaw to bypass the
sanitization of the uploaded file names, and cause a PHP script to store
the uploaded file in an unexpected directory, by using a directory
traversal attack. (CVE-2012-1172)

It was discovered that the fix for CVE-2012-1823, released via
RHSA-2012:0546, did not properly filter all php-cgi command line arguments.
A specially-crafted request to a PHP script could cause the PHP interpreter
to output usage information that triggers an Internal Server Error.
(CVE-2012-2336)

A memory leak flaw was found in the PHP strtotime() function call. A remote
attacker could possibly use this flaw to cause excessive memory consumption
by triggering many strtotime() function calls. (CVE-2012-0789)

It was found that PHP did not check the zend_strndup() function's return
value in certain cases. A remote attacker could possibly use this flaw to
crash a PHP application. (CVE-2011-4153)

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2336</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121045"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121046" severity="medium">
    <xccdf:title>RHSA-2012:1046: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was discovered that the PHP XSL extension did not restrict the file
writing capability of libxslt. A remote attacker could use this flaw to
create or overwrite an arbitrary file that is writable by the user running
PHP, if a PHP script processed untrusted eXtensible Style Sheet Language
Transformations (XSLT) content. (CVE-2012-0057)

Note: This update disables file writing by default. A new PHP configuration
directive, "xsl.security_prefs", can be used to enable file writing in
XSLT.

A flaw was found in the way PHP validated file names in file upload
requests. A remote attacker could possibly use this flaw to bypass the
sanitization of the uploaded file names, and cause a PHP script to store
the uploaded file in an unexpected directory, by using a directory
traversal attack. (CVE-2012-1172)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way the PHP phar extension processed certain fields of
tar archive files. A remote attacker could provide a specially-crafted tar
archive file that, when processed by a PHP application using the phar
extension, could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running PHP. (CVE-2012-2386)

A format string flaw was found in the way the PHP phar extension processed
certain PHAR files. A remote attacker could provide a specially-crafted
PHAR file, which once processed in a PHP application using the phar
extension, could lead to information disclosure and possibly arbitrary code
execution via a crafted phar:// URI. (CVE-2010-2950)

A flaw was found in the DES algorithm implementation in the crypt()
password hashing function in PHP. If the password string to be hashed
contained certain characters, the remainder of the string was ignored when
calculating the hash, significantly reducing the password strength.
(CVE-2012-2143)

Note: With this update, passwords are no longer truncated when performing
DES hashing. Therefore, new hashes of the affected passwords will not match
stored hashes generated using vulnerable PHP versions, and will need to be
updated.

It was discovered that the fix for CVE-2012-1823, released via
RHSA-2012:0546, did not properly filter all php-cgi command line arguments.
A specially-crafted request to a PHP script could cause the PHP interpreter
to execute the script in a loop, or output usage information that triggers
an Internal Server Error. (CVE-2012-2336)

A memory leak flaw was found in the PHP strtotime() function call. A remote
attacker could possibly use this flaw to cause excessive memory consumption
by triggering many strtotime() function calls. (CVE-2012-0789)

A NULL pointer dereference flaw was found in the PHP tidy_diagnose()
function. A remote attacker could use specially-crafted input to crash an
application that uses tidy::diagnose. (CVE-2012-0781)

It was found that PHP did not check the zend_strndup() function's return
value in certain cases. A remote attacker could possibly use this flaw to
crash a PHP application. (CVE-2011-4153)

Upstream acknowledges Rubin Xu and Joseph Bonneau as the original reporters
of CVE-2012-2143.

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1046</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2950</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0781</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2386</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121046"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121047" severity="medium">
    <xccdf:title>RHSA-2012:1047: php53 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was discovered that the PHP XSL extension did not restrict the file
writing capability of libxslt. A remote attacker could use this flaw to
create or overwrite an arbitrary file that is writable by the user running
PHP, if a PHP script processed untrusted eXtensible Style Sheet Language
Transformations (XSLT) content. (CVE-2012-0057)

Note: This update disables file writing by default. A new PHP configuration
directive, "xsl.security_prefs", can be used to enable file writing in
XSLT.

A flaw was found in the way PHP validated file names in file upload
requests. A remote attacker could possibly use this flaw to bypass the
sanitization of the uploaded file names, and cause a PHP script to store
the uploaded file in an unexpected directory, by using a directory
traversal attack. (CVE-2012-1172)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way the PHP phar extension processed certain fields of
tar archive files. A remote attacker could provide a specially-crafted tar
archive file that, when processed by a PHP application using the phar
extension, could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running PHP. (CVE-2012-2386)

A format string flaw was found in the way the PHP phar extension processed
certain PHAR files. A remote attacker could provide a specially-crafted
PHAR file, which once processed in a PHP application using the phar
extension, could lead to information disclosure and possibly arbitrary code
execution via a crafted phar:// URI. (CVE-2010-2950)

A flaw was found in the DES algorithm implementation in the crypt()
password hashing function in PHP. If the password string to be hashed
contained certain characters, the remainder of the string was ignored when
calculating the hash, significantly reducing the password strength.
(CVE-2012-2143)

Note: With this update, passwords are no longer truncated when performing
DES hashing. Therefore, new hashes of the affected passwords will not match
stored hashes generated using vulnerable PHP versions, and will need to be
updated.

It was discovered that the fix for CVE-2012-1823, released via
RHSA-2012:0547, did not properly filter all php-cgi command line arguments.
A specially-crafted request to a PHP script could cause the PHP interpreter
to execute the script in a loop, or output usage information that triggers
an Internal Server Error. (CVE-2012-2336)

A memory leak flaw was found in the PHP strtotime() function call. A remote
attacker could possibly use this flaw to cause excessive memory consumption
by triggering many strtotime() function calls. (CVE-2012-0789)

It was found that PHP did not check the zend_strndup() function's return
value in certain cases. A remote attacker could possibly use this flaw to
crash a PHP application. (CVE-2011-4153)

Upstream acknowledges Rubin Xu and Joseph Bonneau as the original reporters
of CVE-2012-2143.

All php53 users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1047</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2950</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2386</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121047"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121054" severity="high">
    <xccdf:title>RHSA-2012:1054: libtiff security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

libtiff did not properly convert between signed and unsigned integer
values, leading to a buffer overflow. An attacker could use this flaw to
create a specially-crafted TIFF file that, when opened, would cause an
application linked against libtiff to crash or, possibly, execute arbitrary
code. (CVE-2012-2088)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the tiff2pdf tool. An attacker could use these flaws to
create a specially-crafted TIFF file that would cause tiff2pdf to crash or,
possibly, execute arbitrary code. (CVE-2012-2113)

All libtiff users should upgrade to these updated packages, which contain
backported patches to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2113</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121054"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121061" severity="medium">
    <xccdf:title>RHSA-2012:1061: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fix:

* The fix for CVE-2011-1083 (RHSA-2012:0150) introduced a flaw in the way
the Linux kernel's Event Poll (epoll) subsystem handled resource clean up
when an ELOOP error code was returned. A local, unprivileged user could use
this flaw to cause a denial of service. (CVE-2012-3375, Moderate)

Bug fixes:

* The qla2xxx driver handled interrupts for QLogic Fibre Channel adapters
incorrectly due to a bug in a test condition for MSI-X support. This update
corrects the bug and qla2xxx now handles interrupts as expected.
(BZ#816373)

* A process scheduler did not handle RPC priority wait queues correctly.
Consequently, the process scheduler failed to wake up all scheduled tasks
as expected after RPC timeout, which caused the system to become
unresponsive and could significantly decrease system performance. This
update modifies the process scheduler to handle RPC priority wait queues as
expected. All scheduled tasks are now properly woken up after RPC timeout
and the system behaves as expected. (BZ#817571)

* The kernel version 2.6.18-308.4.1.el5 contained several bugs which led to
an overrun of the NFS server page array. Consequently, any attempt to
connect an NFS client running on Red Hat Enterprise Linux 5.8 to the NFS
server running on the system with this kernel caused the NFS server to
terminate unexpectedly and the kernel to panic. This update corrects the
bugs causing NFS page array overruns and the kernel no longer crashes in
this scenario. (BZ#820358)

* An insufficiently designed calculation in the CPU accelerator in the
previous kernel caused an arithmetic overflow in the sched_clock() function
when system uptime exceeded 208.5 days. This overflow led to a kernel panic
on the systems using the Time Stamp Counter (TSC) or Virtual Machine
Interface (VMI) clock source. This update corrects the calculation so that
this arithmetic overflow and kernel panic can no longer occur under these
circumstances.

Note: This advisory does not include a fix for this bug for the 32-bit
architecture. (BZ#824654)

* Under memory pressure, memory pages that are still a part of a
checkpointing transaction can be invalidated. However, when the pages were
invalidated, the journal head was re-filed onto the transactions' "forget"
list, which caused the current running transaction's block to be modified.
As a result, block accounting was not properly performed on that modified
block because it appeared to have already been modified due to the journal
head being re-filed. This could trigger an assertion failure in the
"journal_commit_transaction()" function on the system. The "b_modified"
flag is now cleared before the journal head is filed onto any transaction;
assertion failures no longer occur. (BZ#827205)

* When running more than 30 instances of the cclengine utility concurrently
on IBM System z with IBM Communications Controller for Linux, the system
could become unresponsive. This was caused by a missing wake_up() function
call in the qeth_release_buffer() function in the QETH network device
driver. This update adds the missing wake_up() function call and the system
now responds as expected in this scenario. (BZ#829059)

* Recent changes removing support for the Flow Director from the ixgbe
driver introduced bugs that caused the RSS (Receive Side Scaling)
functionality to stop working correctly on Intel 82599EB 10 Gigabit
Ethernet network devices. This update corrects the return code in the
ixgbe_cache_ring_fdir function and setting of the registers that control
the RSS redirection table. Also, obsolete code related to Flow Director
support has been removed. The RSS functionality now works as expected on
these devices. (BZ#832169)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3375</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121061"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121064" severity="high">
    <xccdf:title>RHSA-2012:1064: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the nf_ct_frag6_reasm()
function in the Linux kernel's netfilter IPv6 connection tracking
implementation. A remote attacker could use this flaw to send
specially-crafted packets to a target system that is using IPv6 and also
has the nf_conntrack_ipv6 kernel module loaded, causing it to crash.
(CVE-2012-2744, Important)

* A flaw was found in the way the Linux kernel's key management facility
handled replacement session keyrings on process forks. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2012-2745, Moderate)

Red Hat would like to thank an anonymous contributor working with the
Beyond Security SecuriTeam Secure Disclosure program for reporting
CVE-2012-2744.

This update also fixes the following bugs:

* Previously introduced firmware files required for new Realtek chipsets
contained an invalid prefix ("rtl_nic_") in the file names, for example
"/lib/firmware/rtl_nic/rtl_nic_rtl8168d-1.fw". This update corrects these
file names. For example, the aforementioned file is now correctly named
"/lib/firmware/rtl_nic/rtl8168d-1.fw". (BZ#832359)

* This update blacklists the ADMA428M revision of the 2GB ATA Flash Disk
device. This is due to data corruption occurring on the said device when
the Ultra-DMA 66 transfer mode is used. When the
"libata.force=5:pio0,6:pio0" kernel parameter is set, the aforementioned
device works as expected. (BZ#832363)

* On Red Hat Enterprise Linux 6, mounting an NFS export from a Windows 2012
server failed due to the fact that the Windows server contains support for
the minor version 1 (v4.1) of the NFS version 4 protocol only, along with
support for versions 2 and 3. The lack of the minor version 0 (v4.0)
support caused Red Hat Enterprise Linux 6 clients to fail instead of
rolling back to version 3 as expected. This update fixes this bug and
mounting an NFS export works as expected. (BZ#832365)

* On ext4 file systems, when fallocate() failed to allocate blocks due to
the ENOSPC condition (no space left on device) for a file larger than 4 GB,
the size of the file became corrupted and, consequently, caused file system
corruption. This was due to a missing cast operator in the
"ext4_fallocate()" function. With this update, the underlying source code
has been modified to address this issue, and file system corruption no
longer occurs. (BZ#833034)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2745</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121064"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121068" severity="high">
    <xccdf:title>RHSA-2012:1068: openjpeg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenJPEG is an open source library for reading and writing image files in
JPEG 2000 format.

An input validation flaw, leading to a heap-based buffer overflow, was
found in the way OpenJPEG handled the tile number and size in an image tile
header. A remote attacker could provide a specially-crafted image file
that, when decoded using an application linked against OpenJPEG, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-3358)

OpenJPEG allocated insufficient memory when encoding JPEG 2000 files from
input images that have certain color depths. A remote attacker could
provide a specially-crafted image file that, when opened in an application
linked against OpenJPEG (such as image_to_j2k), would cause the application
to crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2009-5030)

Users of OpenJPEG should upgrade to these updated packages, which contain
patches to correct these issues. All running applications using OpenJPEG
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3358</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121068"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121081" severity="medium">
    <xccdf:title>RHSA-2012:1081: sudo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way the network matching code in sudo handled
multiple IP networks listed in user specification configuration directives.
A user, who is authorized to run commands with sudo on specific hosts,
could use this flaw to bypass intended restrictions and run those commands
on hosts not matched by any of the network specifications. (CVE-2012-2337)

All users of sudo are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2337</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121081"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121088" severity="high">
    <xccdf:title>RHSA-2012:1088: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-1948, CVE-2012-1951, CVE-2012-1952, CVE-2012-1953,
CVE-2012-1954, CVE-2012-1958, CVE-2012-1962, CVE-2012-1967)

A malicious web page could bypass same-compartment security wrappers (SCSW)
and execute arbitrary code with chrome privileges. (CVE-2012-1959)

A flaw in the context menu functionality in Firefox could allow a malicious
website to bypass intended restrictions and allow a cross-site scripting
attack. (CVE-2012-1966)

A page different to that in the address bar could be displayed when
dragging and dropping to the address bar, possibly making it easier for a
malicious site or user to perform a phishing attack. (CVE-2012-1950)

A flaw in the way Firefox called history.forward and history.back could
allow an attacker to conceal a malicious URL, possibly tricking a user
into believing they are viewing a trusted site. (CVE-2012-1955)

A flaw in a parser utility class used by Firefox to parse feeds (such as
RSS) could allow an attacker to execute arbitrary JavaScript with the
privileges of the user running Firefox. This issue could have affected
other browser components or add-ons that assume the class returns
sanitized input. (CVE-2012-1957)

A flaw in the way Firefox handled X-Frame-Options headers could allow a
malicious website to perform a clickjacking attack. (CVE-2012-1961)

A flaw in the way Content Security Policy (CSP) reports were generated by
Firefox could allow a malicious web page to steal a victim's OAuth 2.0
access tokens and OpenID credentials. (CVE-2012-1963)

A flaw in the way Firefox handled certificate warnings could allow a
man-in-the-middle attacker to create a crafted warning, possibly tricking
a user into accepting an arbitrary certificate as trusted. (CVE-2012-1964)

A flaw in the way Firefox handled feed:javascript URLs could allow output
filtering to be bypassed, possibly leading to a cross-site scripting
attack. (CVE-2012-1965)

The nss update RHBA-2012:0337 for Red Hat Enterprise Linux 5 and 6
introduced a mitigation for the CVE-2011-3389 flaw. For compatibility
reasons, it remains disabled by default in the nss packages. This update
makes Firefox enable the mitigation by default. It can be disabled by
setting the NSS_SSL_CBC_RANDOM_IV environment variable to 0 before
launching Firefox. (BZ#838879)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.6 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Jesse Ruderman, Christian Holler, Bill
McCloskey, Abhishek Arya, Arthur Gerkis, Bill Keese, moz_bug_r_a4, Bobby
Holley, Code Audit Labs, Mariusz Mlynski, Mario Heiderich, Frédéric Buclin,
Karthikeyan Bhargavan, Matt McCutchen, Mario Gomes, and Soroush Dalili as
the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.6 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1948</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1950</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1951</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1952</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1953</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1954</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1963</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1965</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1967</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121088"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121089" severity="high">
    <xccdf:title>RHSA-2012:1089: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2012-1948,
CVE-2012-1951, CVE-2012-1952, CVE-2012-1953, CVE-2012-1954, CVE-2012-1958,
CVE-2012-1962, CVE-2012-1967)

Malicious content could bypass same-compartment security wrappers (SCSW)
and execute arbitrary code with chrome privileges. (CVE-2012-1959)

A flaw in the way Thunderbird called history.forward and history.back could
allow an attacker to conceal a malicious URL, possibly tricking a user
into believing they are viewing trusted content. (CVE-2012-1955)

A flaw in a parser utility class used by Thunderbird to parse feeds (such
as RSS) could allow an attacker to execute arbitrary JavaScript with the
privileges of the user running Thunderbird. This issue could have affected
other Thunderbird components or add-ons that assume the class returns
sanitized input. (CVE-2012-1957)

A flaw in the way Thunderbird handled X-Frame-Options headers could allow
malicious content to perform a clickjacking attack. (CVE-2012-1961)

A flaw in the way Content Security Policy (CSP) reports were generated by
Thunderbird could allow malicious content to steal a victim's OAuth 2.0
access tokens and OpenID credentials. (CVE-2012-1963)

A flaw in the way Thunderbird handled certificate warnings could allow a
man-in-the-middle attacker to create a crafted warning, possibly tricking
a user into accepting an arbitrary certificate as trusted. (CVE-2012-1964)

The nss update RHBA-2012:0337 for Red Hat Enterprise Linux 5 and 6
introduced a mitigation for the CVE-2011-3389 flaw. For compatibility
reasons, it remains disabled by default in the nss packages. This update
makes Thunderbird enable the mitigation by default. It can be disabled by
setting the NSS_SSL_CBC_RANDOM_IV environment variable to 0 before
launching Thunderbird. (BZ#838879)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Jesse Ruderman, Christian Holler, Bill
McCloskey, Abhishek Arya, Arthur Gerkis, Bill Keese, moz_bug_r_a4, Bobby
Holley, Mariusz Mlynski, Mario Heiderich, Frédéric Buclin, Karthikeyan
Bhargavan, and Matt McCutchen as the original reporters of these issues.

Note: None of the issues in this advisory can be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.6 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1089</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1948</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1951</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1952</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1953</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1954</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1955</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1963</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1967</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121089"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121090" severity="medium">
    <xccdf:title>RHSA-2012:1090: nss and nspr security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way the ASN.1 (Abstract Syntax Notation One)
decoder in NSS handled zero length items. This flaw could cause the decoder
to incorrectly skip or replace certain items with a default value, or could
cause an application to crash if, for example, it received a
specially-crafted OCSP (Online Certificate Status Protocol) response.
(CVE-2012-0441)

It was found that a Certificate Authority (CA) issued a subordinate CA
certificate to its customer, that could be used to issue certificates for
any name. This update renders the subordinate CA certificate as untrusted.
(BZ#798533)

Note: The BZ#798533 fix only applies to applications using the NSS Builtin
Object Token. It does not render the certificates untrusted for
applications that use the NSS library, but do not use the NSS Builtin
Object Token.

In addition, the nspr package has been upgraded to upstream version 4.9.1,
and the nss package has been upgraded to upstream version 3.13.5. These
updates provide a number of bug fixes and enhancements over the previous
versions. (BZ#834220, BZ#834219)

All NSS and NSPR users should upgrade to these updated packages, which
correct these issues and add these enhancements. After installing the
update, applications using NSS and NSPR must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0441</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121091" severity="medium">
    <xccdf:title>RHSA-2012:1091: nss, nspr, and nss-util security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way the ASN.1 (Abstract Syntax Notation One)
decoder in NSS handled zero length items. This flaw could cause the decoder
to incorrectly skip or replace certain items with a default value, or could
cause an application to crash if, for example, it received a
specially-crafted OCSP (Online Certificate Status Protocol) response.
(CVE-2012-0441)

The nspr package has been upgraded to upstream version 4.9.1, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#833762)

The nss-util package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#833763)

The nss package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#834100)

All NSS, NSPR, and nss-util users are advised to upgrade to these updated
packages, which correct these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0441</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121091"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121097" severity="medium">
    <xccdf:title>RHSA-2012:1097: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function properly.

It was discovered that the formatted printing functionality in glibc did
not properly restrict the use of alloca(). This could allow an attacker to
bypass FORTIFY_SOURCE protections and execute arbitrary code using a format
string flaw in an application, even though these protections are expected
to limit the impact of such flaws to an application abort. (CVE-2012-3406)

This update also fixes the following bug:

* If a file or a string was in the IBM-930 encoding, and contained the
invalid multibyte character "0xffff", attempting to use iconv() (or the
iconv command) to convert that file or string to another encoding, such as
UTF-8, resulted in a segmentation fault. With this update, the conversion
code for the IBM-930 encoding recognizes this invalid character and calls
an error handler, rather than causing a segmentation fault. (BZ#837896)

All users of glibc are advised to upgrade to these updated packages, which
contain backported patches to fix these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3406</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121097"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121098" severity="medium">
    <xccdf:title>RHSA-2012:1098: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function properly.

Multiple errors in glibc's formatted printing functionality could allow an
attacker to bypass FORTIFY_SOURCE protections and execute arbitrary code
using a format string flaw in an application, even though these protections
are expected to limit the impact of such flaws to an application abort.
(CVE-2012-3404, CVE-2012-3405, CVE-2012-3406)

This update also fixes the following bug:

* A programming error caused an internal array of nameservers to be only
partially initialized when the /etc/resolv.conf file contained IPv6
nameservers. Depending on the contents of a nearby structure, this could
cause certain applications to terminate unexpectedly with a segmentation
fault. The programming error has been fixed, which restores proper behavior
with IPv6 nameservers listed in the /etc/resolv.conf file. (BZ#837026)

All users of glibc are advised to upgrade to these updated packages, which
contain backported patches to fix these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3404</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3405</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3406</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121098"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121102" severity="medium">
    <xccdf:title>RHSA-2012:1102: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A flaw was found in the way the Pidgin MSN protocol plug-in processed text
that was not encoded in UTF-8. A remote attacker could use this flaw to
crash Pidgin by sending a specially-crafted MSN message. (CVE-2012-1178)

An input validation flaw was found in the way the Pidgin MSN protocol
plug-in handled MSN notification messages. A malicious server or a remote
attacker could use this flaw to crash Pidgin by sending a specially-crafted
MSN notification message. (CVE-2012-2318)

A buffer overflow flaw was found in the Pidgin MXit protocol plug-in. A
remote attacker could use this flaw to crash Pidgin by sending a MXit
message containing specially-crafted emoticon tags. (CVE-2012-3374)

Red Hat would like to thank the Pidgin project for reporting the
CVE-2012-3374 issue. Upstream acknowledges Ulf Härnhammar as the original
reporter of CVE-2012-3374.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2318</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3374</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121102"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121116" severity="medium">
    <xccdf:title>RHSA-2012:1116: perl-DBD-Pg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl DBI is a database access Application Programming Interface (API) for
the Perl language. perl-DBD-Pg allows Perl applications to access
PostgreSQL database servers.

Two format string flaws were found in perl-DBD-Pg. A specially-crafted
database warning or error message from a server could cause an application
using perl-DBD-Pg to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2012-1151)

All users of perl-DBD-Pg are advised to upgrade to this updated package,
which contains a backported patch to fix these issues. Applications using
perl-DBD-Pg must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1151</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121116"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121122" severity="high">
    <xccdf:title>RHSA-2012:1122: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

An uninitialized data structure use flaw was found in BIND when DNSSEC
validation was enabled. A remote attacker able to send a large number of
queries to a DNSSEC validating BIND resolver could use this flaw to cause
it to exit unexpectedly with an assertion failure. (CVE-2012-3817)

Users of bind97 are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3817</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121122"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121123" severity="high">
    <xccdf:title>RHSA-2012:1123: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

An uninitialized data structure use flaw was found in BIND when DNSSEC
validation was enabled. A remote attacker able to send a large number of
queries to a DNSSEC validating BIND resolver could use this flaw to cause
it to exit unexpectedly with an assertion failure. (CVE-2012-3817)

Users of bind are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3817</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121123"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121130" severity="medium">
    <xccdf:title>RHSA-2012:1130: xen security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A flaw was found in the way the pyGrub boot loader handled compressed
kernel images. A privileged guest user in a para-virtualized guest (a DomU)
could use this flaw to create a crafted kernel image that, when attempting
to boot it, could result in an out-of-memory condition in the privileged
domain (the Dom0). (CVE-2012-2625)

Red Hat would like to thank Xinli Niu for reporting this issue.

All users of xen are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the xend service must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2625</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121130"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121131" severity="high">
    <xccdf:title>RHSA-2012:1131: krb5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

An uninitialized pointer use flaw was found in the way the MIT Kerberos KDC
handled initial authentication requests (AS-REQ). A remote,
unauthenticated attacker could use this flaw to crash the KDC via a
specially-crafted AS-REQ request. (CVE-2012-1015)

A NULL pointer dereference flaw was found in the MIT Kerberos
administration daemon, kadmind. A Kerberos administrator who has the
"create" privilege could use this flaw to crash kadmind. (CVE-2012-1013)

Red Hat would like to thank the MIT Kerberos project for reporting
CVE-2012-1015. Upstream acknowledges Emmanuel Bouillon (NCI Agency) as the
original reporter of CVE-2012-1015.

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the krb5kdc and kadmind daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121131"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121132" severity="high">
    <xccdf:title>RHSA-2012:1132: icedtea-web security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

An uninitialized pointer use flaw was found in the IcedTea-Web plug-in.
Visiting a malicious web page could possibly cause a web browser using the
IcedTea-Web plug-in to crash, disclose a portion of its memory, or execute
arbitrary code. (CVE-2012-3422)

It was discovered that the IcedTea-Web plug-in incorrectly assumed all
strings received from the browser were NUL terminated. When using the
plug-in with a web browser that does not NUL terminate strings, visiting a
web page containing a Java applet could possibly cause the browser to
crash, disclose a portion of its memory, or execute arbitrary code.
(CVE-2012-3423)

Red Hat would like to thank Chamal De Silva for reporting the CVE-2012-3422
issue.

This erratum also upgrades IcedTea-Web to version 1.2.1. Refer to the NEWS
file, linked to in the References, for further information.

All IcedTea-Web users should upgrade to these updated packages, which
resolve these issues. Web browsers using the IcedTea-Web browser plug-in
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3423</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121135" severity="high">
    <xccdf:title>RHSA-2012:1135: libreoffice security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibreOffice is an open source, community-developed office productivity
suite. It includes the key desktop applications, such as a word processor,
spreadsheet application, presentation manager, formula editor, and a
drawing program.

Multiple heap-based buffer overflow flaws were found in the way LibreOffice
processed encryption information in the manifest files of OpenDocument
Format files. An attacker could provide a specially-crafted OpenDocument
Format file that, when opened in a LibreOffice application, would cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2012-2665)

Upstream acknowledges Timo Warns as the original reporter of these issues.

All LibreOffice users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of LibreOffice applications must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2665</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121136" severity="high">
    <xccdf:title>RHSA-2012:1136: openoffice.org security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

Multiple heap-based buffer overflow flaws were found in the way
OpenOffice.org processed encryption information in the manifest files of
OpenDocument Format files. An attacker could provide a specially-crafted
OpenDocument Format file that, when opened in an OpenOffice.org
application, would cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-2665)

Upstream acknowledges Timo Warns as the original reporter of these issues.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2665</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121136"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121139" severity="high">
    <xccdf:title>RHSA-2012:1139: bind-dyndb-ldap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dynamic LDAP back end is a plug-in for BIND that provides back-end
capabilities to LDAP databases. It features support for dynamic updates and
internal caching that help to reduce the load on LDAP servers.

A flaw was found in the way bind-dyndb-ldap performed the escaping of names
from DNS requests for use in LDAP queries. A remote attacker able to send
DNS queries to a named server that is configured to use bind-dyndb-ldap
could use this flaw to cause named to exit unexpectedly with an assertion
failure. (CVE-2012-3429)

Red Hat would like to thank Sigbjorn Lie of Atea Norway for reporting this
issue.

All bind-dyndb-ldap users should upgrade to this updated package, which
contains a backported patch to correct this issue. For the update to take
effect, the named service must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3429</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121139"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121140" severity="medium">
    <xccdf:title>RHSA-2012:1140: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

A denial of service flaw was found in the way the dhcpd daemon handled
zero-length client identifiers. A remote attacker could use this flaw to
send a specially-crafted request to dhcpd, possibly causing it to enter an
infinite loop and consume an excessive amount of CPU time. (CVE-2012-3571)

Upstream acknowledges Markus Hietava of the Codenomicon CROSS project as
the original reporter of this issue.

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing this update, all
DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3571</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121141" severity="medium">
    <xccdf:title>RHSA-2012:1141: dhcp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

A denial of service flaw was found in the way the dhcpd daemon handled
zero-length client identifiers. A remote attacker could use this flaw to
send a specially-crafted request to dhcpd, possibly causing it to enter an
infinite loop and consume an excessive amount of CPU time. (CVE-2012-3571)

Two memory leak flaws were found in the dhcpd daemon. A remote attacker
could use these flaws to cause dhcpd to exhaust all available memory by
sending a large number of DHCP requests. (CVE-2012-3954)

Upstream acknowledges Markus Hietava of the Codenomicon CROSS project as
the original reporter of CVE-2012-3571, and Glen Eustace of Massey
University, New Zealand, as the original reporter of CVE-2012-3954.

Users of DHCP should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
all DHCP servers will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3954</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121141"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121149" severity="medium">
    <xccdf:title>RHSA-2012:1149: sudo security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

An insecure temporary file use flaw was found in the sudo package's
post-uninstall script. A local attacker could possibly use this flaw to
overwrite an arbitrary file via a symbolic link attack, or modify the
contents of the "/etc/nsswitch.conf" file during the upgrade or removal of
the sudo package. (CVE-2012-3440)

This update also fixes the following bugs:

* Previously, sudo escaped non-alphanumeric characters in commands using
"sudo -s" or "sudo -" at the wrong place and interfered with the
authorization process. Some valid commands were not permitted. Now,
non-alphanumeric characters escape immediately before the command is
executed and no longer interfere with the authorization process.
(BZ#844418)

* Prior to this update, the sudo utility could, under certain
circumstances, fail to receive the SIGCHLD signal when it was executed
from a process that blocked the SIGCHLD signal. As a consequence, sudo
could become suspended and fail to exit. This update modifies the signal
process mask so that sudo can exit and sends the correct output.
(BZ#844419)

* The sudo update RHSA-2012:0309 introduced a regression that caused the
Security-Enhanced Linux (SELinux) context of the "/etc/nsswitch.conf" file
to change during the installation or upgrade of the sudo package. This
could cause various services confined by SELinux to no longer be permitted
to access the file. In reported cases, this issue prevented PostgreSQL and
Postfix from starting. (BZ#842759)

* Updating the sudo package resulted in the "sudoers" line in
"/etc/nsswitch.conf" being removed. This update corrects the bug in the
sudo package's post-uninstall script that caused this issue. (BZ#844420)

* Prior to this update, a race condition bug existed in sudo. When a
program was executed with sudo, the program could possibly exit
successfully before sudo started waiting for it. In this situation, the
program would be left in a zombie state and sudo would wait for it
endlessly, expecting it to still be running. (BZ#844978)

All users of sudo are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1149</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3440</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121149"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121151" severity="low">
    <xccdf:title>RHSA-2012:1151: openldap security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

It was found that the OpenLDAP server daemon ignored olcTLSCipherSuite
settings. This resulted in the default cipher suite always being used,
which could lead to weaker than expected ciphers being accepted during
Transport Layer Security (TLS) negotiation with OpenLDAP clients.
(CVE-2012-2668)

This update also fixes the following bug:

* When the smbk5pwd overlay was enabled in an OpenLDAP server, and a user
changed their password, the Microsoft NT LAN Manager (NTLM) and Microsoft
LAN Manager (LM) hashes were not computed correctly. This led to the
sambaLMPassword and sambaNTPassword attributes being updated with incorrect
values, preventing the user logging in using a Windows-based client or a
Samba client.

With this update, the smbk5pwd overlay is linked against OpenSSL. As such,
the NTLM and LM hashes are computed correctly, and password changes work as
expected when using smbk5pwd. (BZ#844428)

Users of OpenLDAP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the OpenLDAP daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2668</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121151"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121156" severity="medium">
    <xccdf:title>RHSA-2012:1156: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer overflow flaw was found in the i915_gem_execbuffer2() function
in the Intel i915 driver in the Linux kernel. A local, unprivileged user
could use this flaw to cause a denial of service. This issue only affected
32-bit systems. (CVE-2012-2383, Moderate)

* A missing initialization flaw was found in the sco_sock_getsockopt_old()
function in the Linux kernel's Bluetooth implementation. A local,
unprivileged user could use this flaw to cause an information leak.
(CVE-2011-1078, Low)

Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting the
CVE-2011-1078 issue.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1156</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2383</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121156"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121174" severity="low">
    <xccdf:title>RHSA-2012:1174: kernel security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the way the Linux kernel's dl2k driver, used by
certain D-Link Gigabit Ethernet adapters, restricted IOCTLs. A local,
unprivileged user could use this flaw to issue potentially harmful IOCTLs,
which could cause Ethernet adapters using the dl2k driver to malfunction
(for example, losing network connectivity). (CVE-2012-2313, Low)

Red Hat would like to thank Stephan Mueller for reporting this issue.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2313</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121174"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121180" severity="medium">
    <xccdf:title>RHSA-2012:1180: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's GIF image format plug-in. An attacker could create a
specially-crafted GIF image file that, when opened, could cause the GIF
plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2012-3481)

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)
decompression algorithm implementation used by the GIMP's GIF image format
plug-in. An attacker could create a specially-crafted GIF image file that,
when opened, could cause the GIF plug-in to crash or, potentially, execute
arbitrary code with the privileges of the user running the GIMP.
(CVE-2011-2896)

A heap-based buffer overflow flaw was found in the GIMP's KiSS CEL file
format plug-in. An attacker could create a specially-crafted KiSS palette
file that, when opened, could cause the CEL plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2012-3403)

Red Hat would like to thank Matthias Weckbecker of the SUSE Security Team
for reporting the CVE-2012-3481 issue.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3481</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121181" severity="medium">
    <xccdf:title>RHSA-2012:1181: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the GIMP's Adobe Photoshop (PSD) image file plug-in. An
attacker could create a specially-crafted PSD image file that, when opened,
could cause the PSD plug-in to crash or, potentially, execute arbitrary
code with the privileges of the user running the GIMP. (CVE-2009-3909,
CVE-2012-3402)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's GIF image format plug-in. An attacker could create a
specially-crafted GIF image file that, when opened, could cause the GIF
plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2012-3481)

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)
decompression algorithm implementation used by the GIMP's GIF image format
plug-in. An attacker could create a specially-crafted GIF image file that,
when opened, could cause the GIF plug-in to crash or, potentially, execute
arbitrary code with the privileges of the user running the GIMP.
(CVE-2011-2896)

A heap-based buffer overflow flaw was found in the GIMP's KiSS CEL file
format plug-in. An attacker could create a specially-crafted KiSS palette
file that, when opened, could cause the CEL plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2012-3403)

Red Hat would like to thank Secunia Research for reporting CVE-2009-3909,
and Matthias Weckbecker of the SUSE Security Team for reporting
CVE-2012-3481.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-3909</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3481</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121181"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121201" severity="medium">
    <xccdf:title>RHSA-2012:1201: tetex security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>teTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (DVI) file as output.

teTeX embeds a copy of t1lib to rasterize bitmaps from PostScript Type 1
fonts. The following issues affect t1lib code:

Two heap-based buffer overflow flaws were found in the way t1lib processed
Adobe Font Metrics (AFM) files. If a specially-crafted font file was opened
by teTeX, it could cause teTeX to crash or, potentially, execute arbitrary
code with the privileges of the user running teTeX. (CVE-2010-2642,
CVE-2011-0433)

An invalid pointer dereference flaw was found in t1lib. A specially-crafted
font file could, when opened, cause teTeX to crash or, potentially, execute
arbitrary code with the privileges of the user running teTeX.
(CVE-2011-0764)

A use-after-free flaw was found in t1lib. A specially-crafted font file
could, when opened, cause teTeX to crash or, potentially, execute arbitrary
code with the privileges of the user running teTeX. (CVE-2011-1553)

An off-by-one flaw was found in t1lib. A specially-crafted font file could,
when opened, cause teTeX to crash or, potentially, execute arbitrary code
with the privileges of the user running teTeX. (CVE-2011-1554)

An out-of-bounds memory read flaw was found in t1lib. A specially-crafted
font file could, when opened, cause teTeX to crash. (CVE-2011-1552)

teTeX embeds a copy of Xpdf, an open source Portable Document Format (PDF)
file viewer, to allow adding images in PDF format to the generated PDF
documents. The following issues affect Xpdf code:

An uninitialized pointer use flaw was discovered in Xpdf. If pdflatex was
used to process a TeX document referencing a specially-crafted PDF file, it
could cause pdflatex to crash or, potentially, execute arbitrary code with
the privileges of the user running pdflatex. (CVE-2010-3702)

An array index error was found in the way Xpdf parsed PostScript Type 1
fonts embedded in PDF documents. If pdflatex was used to process a TeX
document referencing a specially-crafted PDF file, it could cause pdflatex
to crash or, potentially, execute arbitrary code with the privileges of the
user running pdflatex. (CVE-2010-3704)

Red Hat would like to thank the Evince development team for reporting
CVE-2010-2642. Upstream acknowledges Jon Larimer of IBM X-Force as the
original reporter of CVE-2010-2642.

All users of tetex are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-3704</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1554</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121201"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121202" severity="medium">
    <xccdf:title>RHSA-2012:1202: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

A flaw was found in libvirtd's RPC call handling. An attacker able to
establish a read-only connection to libvirtd could trigger this flaw with a
specially-crafted RPC command that has the number of parameters set to 0,
causing libvirtd to access invalid memory and crash. (CVE-2012-3445)

This update also fixes the following bugs:

* Previously, repeatedly migrating a guest between two machines while using
the tunnelled migration could cause the libvirt daemon to lock up
unexpectedly. The bug in the code for locking remote drivers has been fixed
and repeated tunnelled migrations of domains now work as expected.
(BZ#847946)

* Previously, when certain system locales were used by the system, libvirt
could issue incorrect commands to the hypervisor. This bug has been fixed
and the libvirt library and daemon are no longer affected by the choice of
the user locale. (BZ#847959)

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3445</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121202"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121206" severity="medium">
    <xccdf:title>RHSA-2012:1206: python-paste-script security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python Paste provides middleware for building and running Python web
applications. The python-paste-script package includes paster, a tool for
working with and running Python Paste applications.

It was discovered that paster did not drop supplementary group privileges
when started by the root user. Running "paster serve" as root to start a
Python web application that will run as a non-root user and group resulted
in that application running with root group privileges. This could possibly
allow a remote attacker to gain access to files that should not be
accessible to the application. (CVE-2012-0878)

All paster users should upgrade to this updated package, which contains a
backported patch to resolve this issue. All running paster instances
configured to drop privileges must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0878</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121207" severity="medium">
    <xccdf:title>RHSA-2012:1207: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function properly.

Multiple integer overflow flaws, leading to stack-based buffer overflows,
were found in glibc's functions for converting a string to a numeric
representation (strtod(), strtof(), and strtold()). If an application used
such a function on attacker controlled input, it could cause the
application to crash or, potentially, execute arbitrary code.
(CVE-2012-3480)

This update also fixes the following bug:

* Previously, logic errors in various mathematical functions, including
exp, exp2, expf, exp2f, pow, sin, tan, and rint, caused inconsistent
results when the functions were used with the non-default rounding mode.
This could also cause applications to crash in some cases. With this
update, the functions now give correct results across the four different
rounding modes. (BZ#839411)

All users of glibc are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121207"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121208" severity="medium">
    <xccdf:title>RHSA-2012:1208: glibc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C and standard math libraries used
by multiple programs on the system. Without these libraries, the Linux
system cannot function properly.

Multiple integer overflow flaws, leading to stack-based buffer overflows,
were found in glibc's functions for converting a string to a numeric
representation (strtod(), strtof(), and strtold()). If an application used
such a function on attacker controlled input, it could cause the
application to crash or, potentially, execute arbitrary code.
(CVE-2012-3480)

All users of glibc are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121208"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121210" severity="high">
    <xccdf:title>RHSA-2012:1210: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-1970, CVE-2012-1972, CVE-2012-1973, CVE-2012-1974,
CVE-2012-1975, CVE-2012-1976, CVE-2012-3956, CVE-2012-3957, CVE-2012-3958,
CVE-2012-3959, CVE-2012-3960, CVE-2012-3961, CVE-2012-3962, CVE-2012-3963,
CVE-2012-3964)

A web page containing a malicious Scalable Vector Graphics (SVG) image file
could cause Firefox to crash or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2012-3969, CVE-2012-3970)

Two flaws were found in the way Firefox rendered certain images using
WebGL. A web page containing malicious content could cause Firefox to crash
or, under certain conditions, possibly execute arbitrary code with the
privileges of the user running Firefox. (CVE-2012-3967, CVE-2012-3968)

A flaw was found in the way Firefox decoded embedded bitmap images in Icon
Format (ICO) files. A web page containing a malicious ICO file could cause
Firefox to crash or, under certain conditions, possibly execute arbitrary
code with the privileges of the user running Firefox. (CVE-2012-3966)

A flaw was found in the way the "eval" command was handled by the Firefox
Web Console. Running "eval" in the Web Console while viewing a web page
containing malicious content could possibly cause Firefox to execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2012-3980)

An out-of-bounds memory read flaw was found in the way Firefox used the
format-number feature of XSLT (Extensible Stylesheet Language
Transformations). A web page containing malicious content could possibly
cause an information leak, or cause Firefox to crash. (CVE-2012-3972)

It was found that the SSL certificate information for a previously visited
site could be displayed in the address bar while the main window displayed
a new page. This could lead to phishing attacks as attackers could use this
flaw to trick users into believing they are viewing a trusted site.
(CVE-2012-3976)

A flaw was found in the location object implementation in Firefox.
Malicious content could use this flaw to possibly allow restricted content
to be loaded. (CVE-2012-3978)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.7 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christian Holler, Jesse Ruderman, John
Schoenick, Vladimir Vukicevic, Daniel Holbert, Abhishek Arya, Frédéric
Hoguin, miaubiz, Arthur Gerkis, Nicolas Grégoire, Mark Poticha,
moz_bug_r_a4, and Colby Russell as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.7 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1972</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1973</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1974</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3963</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3967</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3968</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3969</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3972</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3978</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3980</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121210"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121211" severity="high">
    <xccdf:title>RHSA-2012:1211: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2012-1970,
CVE-2012-1972, CVE-2012-1973, CVE-2012-1974, CVE-2012-1975, CVE-2012-1976,
CVE-2012-3956, CVE-2012-3957, CVE-2012-3958, CVE-2012-3959, CVE-2012-3960,
CVE-2012-3961, CVE-2012-3962, CVE-2012-3963, CVE-2012-3964)

Content containing a malicious Scalable Vector Graphics (SVG) image file
could cause Thunderbird to crash or, potentially, execute arbitrary code
with the privileges of the user running Thunderbird. (CVE-2012-3969,
CVE-2012-3970)

Two flaws were found in the way Thunderbird rendered certain images using
WebGL. Malicious content could cause Thunderbird to crash or, under certain
conditions, possibly execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2012-3967, CVE-2012-3968)

A flaw was found in the way Thunderbird decoded embedded bitmap images in
Icon Format (ICO) files. Content containing a malicious ICO file could
cause Thunderbird to crash or, under certain conditions, possibly execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2012-3966)

A flaw was found in the way the "eval" command was handled by the
Thunderbird Error Console. Running "eval" in the Error Console while
viewing malicious content could possibly cause Thunderbird to execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2012-3980)

An out-of-bounds memory read flaw was found in the way Thunderbird used the
format-number feature of XSLT (Extensible Stylesheet Language
Transformations). Malicious content could possibly cause an information
leak, or cause Thunderbird to crash. (CVE-2012-3972)

A flaw was found in the location object implementation in Thunderbird.
Malicious content could use this flaw to possibly allow restricted content
to be loaded. (CVE-2012-3978)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christian Holler, Jesse Ruderman, John
Schoenick, Vladimir Vukicevic, Daniel Holbert, Abhishek Arya, Frédéric
Hoguin, miaubiz, Arthur Gerkis, Nicolas Grégoire, moz_bug_r_a4, and Colby
Russell as the original reporters of these issues.

Note: All issues except CVE-2012-3969 and CVE-2012-3970 cannot be exploited
by a specially-crafted HTML mail message as JavaScript is disabled by
default for mail messages. They could be exploited another way in
Thunderbird, for example, when viewing the full remote content of an RSS
feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.7 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1972</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1973</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1974</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3963</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3966</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3967</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3968</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3969</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3972</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3978</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3980</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121211"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121221" severity="high">
    <xccdf:title>RHSA-2012:1221: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

It was discovered that the Beans component in OpenJDK did not perform
permission checks properly. An untrusted Java application or applet could
use this flaw to use classes from restricted packages, allowing it to
bypass Java sandbox restrictions. (CVE-2012-1682)

A hardening fix was applied to the AWT component in OpenJDK, removing
functionality from the restricted SunToolkit class that was used in
combination with other flaws to bypass Java sandbox restrictions.
(CVE-2012-0547)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.4. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1682</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121221"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121222" severity="high">
    <xccdf:title>RHSA-2012:1222: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

It was discovered that the Beans component in OpenJDK did not perform
permission checks properly. An untrusted Java application or applet could
use this flaw to use classes from restricted packages, allowing it to
bypass Java sandbox restrictions. (CVE-2012-1682)

A hardening fix was applied to the AWT component in OpenJDK, removing
functionality from the restricted SunToolkit class that was used in
combination with other flaws to bypass Java sandbox restrictions.
(CVE-2012-0547)

This erratum also upgrades the OpenJDK package to IcedTea6 1.10.9. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1682</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121222"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121223" severity="high">
    <xccdf:title>RHSA-2012:1223: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple improper permission check issues were discovered in the Beans
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2012-4681,
CVE-2012-1682, CVE-2012-3136)

A hardening fix was applied to the AWT component in OpenJDK, removing
functionality from the restricted SunToolkit class that was used in
combination with other flaws to bypass Java sandbox restrictions.
(CVE-2012-0547)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4681</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121223"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121234" severity="high">
    <xccdf:title>RHSA-2012:1234: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space
component for running virtual machines using KVM.

A flaw was found in the way QEMU handled VT100 terminal escape sequences
when emulating certain character devices. A guest user with privileges to
write to a character device that is emulated on the host using a virtual
console back-end could use this flaw to crash the qemu-kvm process on the
host or, possibly, escalate their privileges on the host. (CVE-2012-3515)

This flaw did not affect the default use of KVM. Affected configurations
were:

* When guests were started from the command line ("/usr/libexec/qemu-kvm")
without the "-nodefaults" option, and also without specifying a
serial or parallel device, or a virtio-console device, that specifically
does not use a virtual console (vc) back-end. (Note that Red Hat does not
support invoking "qemu-kvm" from the command line without "-nodefaults" on
Red Hat Enterprise Linux 6.)

* Guests that were managed via libvirt, such as when using Virtual Machine
Manager (virt-manager), but that have a serial or parallel device, or a
virtio-console device, that uses a virtual console back-end. By default,
guests managed via libvirt will not use a virtual console back-end
for such devices.

Red Hat would like to thank the Xen project for reporting this issue.

All users of qemu-kvm should upgrade to these updated packages, which
resolve this issue. After installing this update, shut down all running
virtual machines. Once all virtual machines have shut down, start them
again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3515</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121234"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121235" severity="high">
    <xccdf:title>RHSA-2012:1235: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built
for the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way QEMU handled VT100 terminal escape sequences
when emulating certain character devices. A guest user with privileges to
write to a character device that is emulated on the host using a virtual
console back-end could use this flaw to crash the qemu-kvm process on the
host or, possibly, escalate their privileges on the host. (CVE-2012-3515)

This flaw did not affect the default use of KVM. Affected configurations
were:

* When guests were started from the command line ("/usr/libexec/qemu-kvm"),
and without specifying a serial or parallel device that specifically does
not use a virtual console (vc) back-end. (Note that Red Hat does not
support invoking "qemu-kvm" from the command line on Red Hat Enterprise
Linux 5.)

* Guests that were managed via libvirt, such as when using Virtual Machine
Manager (virt-manager), but that have a serial or parallel device that uses
a virtual console back-end. By default, guests managed via libvirt will not
use a virtual console back-end for such devices.

Red Hat would like to thank the Xen project for reporting this issue.

All KVM users should upgrade to these updated packages, which correct this
issue. Note: The procedure in the Solution section must be performed before
this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1235</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3515</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121235"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121236" severity="high">
    <xccdf:title>RHSA-2012:1236: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A flaw was found in the way QEMU handled VT100 terminal escape sequences
when emulating certain character devices. A guest user with privileges to
write to a character device that is emulated on the host using a virtual
console back-end could use this flaw to crash the qemu process on the
host or, possibly, escalate their privileges on the host. (CVE-2012-3515)

This flaw did not affect the default use of the Xen hypervisor
implementation in Red Hat Enterprise Linux 5. This problem only affected
fully-virtualized guests that have a serial or parallel device that uses a
virtual console (vc) back-end. By default, the virtual console back-end is
not used for such devices; only guests explicitly configured to use them
in this way were affected.

Red Hat would like to thank the Xen project for reporting this issue.

All users of xen are advised to upgrade to these updated packages, which
correct this issue. After installing the updated packages, all
fully-virtualized guests must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1236</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3515</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121236"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121255" severity="medium">
    <xccdf:title>RHSA-2012:1255: libexif security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libexif packages provide an Exchangeable image file format (Exif)
library. Exif allows metadata to be added to and read from certain types
of image files.

Multiple flaws were found in the way libexif processed Exif tags. An
attacker could create a specially-crafted image file that, when opened in
an application linked against libexif, could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841)

Red Hat would like to thank Dan Fandrich for reporting these issues.
Upstream acknowledges Mateusz Jurczyk of the Google Security Team as the
original reporter of CVE-2012-2812, CVE-2012-2813, and CVE-2012-2814; and
Yunho Kim as the original reporter of CVE-2012-2836 and CVE-2012-2837.

Users of libexif are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications linked against libexif must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2836</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121255"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121256" severity="medium">
    <xccdf:title>RHSA-2012:1256: ghostscript security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in Ghostscript's International Color Consortium Format library
(icclib). An attacker could create a specially-crafted PostScript or PDF
file with embedded images that would cause Ghostscript to crash or,
potentially, execute arbitrary code with the privileges of the user running
Ghostscript. (CVE-2012-4405)

Red Hat would like to thank Marc Schönefeld for reporting this issue.

Users of Ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1256</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4405</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121256"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121258" severity="medium">
    <xccdf:title>RHSA-2012:1258: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol. The Quagga
ospfd and ospf6d daemons implement the OSPF (Open Shortest Path First)
routing protocol.

A heap-based buffer overflow flaw was found in the way the bgpd daemon
processed malformed Extended Communities path attributes. An attacker could
send a specially-crafted BGP message, causing bgpd on a target system to
crash or, possibly, execute arbitrary code with the privileges of the user
running bgpd. The UPDATE message would have to arrive from an explicitly
configured BGP peer, but could have originated elsewhere in the BGP
network. (CVE-2011-3327)

A NULL pointer dereference flaw was found in the way the bgpd daemon
processed malformed route Extended Communities attributes. A configured
BGP peer could crash bgpd on a target system via a specially-crafted BGP
message. (CVE-2010-1674)

A stack-based buffer overflow flaw was found in the way the ospf6d daemon
processed malformed Link State Update packets. An OSPF router could use
this flaw to crash ospf6d on an adjacent router. (CVE-2011-3323)

A flaw was found in the way the ospf6d daemon processed malformed link
state advertisements. An OSPF neighbor could use this flaw to crash
ospf6d on a target system. (CVE-2011-3324)

A flaw was found in the way the ospfd daemon processed malformed Hello
packets. An OSPF neighbor could use this flaw to crash ospfd on a
target system. (CVE-2011-3325)

A flaw was found in the way the ospfd daemon processed malformed link state
advertisements. An OSPF router in the autonomous system could use this flaw
to crash ospfd on a target system. (CVE-2011-3326)

An assertion failure was found in the way the ospfd daemon processed
certain Link State Update packets. An OSPF router could use this flaw to
cause ospfd on an adjacent router to abort. (CVE-2012-0249)

A buffer overflow flaw was found in the way the ospfd daemon processed
certain Link State Update packets. An OSPF router could use this flaw to
crash ospfd on an adjacent router. (CVE-2012-0250)

Red Hat would like to thank CERT-FI for reporting CVE-2011-3327,
CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326; and the
CERT/CC for reporting CVE-2012-0249 and CVE-2012-0250. CERT-FI acknowledges
Riku Hietamäki, Tuomo Untinen and Jukka Taimisto of the Codenomicon CROSS
project as the original reporters of CVE-2011-3327, CVE-2011-3323,
CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326. The CERT/CC acknowledges
Martin Winter at OpenSourceRouting.org as the original reporter of
CVE-2012-0249 and CVE-2012-0250.

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd, ospfd, and ospf6d daemons will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0250</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121258"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121259" severity="medium">
    <xccdf:title>RHSA-2012:1259: quagga security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol. The Quagga
ospfd and ospf6d daemons implement the OSPF (Open Shortest Path First)
routing protocol.

A heap-based buffer overflow flaw was found in the way the bgpd daemon
processed malformed Extended Communities path attributes. An attacker could
send a specially-crafted BGP message, causing bgpd on a target system to
crash or, possibly, execute arbitrary code with the privileges of the user
running bgpd. The UPDATE message would have to arrive from an explicitly
configured BGP peer, but could have originated elsewhere in the BGP
network. (CVE-2011-3327)

A stack-based buffer overflow flaw was found in the way the ospf6d daemon
processed malformed Link State Update packets. An OSPF router could use
this flaw to crash ospf6d on an adjacent router. (CVE-2011-3323)

A flaw was found in the way the ospf6d daemon processed malformed link
state advertisements. An OSPF neighbor could use this flaw to crash
ospf6d on a target system. (CVE-2011-3324)

A flaw was found in the way the ospfd daemon processed malformed Hello
packets. An OSPF neighbor could use this flaw to crash ospfd on a
target system. (CVE-2011-3325)

A flaw was found in the way the ospfd daemon processed malformed link state
advertisements. An OSPF router in the autonomous system could use this flaw
to crash ospfd on a target system. (CVE-2011-3326)

An assertion failure was found in the way the ospfd daemon processed
certain Link State Update packets. An OSPF router could use this flaw to
cause ospfd on an adjacent router to abort. (CVE-2012-0249)

A buffer overflow flaw was found in the way the ospfd daemon processed
certain Link State Update packets. An OSPF router could use this flaw to
crash ospfd on an adjacent router. (CVE-2012-0250)

Two flaws were found in the way the bgpd daemon processed certain BGP OPEN
messages. A configured BGP peer could cause bgpd on a target system to
abort via a specially-crafted BGP OPEN message. (CVE-2012-0255,
CVE-2012-1820)

Red Hat would like to thank CERT-FI for reporting CVE-2011-3327,
CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326; and the
CERT/CC for reporting CVE-2012-0249, CVE-2012-0250, CVE-2012-0255, and
CVE-2012-1820. CERT-FI acknowledges Riku Hietamäki, Tuomo Untinen and Jukka
Taimisto of the Codenomicon CROSS project as the original reporters of
CVE-2011-3327, CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and
CVE-2011-3326. The CERT/CC acknowledges Martin Winter at
OpenSourceRouting.org as the original reporter of CVE-2012-0249,
CVE-2012-0250, and CVE-2012-0255, and Denis Ovsienko as the original
reporter of CVE-2012-1820.

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd, ospfd, and ospf6d daemons will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1259</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3324</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0250</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1820</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121259"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121261" severity="medium">
    <xccdf:title>RHSA-2012:1261: dbus security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

It was discovered that the D-Bus library honored environment settings even
when running with elevated privileges. A local attacker could possibly use
this flaw to escalate their privileges, by setting specific environment
variables before running a setuid or setgid application linked against the
D-Bus library (libdbus). (CVE-2012-3524)

Note: With this update, libdbus ignores environment variables when used by
setuid or setgid applications. The environment is not ignored when an
application gains privileges via file system capabilities; however, no
application shipped in Red Hat Enterprise Linux 6 gains privileges via file
system capabilities.

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
reporting this issue.

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1261</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3524</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121261"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121263" severity="medium">
    <xccdf:title>RHSA-2012:1263: postgresql and postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

It was found that the optional PostgreSQL xml2 contrib module allowed local
files and remote URLs to be read and written to with the privileges of the
database server when parsing Extensible Stylesheet Language Transformations
(XSLT). An unprivileged database user could use this flaw to read and write
to local files (such as the database's configuration files) and remote URLs
they would otherwise not have access to by issuing a specially-crafted SQL
query. (CVE-2012-3488)

It was found that the "xml" data type allowed local files and remote URLs
to be read with the privileges of the database server to resolve DTD and
entity references in the provided XML. An unprivileged database user could
use this flaw to read local files they would otherwise not have access to
by issuing a specially-crafted SQL query. Note that the full contents of
the files were not returned, but portions could be displayed to the user
via error messages. (CVE-2012-3489)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Peter Eisentraut as the original reporter of
CVE-2012-3488, and Noah Misch as the original reporter of CVE-2012-3489.

These updated packages upgrade PostgreSQL to version 8.4.13. Refer to the
PostgreSQL Release Notes for a list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-13.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3489</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121263"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121264" severity="medium">
    <xccdf:title>RHSA-2012:1264: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

It was found that the optional PostgreSQL xml2 contrib module allowed local
files and remote URLs to be read and written to with the privileges of the
database server when parsing Extensible Stylesheet Language Transformations
(XSLT). An unprivileged database user could use this flaw to read and write
to local files (such as the database's configuration files) and remote URLs
they would otherwise not have access to by issuing a specially-crafted SQL
query. (CVE-2012-3488)

Red Hat would like to thank the PostgreSQL project for reporting this
issue. Upstream acknowledges Peter Eisentraut as the original reporter.

All PostgreSQL users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1264</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3488</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121264"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121265" severity="high">
    <xccdf:title>RHSA-2012:1265: libxslt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libxslt is a library for transforming XML files into other textual formats
(including HTML, plain text, and other XML representations of the
underlying data) using the standard XSLT stylesheet transformation
mechanism.

A heap-based buffer overflow flaw was found in the way libxslt applied
templates to nodes selected by certain namespaces. An attacker could use
this flaw to create a malicious XSL file that, when used by an application
linked against libxslt to perform an XSL transformation, could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2012-2871)

Several denial of service flaws were found in libxslt. An attacker could
use these flaws to create a malicious XSL file that, when used by an
application linked against libxslt to perform an XSL transformation, could
cause the application to crash. (CVE-2012-2825, CVE-2012-2870,
CVE-2011-3970)

An information leak could occur if an application using libxslt processed
an untrusted XPath expression, or used a malicious XSL file to perform an
XSL transformation. If combined with other flaws, this leak could possibly
help an attacker bypass intended memory corruption protections.
(CVE-2011-1202)

All libxslt users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications linked against libxslt must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1265</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3970</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2893</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121265"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121266" severity="high">
    <xccdf:title>RHSA-2012:1266: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled resource records with a large
RDATA value. A malicious owner of a DNS domain could use this flaw to
create specially-crafted DNS resource records, that would cause a recursive
resolver or secondary server to exit unexpectedly with an assertion
failure. (CVE-2012-4244)

Users of bind97 are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121266"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121267" severity="high">
    <xccdf:title>RHSA-2012:1267: bind security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled resource records with a large
RDATA value. A malicious owner of a DNS domain could use this flaw to
create specially-crafted DNS resource records, that would cause a recursive
resolver or secondary server to exit unexpectedly with an assertion
failure. (CVE-2012-4244)

This update also fixes the following bug:

* The bind-chroot-admin script, executed when upgrading the bind-chroot
package, failed to correctly update the permissions of the
/var/named/chroot/etc/named.conf file. Depending on the permissions of the
file, this could have prevented named from starting after installing
package updates. With this update, bind-chroot-admin correctly updates the
permissions and ownership of the file. (BZ#857056)

Users of bind are advised to upgrade to these updated packages, which
correct these issues. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1267</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121267"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121268" severity="high">
    <xccdf:title>RHSA-2012:1268: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled resource records with a large
RDATA value. A malicious owner of a DNS domain could use this flaw to
create specially-crafted DNS resource records, that would cause a recursive
resolver or secondary server to exit unexpectedly with an assertion
failure. (CVE-2012-4244)

Users of bind are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1268</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121268"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121269" severity="medium">
    <xccdf:title>RHSA-2012:1269: qpid security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Qpid is a reliable, cross-platform, asynchronous messaging system
that supports the Advanced Message Queuing Protocol (AMQP) in several
common programming languages.

It was discovered that the Qpid daemon (qpidd) did not allow the number of
connections from clients to be restricted. A malicious client could use
this flaw to open an excessive amount of connections, preventing other
legitimate clients from establishing a connection to qpidd. (CVE-2012-2145)

To address CVE-2012-2145, new qpidd configuration options were introduced:
max-negotiate-time defines the time during which initial protocol
negotiation must succeed, connection-limit-per-user and
connection-limit-per-ip can be used to limit the number of connections per
user and client host IP. Refer to the qpidd manual page for additional
details.

In addition, the qpid-cpp, qpid-qmf, qpid-tools, and python-qpid packages
have been upgraded to upstream version 0.14, which provides support for Red
Hat Enterprise MRG 2.2, as well as a number of bug fixes and enhancements
over the previous version. (BZ#840053, BZ#840055, BZ#840056, BZ#840058)

All users of qpid are advised to upgrade to these updated packages, which
fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1269</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2145</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121269"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121283" severity="high">
    <xccdf:title>RHSA-2012:1283: openjpeg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenJPEG is an open source library for reading and writing image files in
JPEG 2000 format.

It was found that OpenJPEG failed to sanity-check an image header field
before using it. A remote attacker could provide a specially-crafted image
file that could cause an application linked against OpenJPEG to crash or,
possibly, execute arbitrary code. (CVE-2012-3535)

This issue was discovered by Huzaifa Sidhpurwala of the Red Hat Security
Response Team.

Users of OpenJPEG should upgrade to these updated packages, which contain
a patch to correct this issue. All running applications using OpenJPEG
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3535</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121283"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121284" severity="medium">
    <xccdf:title>RHSA-2012:1284: spice-gtk security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The spice-gtk packages provide a GIMP Toolkit (GTK+) widget for SPICE
(Simple Protocol for Independent Computing Environments) clients. Both
Virtual Machine Manager and Virtual Machine Viewer can make use of this
widget to access virtual machines using the SPICE protocol.

It was discovered that the spice-gtk setuid helper application,
spice-client-glib-usb-acl-helper, did not clear the environment variables
read by the libraries it uses. A local attacker could possibly use this
flaw to escalate their privileges by setting specific environment variables
before running the helper application. (CVE-2012-4425)

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
reporting this issue.

All users of spice-gtk are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1284</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4425</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121284"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121288" severity="medium">
    <xccdf:title>RHSA-2012:1288: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way libxml2 handled documents that enable entity
expansion. A remote attacker could provide a large, specially-crafted XML
file that, when opened in an application linked against libxml2, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-2807)

A one byte buffer overflow was found in the way libxml2 evaluated certain
parts of XML Pointer Language (XPointer) expressions. A remote attacker
could provide a specially-crafted XML file that, when opened in an
application linked against libxml2, would cause the application to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3102)

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2807</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121288"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121304" severity="medium">
    <xccdf:title>RHSA-2012:1304: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer overflow flaw was found in the i915_gem_do_execbuffer()
function in the Intel i915 driver in the Linux kernel. A local,
unprivileged user could use this flaw to cause a denial of service. This
issue only affected 32-bit systems. (CVE-2012-2384, Moderate)

* A memory leak flaw was found in the way the Linux kernel's memory
subsystem handled resource clean up in the mmap() failure path when the
MAP_HUGETLB flag was set. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2390, Moderate)

* A race condition was found in the way access to inet-&gt;opt ip_options was
synchronized in the Linux kernel's TCP/IP protocol suite implementation.
Depending on the network facing applications running on the system, a
remote attacker could possibly trigger this flaw to cause a denial of
service. A local, unprivileged user could use this flaw to cause a denial
of service regardless of the applications the system runs. (CVE-2012-3552,
Moderate)

* A flaw was found in the way the Linux kernel's dl2k driver, used by
certain D-Link Gigabit Ethernet adapters, restricted IOCTLs. A local,
unprivileged user could use this flaw to issue potentially harmful IOCTLs,
which could cause Ethernet adapters using the dl2k driver to malfunction
(for example, losing network connectivity). (CVE-2012-2313, Low)

* A flaw was found in the way the msg_namelen variable in the rds_recvmsg()
function of the Linux kernel's Reliable Datagram Sockets (RDS) protocol
implementation was initialized. A local, unprivileged user could use this
flaw to leak kernel stack memory to user-space. (CVE-2012-3430, Low)

Red Hat would like to thank Hafid Lin for reporting CVE-2012-3552, and
Stephan Mueller for reporting CVE-2012-2313. The CVE-2012-3430 issue was
discovered by the Red Hat InfiniBand team.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2390</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3552</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121304"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121323" severity="high">
    <xccdf:title>RHSA-2012:1323: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way socket buffers (skb) requiring TSO (TCP
segment offloading) were handled by the sfc driver. If the skb did not fit
within the minimum-size of the transmission queue, the network card could
repeatedly reset itself. A remote attacker could use this flaw to cause a
denial of service. (CVE-2012-3412, Important)

* A use-after-free flaw was found in the xacct_add_tsk() function in the
Linux kernel's taskstats subsystem. A local, unprivileged user could use
this flaw to cause an information leak or a denial of service.
(CVE-2012-3510, Moderate)

* A buffer overflow flaw was found in the hfs_bnode_read() function in the
HFS Plus (HFS+) file system implementation in the Linux kernel. A local
user able to mount a specially-crafted HFS+ file system image could use
this flaw to cause a denial of service or escalate their privileges.
(CVE-2012-2319, Low)

* A flaw was found in the way the msg_namelen variable in the rds_recvmsg()
function of the Linux kernel's Reliable Datagram Sockets (RDS) protocol
implementation was initialized. A local, unprivileged user could use this
flaw to leak kernel stack memory to user-space. (CVE-2012-3430, Low)

Red Hat would like to thank Ben Hutchings of Solarflare (tm) for reporting
CVE-2012-3412, and Alexander Peslyak for reporting CVE-2012-3510. The
CVE-2012-3430 issue was discovered by the Red Hat InfiniBand team.

This update also fixes the following bugs:

* The cpuid_whitelist() function, masking the Enhanced Intel SpeedStep
(EST) flag from all guests, prevented the "cpuspeed" service from working
in the privileged Xen domain (dom0). CPU scaling was therefore not
possible. With this update, cpuid_whitelist() is aware whether the domain
executing CPUID is privileged or not, and enables the EST flag for dom0.
(BZ#846125)

* If a delayed-allocation write was performed before quota was enabled,
the kernel displayed the following warning message:

    WARNING: at fs/quota/dquot.c:988 dquot_claim_space+0x77/0x112()

This was because information about the delayed allocation was not recorded
in the quota structure. With this update, writes prior to enabling quota
are properly accounted for, and the message is not displayed. (BZ#847326)

* In Red Hat Enterprise Linux 5.9, the DSCP (Differentiated Services Code
Point) netfilter module now supports mangling of the DSCP field.
(BZ#847327)

* Some subsystems clear the TIF_SIGPENDING flag during error handling in
fork() paths. Previously, if the flag was cleared, the ERESTARTNOINTR error
code could be returned. The underlying source code has been modified so
that the error code is no longer returned. (BZ#847359)

* An unnecessary check for the RXCW.CW bit could cause the Intel e1000e NIC
(Network Interface Controller) to not work properly. The check has been
removed so that the Intel e1000e NIC works as expected. (BZ#852448)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2319</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3510</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121326" severity="medium">
    <xccdf:title>RHSA-2012:1326: freeradius security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.

A buffer overflow flaw was discovered in the way radiusd handled the
expiration date field in X.509 client certificates. A remote attacker could
possibly use this flaw to crash radiusd if it were configured to use the
certificate or TLS tunnelled authentication methods (such as EAP-TLS,
EAP-TTLS, and PEAP). (CVE-2012-3547)

Red Hat would like to thank Timo Warns of PRESENSE Technologies GmbH for
reporting this issue.

Users of FreeRADIUS are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, radiusd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121326"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121327" severity="medium">
    <xccdf:title>RHSA-2012:1327: freeradius2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.

A buffer overflow flaw was discovered in the way radiusd handled the
expiration date field in X.509 client certificates. A remote attacker could
possibly use this flaw to crash radiusd if it were configured to use the
certificate or TLS tunnelled authentication methods (such as EAP-TLS,
EAP-TTLS, and PEAP). (CVE-2012-3547)

Red Hat would like to thank Timo Warns of PRESENSE Technologies GmbH for
reporting this issue.

Users of FreeRADIUS are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, radiusd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121350" severity="high">
    <xccdf:title>RHSA-2012:1350: firefox security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-3982, CVE-2012-3988, CVE-2012-3990, CVE-2012-3995,
CVE-2012-4179, CVE-2012-4180, CVE-2012-4181, CVE-2012-4182, CVE-2012-4183,
CVE-2012-4185, CVE-2012-4186, CVE-2012-4187, CVE-2012-4188)

Two flaws in Firefox could allow a malicious website to bypass intended
restrictions, possibly leading to information disclosure, or Firefox
executing arbitrary code. Note that the information disclosure issue could
possibly be combined with other flaws to achieve arbitrary code execution.
(CVE-2012-3986, CVE-2012-3991)

Multiple flaws were found in the location object implementation in Firefox.
Malicious content could be used to perform cross-site scripting attacks,
script injection, or spoofing attacks. (CVE-2012-1956, CVE-2012-3992,
CVE-2012-3994)

Two flaws were found in the way Chrome Object Wrappers were implemented.
Malicious content could be used to perform cross-site scripting attacks or
cause Firefox to execute arbitrary code. (CVE-2012-3993, CVE-2012-4184)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.8 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Jesse Ruderman, Soroush Dalili,
miaubiz, Abhishek Arya, Atte Kettunen, Johnny Stenback, Alice White,
moz_bug_r_a4, and Mariusz Mlynski as the original reporters of these
issues.

This update also fixes the following bug:

* In certain environments, storing personal Firefox configuration files
(~/.mozilla/) on an NFS share, such as when your home directory is on a
NFS share, led to Firefox functioning incorrectly, for example, navigation
buttons not working as expected, and bookmarks not saving. This update
adds a new configuration option, storage.nfs_filesystem, that can be used
to resolve this issue.

If you experience this issue:

1) Start Firefox.

2) Type "about:config" (without quotes) into the URL bar and press the
Enter key.

3) If prompted with "This might void your warranty!", click the "I'll be
careful, I promise!" button.

4) Right-click in the Preference Name list. In the menu that opens, select
New -&gt; Boolean.

5) Type "storage.nfs_filesystem" (without quotes) for the preference name
and then click the OK button.

6) Select "true" for the boolean value and then press the OK button.
(BZ#809571, BZ#816234)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.8 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1350</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3993</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4187</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121350"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121351" severity="high">
    <xccdf:title>RHSA-2012:1351: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2012-3982,
CVE-2012-3988, CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,
CVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,
CVE-2012-4187, CVE-2012-4188)

Two flaws in Thunderbird could allow malicious content to bypass intended
restrictions, possibly leading to information disclosure, or Thunderbird
executing arbitrary code. Note that the information disclosure issue could
possibly be combined with other flaws to achieve arbitrary code execution.
(CVE-2012-3986, CVE-2012-3991)

Multiple flaws were found in the location object implementation in
Thunderbird. Malicious content could be used to perform cross-site
scripting attacks, script injection, or spoofing attacks. (CVE-2012-1956,
CVE-2012-3992, CVE-2012-3994)

Two flaws were found in the way Chrome Object Wrappers were implemented.
Malicious content could be used to perform cross-site scripting attacks or
cause Thunderbird to execute arbitrary code. (CVE-2012-3993, CVE-2012-4184)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Jesse Ruderman, Soroush Dalili,
miaubiz, Abhishek Arya, Atte Kettunen, Johnny Stenback, Alice White,
moz_bug_r_a4, and Mariusz Mlynski as the original reporters of these
issues.

Note: None of the issues in this advisory can be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.8 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3993</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3994</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4187</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121351"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121359" severity="medium">
    <xccdf:title>RHSA-2012:1359: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

A flaw was found in libvirtd's RPC call handling. An attacker able to
establish a read-only connection to libvirtd could use this flaw to crash
libvirtd by sending an RPC message that has an event as the RPC number, or
an RPC number that falls into a gap in the RPC dispatch table.
(CVE-2012-4423)

This issue was discovered by Wenlong Huang of the Red Hat Virtualization QE
Team.

This update also fixes the following bugs:

* When the host_uuid option was present in the libvirtd.conf file, the
augeas libvirt lens was unable to parse the file. This bug has been fixed
and the augeas libvirt lens now parses libvirtd.conf as expected in the
described scenario. (BZ#858988)

* Disk hot plug is a two-part action: the qemuMonitorAddDrive() call is
followed by the qemuMonitorAddDevice() call. When the first part succeeded
but the second one failed, libvirt failed to roll back the first part and
the device remained in use even though the disk hot plug failed. With this
update, the rollback for the drive addition is properly performed in the
described scenario and disk hot plug now works as expected. (BZ#859376)

* When a virtual machine was started with an image chain using block
devices and a block rebase operation was issued, the operation failed on
completion in the blockJobAbort() function. This update relabels and
configures cgroups for the backing files and the rebase operation now
succeeds. (BZ#860720)

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1359</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4423</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121359"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121361" severity="high">
    <xccdf:title>RHSA-2012:1361: xulrunner security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>XULRunner provides the XUL Runtime environment for applications using the
Gecko layout engine.

A flaw was found in the way XULRunner handled security wrappers. A web page
containing malicious content could possibly cause an application linked
against XULRunner (such as Mozilla Firefox) to execute arbitrary code with
the privileges of the user running the application. (CVE-2012-4193)

For technical details regarding this flaw, refer to the Mozilla security
advisories. You can find a link to the Mozilla advisories in the References
section of this erratum.

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges moz_bug_r_a4 as the original reporter.

All XULRunner users should upgrade to these updated packages, which correct
this issue. After installing the update, applications using XULRunner must
be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1361</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121361"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121362" severity="high">
    <xccdf:title>RHSA-2012:1362: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled security wrappers.
Malicious content could cause Thunderbird to execute arbitrary code with
the privileges of the user running Thunderbird. (CVE-2012-4193)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges moz_bug_r_a4 as the original reporter.

Note: This issue cannot be exploited by a specially-crafted HTML mail
message as JavaScript is disabled by default for mail messages. It could be
exploited another way in Thunderbird, for example, when viewing the full
remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
corrects this issue. After installing the update, Thunderbird must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1362</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4193</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121362"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121363" severity="high">
    <xccdf:title>RHSA-2012:1363: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled certain combinations of resource
records. A remote attacker could use this flaw to cause a recursive
resolver, or an authoritative server in certain configurations, to lockup.
(CVE-2012-5166)

Users of bind are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1363</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5166</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121363"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121364" severity="high">
    <xccdf:title>RHSA-2012:1364: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled certain combinations of resource
records. A remote attacker could use this flaw to cause a recursive
resolver, or an authoritative server in certain configurations, to lockup.
(CVE-2012-5166)

Users of bind97 are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5166</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121364"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121366" severity="high">
    <xccdf:title>RHSA-2012:1366: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the way socket buffers (skb) requiring TSO (TCP
segment offloading) were handled by the sfc driver. If the skb did not fit
within the minimum-size of the transmission queue, the network card could
repeatedly reset itself. A remote attacker could use this flaw to cause a
denial of service. (CVE-2012-3412, Important)

Red Hat would like to thank Ben Hutchings of Solarflare (tm) for reporting
this issue.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1366</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121366"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121384" severity="high">
    <xccdf:title>RHSA-2012:1384: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the Beans,
Swing, and JMX components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2012-5086, CVE-2012-5084, CVE-2012-5089)

Multiple improper permission check issues were discovered in the Scripting,
JMX, Concurrency, Libraries, and Security components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2012-5068, CVE-2012-5071,
CVE-2012-5069, CVE-2012-5073, CVE-2012-5072)

It was discovered that java.util.ServiceLoader could create an instance of
an incompatible class while performing provider lookup. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2012-5079)

It was discovered that the Java Secure Socket Extension (JSSE) SSL/TLS
implementation did not properly handle handshake records containing an
overly large data length value. An unauthenticated, remote attacker could
possibly use this flaw to cause an SSL/TLS server to terminate with an
exception. (CVE-2012-5081)

It was discovered that the JMX component in OpenJDK could perform certain
actions in an insecure manner. An untrusted Java application or applet
could possibly use this flaw to disclose sensitive information.
(CVE-2012-5075)

A bug in the Java HotSpot Virtual Machine optimization code could cause it
to not perform array initialization in certain cases. An untrusted Java
application or applet could use this flaw to disclose portions of the
virtual machine's memory. (CVE-2012-4416)

It was discovered that the SecureRandom class did not properly protect
against the creation of multiple seeders. An untrusted Java application or
applet could possibly use this flaw to disclose sensitive information.
(CVE-2012-5077)

It was discovered that the java.io.FilePermission class exposed the hash
code of the canonicalized path name. An untrusted Java application or
applet could possibly use this flaw to determine certain system paths, such
as the current working directory. (CVE-2012-3216)

This update disables Gopher protocol support in the java.net package by
default. Gopher support can be enabled by setting the newly introduced
property, "jdk.net.registerGopherProtocol", to true. (CVE-2012-5085)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.5. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5089</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121384"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121385" severity="high">
    <xccdf:title>RHSA-2012:1385: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the Beans,
Swing, and JMX components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2012-5086, CVE-2012-5084, CVE-2012-5089)

Multiple improper permission check issues were discovered in the Scripting,
JMX, Concurrency, Libraries, and Security components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2012-5068, CVE-2012-5071,
CVE-2012-5069, CVE-2012-5073, CVE-2012-5072)

It was discovered that java.util.ServiceLoader could create an instance of
an incompatible class while performing provider lookup. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2012-5079)

It was discovered that the Java Secure Socket Extension (JSSE) SSL/TLS
implementation did not properly handle handshake records containing an
overly large data length value. An unauthenticated, remote attacker could
possibly use this flaw to cause an SSL/TLS server to terminate with an
exception. (CVE-2012-5081)

It was discovered that the JMX component in OpenJDK could perform certain
actions in an insecure manner. An untrusted Java application or applet
could possibly use this flaw to disclose sensitive information.
(CVE-2012-5075)

A bug in the Java HotSpot Virtual Machine optimization code could cause it
to not perform array initialization in certain cases. An untrusted Java
application or applet could use this flaw to disclose portions of the
virtual machine's memory. (CVE-2012-4416)

It was discovered that the SecureRandom class did not properly protect
against the creation of multiple seeders. An untrusted Java application or
applet could possibly use this flaw to disclose sensitive information.
(CVE-2012-5077)

It was discovered that the java.io.FilePermission class exposed the hash
code of the canonicalized path name. An untrusted Java application or
applet could possibly use this flaw to determine certain system paths, such
as the current working directory. (CVE-2012-3216)

This update disables Gopher protocol support in the java.net package by
default. Gopher support can be enabled by setting the newly introduced
property, "jdk.net.registerGopherProtocol", to true. (CVE-2012-5085)

This erratum also upgrades the OpenJDK package to IcedTea6 1.10.10. Refer
to the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5089</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121385"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121386" severity="high">
    <xccdf:title>RHSA-2012:1386: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple improper permission check issues were discovered in the Beans,
Libraries, Swing, and JMX components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2012-5086, CVE-2012-5087, CVE-2012-5088, CVE-2012-5084,
CVE-2012-5089)

The default Java security properties configuration did not restrict access
to certain com.sun.org.glassfish packages. An untrusted Java application
or applet could use these flaws to bypass Java sandbox restrictions. This
update lists those packages as restricted. (CVE-2012-5076, CVE-2012-5074)

Multiple improper permission check issues were discovered in the Scripting,
JMX, Concurrency, Libraries, and Security components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2012-5068, CVE-2012-5071,
CVE-2012-5069, CVE-2012-5073, CVE-2012-5072)

It was discovered that java.util.ServiceLoader could create an instance of
an incompatible class while performing provider lookup. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2012-5079)

It was discovered that the Java Secure Socket Extension (JSSE) SSL/TLS
implementation did not properly handle handshake records containing an
overly large data length value. An unauthenticated, remote attacker could
possibly use this flaw to cause an SSL/TLS server to terminate with an
exception. (CVE-2012-5081)

It was discovered that the JMX component in OpenJDK could perform certain
actions in an insecure manner. An untrusted Java application or applet
could possibly use these flaws to disclose sensitive information.
(CVE-2012-5070, CVE-2012-5075)

A bug in the Java HotSpot Virtual Machine optimization code could cause it
to not perform array initialization in certain cases. An untrusted Java
application or applet could use this flaw to disclose portions of the
virtual machine's memory. (CVE-2012-4416)

It was discovered that the SecureRandom class did not properly protect
against the creation of multiple seeders. An untrusted Java application or
applet could possibly use this flaw to disclose sensitive information.
(CVE-2012-5077)

It was discovered that the java.io.FilePermission class exposed the hash
code of the canonicalized path name. An untrusted Java application or
applet could possibly use this flaw to determine certain system paths, such
as the current working directory. (CVE-2012-3216)

This update disables Gopher protocol support in the java.net package by
default. Gopher support can be enabled by setting the newly introduced
property, "jdk.net.registerGopherProtocol", to true. (CVE-2012-5085)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.3. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5070</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5076</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5084</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5089</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121386"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121407" severity="high">
    <xccdf:title>RHSA-2012:1407: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Multiple flaws were found in the location object implementation in Firefox.
Malicious content could be used to perform cross-site scripting attacks,
bypass the same-origin policy, or cause Firefox to execute arbitrary code.
(CVE-2012-4194, CVE-2012-4195, CVE-2012-4196)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.10 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Mariusz Mlynski, moz_bug_r_a4, and Antoine
Delignat-Lavaud as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.10 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4196</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121407"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121413" severity="high">
    <xccdf:title>RHSA-2012:1413: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Multiple flaws were found in the location object implementation in
Thunderbird. Malicious content could be used to perform cross-site
scripting attacks, bypass the same-origin policy, or cause Thunderbird to
execute arbitrary code. (CVE-2012-4194, CVE-2012-4195, CVE-2012-4196)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Mariusz Mlynski, moz_bug_r_a4, and Antoine
Delignat-Lavaud as the original reporters of these issues.

Note: None of the issues in this advisory can be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.10 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4196</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121413"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121416" severity="high">
    <xccdf:title>RHSA-2012:1416: kdelibs security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdelibs packages provide libraries for the K Desktop Environment
(KDE). Konqueror is a web browser.

A heap-based buffer overflow flaw was found in the way the CSS (Cascading
Style Sheets) parser in kdelibs parsed the location of the source for font
faces. A web page containing malicious content could cause an application
using kdelibs (such as Konqueror) to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-4512)

A heap-based buffer over-read flaw was found in the way kdelibs calculated
canvas dimensions for large images. A web page containing malicious content
could cause an application using kdelibs to crash or disclose portions of
its memory. (CVE-2012-4513)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121416"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121426" severity="medium">
    <xccdf:title>RHSA-2012:1426: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A use-after-free flaw was found in the Linux kernel's memory management
subsystem in the way quota handling for huge pages was performed. A local,
unprivileged user could use this flaw to cause a denial of service or,
potentially, escalate their privileges. (CVE-2012-2133, Moderate)

* A use-after-free flaw was found in the madvise() system call
implementation in the Linux kernel. A local, unprivileged user could use
this flaw to cause a denial of service or, potentially, escalate their
privileges. (CVE-2012-3511, Moderate)

* It was found that when running a 32-bit binary that uses a large number
of shared libraries, one of the libraries would always be loaded at a
predictable address in memory. An attacker could use this flaw to bypass
the Address Space Layout Randomization (ASLR) security feature.
(CVE-2012-1568, Low)

* Buffer overflow flaws were found in the udf_load_logicalvol() function
in the Universal Disk Format (UDF) file system implementation in the Linux
kernel. An attacker with physical access to a system could use these flaws
to cause a denial of service or escalate their privileges. (CVE-2012-3400,
Low)

Red Hat would like to thank Shachar Raindel for reporting CVE-2012-2133.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2133</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3400</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3511</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121426"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121434" severity="high">
    <xccdf:title>RHSA-2012:1434: icedtea-web security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

A buffer overflow flaw was found in the IcedTea-Web plug-in. Visiting a
malicious web page could cause a web browser using the IcedTea-Web plug-in
to crash or, possibly, execute arbitrary code. (CVE-2012-4540)

Red Hat would like to thank Arthur Gerkis for reporting this issue.

This erratum also upgrades IcedTea-Web to version 1.2.2. Refer to the NEWS
file, linked to in the References, for further information.

All IcedTea-Web users should upgrade to these updated packages, which
resolve this issue. Web browsers using the IcedTea-Web browser plug-in must
be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1434</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4540</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121434"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121445" severity="low">
    <xccdf:title>RHSA-2012:1445: kernel security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that the RHSA-2010:0178 update did not correctly fix the
CVE-2009-4307 issue, a divide-by-zero flaw in the ext4 file system code. A
local, unprivileged user with the ability to mount an ext4 file system
could use this flaw to cause a denial of service. (CVE-2012-2100, Low)

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct this issue, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2100</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121445"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121455" severity="medium">
    <xccdf:title>RHSA-2012:1455: gegl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GEGL (Generic Graphics Library) is a graph-based image processing
framework.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the gegl utility processed .ppm (Portable Pixel Map) image
files. An attacker could create a specially-crafted .ppm file that, when
opened in gegl, would cause gegl to crash or, potentially, execute
arbitrary code. (CVE-2012-4433)

This issue was discovered by Murray McAllister of the Red Hat Security
Response Team.

Users of gegl should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4433</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121459" severity="low">
    <xccdf:title>RHSA-2012:1459: nspluginwrapper security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>nspluginwrapper is a utility which allows 32-bit plug-ins to run in a
64-bit browser environment (a common example is Adobe's browser plug-in for
presenting proprietary Flash files embedded in web pages). It includes the
plug-in viewer and a tool for managing plug-in installations and updates.

It was not possible for plug-ins wrapped by nspluginwrapper to discover
whether the browser was running in Private Browsing mode. This flaw could
lead to plug-ins wrapped by nspluginwrapper using normal mode while they
were expected to run in Private Browsing mode. (CVE-2011-2486)

This update also fixes the following bug:

* When using the Adobe Reader web browser plug-in provided by the
acroread-plugin package on a 64-bit system, opening Portable Document
Format (PDF) files in Firefox could cause the plug-in to crash and a black
window to be displayed where the PDF should be. Firefox had to be restarted
to resolve the issue. This update implements a workaround in
nspluginwrapper to automatically handle the plug-in crash, so that users
no longer have to keep restarting Firefox. (BZ#869554)

All users of nspluginwrapper are advised to upgrade to these updated
packages, which upgrade nspluginwrapper to upstream version 1.4.4, and
correct these issues. After installing the update, Firefox must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121461" severity="medium">
    <xccdf:title>RHSA-2012:1461: libproxy security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libproxy is a library that handles all the details of proxy configuration.

A buffer overflow flaw was found in the way libproxy handled the
downloading of proxy auto-configuration (PAC) files. A malicious server
hosting a PAC file or a man-in-the-middle attacker could use this flaw to
cause an application using libproxy to crash or, possibly, execute
arbitrary code, if the proxy settings obtained by libproxy (from the
environment or the desktop environment settings) instructed the use of a
PAC proxy configuration. (CVE-2012-4505)

This issue was discovered by the Red Hat Security Response Team.

Users of libproxy should upgrade to these updated packages, which contain
a backported patch to correct this issue. All applications using libproxy
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4505</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121461"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121462" severity="high">
    <xccdf:title>RHSA-2012:1462: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory pages, listed in the References section. (CVE-2012-1688,
CVE-2012-1690, CVE-2012-1703, CVE-2012-2749, CVE-2012-0540, CVE-2012-1689,
CVE-2012-1734, CVE-2012-3163, CVE-2012-3158, CVE-2012-3177, CVE-2012-3166,
CVE-2012-3173, CVE-2012-3150, CVE-2012-3180, CVE-2012-3167, CVE-2012-3197,
CVE-2012-3160)

These updated packages upgrade MySQL to version 5.1.66. Refer to the MySQL
release notes listed in the References section for a full list of changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3197</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121462"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121482" severity="high">
    <xccdf:title>RHSA-2012:1482: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the
XUL Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-4214, CVE-2012-4215, CVE-2012-4216, CVE-2012-5829,
CVE-2012-5830, CVE-2012-5833, CVE-2012-5835, CVE-2012-5839, CVE-2012-5840,
CVE-2012-5842)

A buffer overflow flaw was found in the way Firefox handled GIF (Graphics
Interchange Format) images. A web page containing a malicious GIF image
could cause Firefox to crash or, possibly, execute arbitrary code with the
privileges of the user running Firefox. (CVE-2012-4202)

A flaw was found in the way the Style Inspector tool in Firefox handled
certain Cascading Style Sheets (CSS). Running the tool (Tools -&gt; Web
Developer -&gt; Inspect) on malicious CSS could result in the execution of
HTML and CSS content with chrome privileges. (CVE-2012-4210)

A flaw was found in the way Firefox decoded the HZ-GB-2312 character
encoding. A web page containing malicious content could cause Firefox to
run JavaScript code with the permissions of a different website.
(CVE-2012-4207)

A flaw was found in the location object implementation in Firefox.
Malicious content could possibly use this flaw to allow restricted content
to be loaded by plug-ins. (CVE-2012-4209)

A flaw was found in the way cross-origin wrappers were implemented.
Malicious content could use this flaw to perform cross-site scripting
attacks. (CVE-2012-5841)

A flaw was found in the evalInSandbox implementation in Firefox. Malicious
content could use this flaw to perform cross-site scripting attacks.
(CVE-2012-4201)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.11 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Abhishek Arya, miaubiz, Jesse Ruderman, Andrew
McCreight, Bob Clary, Kyle Huey, Atte Kettunen, Mariusz Mlynski, Masato
Kinugawa, Bobby Holley, and moz_bug_r_a4 as the original reporters of these
issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.11 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5841</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5842</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121482"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121483" severity="high">
    <xccdf:title>RHSA-2012:1483: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2012-4214,
CVE-2012-4215, CVE-2012-4216, CVE-2012-5829, CVE-2012-5830, CVE-2012-5833,
CVE-2012-5835, CVE-2012-5839, CVE-2012-5840, CVE-2012-5842)

A buffer overflow flaw was found in the way Thunderbird handled GIF
(Graphics Interchange Format) images. Content containing a malicious GIF
image could cause Thunderbird to crash or, possibly, execute arbitrary code
with the privileges of the user running Thunderbird. (CVE-2012-4202)

A flaw was found in the way Thunderbird decoded the HZ-GB-2312 character
encoding. Malicious content could cause Thunderbird to run JavaScript code
with the permissions of different content. (CVE-2012-4207)

A flaw was found in the location object implementation in Thunderbird.
Malicious content could possibly use this flaw to allow restricted content
to be loaded by plug-ins. (CVE-2012-4209)

A flaw was found in the way cross-origin wrappers were implemented.
Malicious content could use this flaw to perform cross-site scripting
attacks. (CVE-2012-5841)

A flaw was found in the evalInSandbox implementation in Thunderbird.
Malicious content could use this flaw to perform cross-site scripting
attacks. (CVE-2012-4201)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Abhishek Arya, miaubiz, Jesse Ruderman, Andrew
McCreight, Bob Clary, Kyle Huey, Atte Kettunen, Masato Kinugawa, Mariusz
Mlynski, Bobby Holley, and moz_bug_r_a4 as the original reporters of
these issues.

Note: All issues except CVE-2012-4202 cannot be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.11 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4202</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5841</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5842</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121483"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121512" severity="high">
    <xccdf:title>RHSA-2012:1512: libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A heap-based buffer underflow flaw was found in the way libxml2 decoded
certain entities. A remote attacker could provide a specially-crafted XML
file that, when opened in an application linked against libxml2, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-5134)

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5134</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121512"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121540" severity="high">
    <xccdf:title>RHSA-2012:1540: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages contain the Linux kernel.

Security fixes:

* A race condition in the way asynchronous I/O and fallocate() interacted
when using ext4 could allow a local, unprivileged user to obtain random
data from a deleted file. (CVE-2012-4508, Important)

* A flaw in the way the Xen hypervisor implementation range checked guest
provided addresses in the XENMEM_exchange hypercall could allow a
malicious, para-virtualized guest administrator to crash the hypervisor or,
potentially, escalate their privileges, allowing them to execute arbitrary
code at the hypervisor level. (CVE-2012-5513, Important)

* A flaw in the Reliable Datagram Sockets (RDS) protocol implementation
could allow a local, unprivileged user to cause a denial of service.
(CVE-2012-2372, Moderate)

* A race condition in the way access to inet-&gt;opt ip_options was
synchronized in the Linux kernel's TCP/IP protocol suite implementation.
Depending on the network facing applications running on the system, a
remote attacker could possibly trigger this flaw to cause a denial of
service. A local, unprivileged user could use this flaw to cause a denial
of service regardless of the applications the system runs. (CVE-2012-3552,
Moderate)

* The Xen hypervisor implementation did not properly restrict the period
values used to initialize per VCPU periodic timers. A privileged guest user
could cause an infinite loop on the physical CPU. If the watchdog were
enabled, it would detect said loop and panic the host system.
(CVE-2012-4535, Moderate)

* A flaw in the way the Xen hypervisor implementation handled
set_p2m_entry() error conditions could allow a privileged,
fully-virtualized guest user to crash the hypervisor. (CVE-2012-4537,
Moderate)

Red Hat would like to thank Theodore Ts'o for reporting CVE-2012-4508; the
Xen project for reporting CVE-2012-5513, CVE-2012-4535, and CVE-2012-4537;
and Hafid Lin for reporting CVE-2012-3552. Upstream acknowledges Dmitry
Monakhov as the original reporter of CVE-2012-4508. CVE-2012-2372 was
discovered by Li Honggang of Red Hat.

Bug fixes:

* Previously, the interrupt handlers of the qla2xxx driver could clear
pending interrupts right after the IRQ lines were attached during system
start-up. Consequently, the kernel could miss the interrupt that reported
completion of the link initialization, and the qla2xxx driver then failed
to detect all attached LUNs. With this update, the qla2xxx driver has been
modified to no longer clear interrupt bits after attaching the IRQ lines.
The driver now correctly detects all attached LUNs as expected. (BZ#870118)

* The Ethernet channel bonding driver reported the MII (Media Independent
Interface) status of the bond interface in 802.3ad mode as being up even
though the MII status of all of the slave devices was down. This could pose
a problem if the MII status of the bond interface was used to determine if
failover should occur. With this update, the agg_device_up() function has
been added to the bonding driver, which allows the driver to report the
link status of the bond interface correctly, that is, down when all of its
slaves are down, in the 802.3ad mode. (BZ#877943)

Enhancements:

* This update backports several changes from the latest upstream version of
the bnx2x driver. The most important change, the remote-fault link
detection feature, allows the driver to periodically scan the physical link
layer for remote faults. If the physical link appears to be up and a fault
is detected, the driver indicates that the link is down. When the fault is
cleared, the driver indicates that the link is up again. (BZ#870120)

* The INET socket interface has been modified to send a warning message
when the ip_options structure is allocated directly by a third-party module
using the kmalloc() function. (BZ#874973)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add these enhancements. The system must
be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2372</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5513</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121540"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121549" severity="high">
    <xccdf:title>RHSA-2012:1549: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly. DNS64 is
used to automatically generate DNS records so IPv6 based clients can access
IPv4 systems through a NAT64 server.

A flaw was found in the DNS64 implementation in BIND. If a remote attacker
sent a specially-crafted query to a named server, named could exit
unexpectedly with an assertion failure. Note that DNS64 support is not
enabled by default. (CVE-2012-5688)

Users of bind are advised to upgrade to these updated packages, which
correct this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5688</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121549"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121551" severity="high">
    <xccdf:title>RHSA-2012:1551: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

A stack-based buffer overflow flaw was found in the user permission
checking code in MySQL. An authenticated database user could use this flaw
to crash the mysqld daemon or, potentially, execute arbitrary code with the
privileges of the user running the mysqld daemon. (CVE-2012-5611)

All MySQL users should upgrade to these updated packages, which correct
this issue. After installing this update, the MySQL server daemon (mysqld)
will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5611</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121551"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121580" severity="medium">
    <xccdf:title>RHSA-2012:1580: kernel security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the RHSA-2012:0862 update did not correctly fix the
CVE-2011-4131 issue. A malicious Network File System version 4 (NFSv4)
server could return a crafted reply to a GETACL request, causing a denial
of service on the client. (CVE-2012-2375, Moderate)

* A divide-by-zero flaw was found in the TCP Illinois congestion control
algorithm implementation in the Linux kernel. If the TCP Illinois
congestion control algorithm were in use (the sysctl
net.ipv4.tcp_congestion_control variable set to "illinois"), a local,
unprivileged user could trigger this flaw and cause a denial of service.
(CVE-2012-4565, Moderate)

* A NULL pointer dereference flaw was found in the way a new node's hot
added memory was propagated to other nodes' zonelists. By utilizing this
newly added memory from one of the remaining nodes, a local, unprivileged
user could use this flaw to cause a denial of service. (CVE-2012-5517,
Moderate)

* It was found that the initial release of Red Hat Enterprise Linux 6 did
not correctly fix the CVE-2009-4307 issue, a divide-by-zero flaw in the
ext4 file system code. A local, unprivileged user with the ability to mount
an ext4 file system could use this flaw to cause a denial of service.
(CVE-2012-2100, Low)

* A flaw was found in the way the Linux kernel's IPv6 implementation
handled overlapping, fragmented IPv6 packets. A remote attacker could
potentially use this flaw to bypass protection mechanisms (such as a
firewall or intrusion detection system (IDS)) when sending network packets
to a target system. (CVE-2012-4444, Low)

Red Hat would like to thank Antonios Atlasis working with Beyond Security's
SecuriTeam Secure Disclosure program and Loganaden Velvindron of AFRINIC
for reporting CVE-2012-4444. The CVE-2012-2375 issue was discovered by Jian
Li of Red Hat, and CVE-2012-4565 was discovered by Rodrigo Freire of Red
Hat.

This update also fixes numerous bugs and adds one enhancement. Space 
precludes documenting all of these changes in this advisory. Documentation
for these changes will be available shortly from the Red Hat Enterprise 
Linux 6.3 Technical Notes document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, fix these bugs and add the enhancement 
noted in the Technical Notes. The system must be rebooted for this update 
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5517</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20121590" severity="medium">
    <xccdf:title>RHSA-2012:1590: libtiff security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF images using the Pixar Log Format encoding. An attacker could
create a specially-crafted TIFF file that, when opened, could cause an
application using libtiff to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2012-4447)

A stack-based buffer overflow flaw was found in the way libtiff handled
DOTRANGE tags. An attacker could use this flaw to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2012-5581)

A heap-based buffer overflow flaw was found in the tiff2pdf tool. An
attacker could use this flaw to create a specially-crafted TIFF file that
would cause tiff2pdf to crash or, possibly, execute arbitrary code.
(CVE-2012-3401)

A missing return value check flaw, leading to a heap-based buffer overflow,
was found in the ppm2tiff tool. An attacker could use this flaw to create a
specially-crafted PPM (Portable Pixel Map) file that would cause ppm2tiff
to crash or, possibly, execute arbitrary code. (CVE-2012-4564)

The CVE-2012-5581, CVE-2012-3401, and CVE-2012-4564 issues were discovered
by Huzaifa Sidhpurwala of the Red Hat Security Response Team.

All libtiff users should upgrade to these updated packages, which contain
backported patches to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2012:1590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5581</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20121590"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130120" severity="low">
    <xccdf:title>RHSA-2013:0120: quota security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The quota package provides system administration tools for monitoring
and limiting user and group disk usage on file systems.

It was discovered that the rpc.rquotad service did not use tcp_wrappers
correctly. Certain hosts access rules defined in "/etc/hosts.allow" and
"/etc/hosts.deny" may not have been honored, possibly allowing remote
attackers to bypass intended access restrictions. (CVE-2012-3417)

This issue was discovered by the Red Hat Security Response Team.

This update also fixes the following bugs:

* Prior to this update, values were not properly transported via the remote
procedure call (RPC) and interpreted by the client when querying the quota
usage or limits for network-mounted file systems if the quota values were
2^32 kilobytes or greater. As a consequence, the client reported mangled
values. This update modifies the underlying code so that such values are
correctly interpreted by the client. (BZ#667360)

* Prior to this update, warnquota sent messages about exceeded quota limits
from a valid domain name if the warnquota tool was enabled to send warning
e-mails and the superuser did not change the default warnquota
configuration. As a consequence, the recipient could reply to invalid
addresses. This update modifies the default warnquota configuration to use
the reserved example.com. domain. Now, warnings about exceeded quota limits
are sent from the reserved domain that inform the superuser to change to
the correct value. (BZ#680429)

* Previously, quota utilities could not recognize the file system as having
quotas enabled and refused to operate on it due to incorrect updating of
/etc/mtab. This update prefers /proc/mounts to get a list of file systems
with enabled quotas. Now, quota utilities recognize file systems with
enabled quotas as expected. (BZ#689822)

* Prior to this update, the setquota(8) tool on XFS file systems failed
to set disk limits to values greater than 2^31 kilobytes. This update
modifies the integer conversion in the setquota(8) tool to use a 64-bit
variable big enough to store such values. (BZ#831520)

All users of quota are advised to upgrade to this updated package, which
contains backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0120</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3417</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130120"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130121" severity="low">
    <xccdf:title>RHSA-2013:0121: mysql security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

It was found that the fix for the CVE-2009-4030 issue, a flaw in the way
MySQL checked the paths used as arguments for the DATA DIRECTORY and INDEX
DIRECTORY directives when the "datadir" option was configured with a
relative path, was incorrectly removed when the mysql packages in Red Hat
Enterprise Linux 5 were updated to version 5.0.95 via RHSA-2012:0127. An
authenticated attacker could use this flaw to bypass the restriction
preventing the use of subdirectories of the MySQL data directory being used
as DATA DIRECTORY and INDEX DIRECTORY paths. This update re-applies the fix
for CVE-2009-4030. (CVE-2012-4452)

Note: If the use of the DATA DIRECTORY and INDEX DIRECTORY directives were
disabled as described in RHSA-2010:0109 (by adding "symbolic-links=0" to
the "[mysqld]" section of the "my.cnf" configuration file), users were not
vulnerable to this issue.

This issue was discovered by Karel Volný of the Red Hat Quality Engineering
team.

This update also fixes the following bugs:

* Prior to this update, the log file path in the logrotate script did not
behave as expected. As a consequence, the logrotate function failed to
rotate the "/var/log/mysqld.log" file. This update modifies the logrotate
script to allow rotating the mysqld.log file. (BZ#647223)

* Prior to this update, the mysqld daemon could fail when using the EXPLAIN
flag in prepared statement mode. This update modifies the underlying code
to handle the EXPLAIN flag as expected. (BZ#654000)

* Prior to this update, the mysqld init script could wrongly report that
mysql server startup failed when the server was actually started. This
update modifies the init script to report the status of the mysqld server
as expected. (BZ#703476)

* Prior to this update, the "--enable-profiling" option was by default
disabled. This update enables the profiling feature. (BZ#806365)

All MySQL users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the MySQL server daemon (mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4452</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130121"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130122" severity="medium">
    <xccdf:title>RHSA-2013:0122: tcl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Tcl (Tool Command Language) provides a powerful platform for creating
integration applications that tie together diverse applications, protocols,
devices, and frameworks. When paired with the Tk toolkit, Tcl provides a
fast and powerful way to create cross-platform GUI applications.

Two denial of service flaws were found in the Tcl regular expression
handling engine. If Tcl or an application using Tcl processed a
specially-crafted regular expression, it would lead to excessive CPU and
memory consumption. (CVE-2007-4772, CVE-2007-6067)

This update also fixes the following bug:

* Due to a suboptimal implementation of threading in the current version of
the Tcl language interpreter, an attempt to use threads in combination with
fork in a Tcl script could cause the script to stop responding. At the
moment, it is not possible to rewrite the source code or drop support for
threading entirely. Consequent to this, this update provides a version of
Tcl without threading support in addition to the standard version with this
support. Users who need to use fork in their Tcl scripts and do not require
threading can now switch to the version without threading support by using
the alternatives command. (BZ#478961)

All users of Tcl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-4772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2007-6067</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130122"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130123" severity="low">
    <xccdf:title>RHSA-2013:0123: OpenIPMI security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The OpenIPMI packages provide command line tools and utilities to access
platform information using Intelligent Platform Management Interface
(IPMI). System administrators can use OpenIPMI to manage systems and to
perform system health monitoring.

It was discovered that the IPMI event daemon (ipmievd) created its process
ID (PID) file with world-writable permissions. A local user could use this
flaw to make the ipmievd init script kill an arbitrary process when the
ipmievd daemon is stopped or restarted. (CVE-2011-4339)

Note: This issue did not affect the default configuration of OpenIPMI as
shipped with Red Hat Enterprise Linux 5.

This update also fixes the following bugs:

* Prior to this update, the ipmitool utility first checked the IPMI
hardware for Dell IPMI extensions and listed only supported commands when
printing command usage like the option "ipmtool delloem help". On a
non-Dell platform, the usage text was incomplete and misleading. This
update lists all Dell OEM extensions in usage texts on all platforms, which
allows users to check for command line arguments on non-Dell hardware.
(BZ#658762)

* Prior to this update, the ipmitool utility tried to retrieve the Sensor
Data Records (SDR) from the IPMI bus instead of the Baseboard Management
Controller (BMC) bus when IPMI-enabled devices reported SDR under a
different owner than the BMC. As a consequence, the timeout setting for the
SDR read attempt could significantly decrease the performance and no sensor
data was shown. This update modifies ipmitool to read these SDR records
from the BMC and shows the correct sensor data on these platforms.
(BZ#671059, BZ#749796)

* Prior to this update, the exit code of the "ipmitool -o list" option was
not set correctly. As a consequence, "ipmitool -o list" always returned the
value 1 instead of the expected value 0. This update modifies the
underlying code to return the value 0 as expected. (BZ#740780)

* Prior to this update, the "ipmi" service init script did not specify the
full path to the "/sbin/lsmod" and "/sbin/modprobe" system utilities. As a
consequence, the init script failed when it was executed if PATH did not
point to /sbin, for example, when running "sudo /etc/init.d/ipmi". This
update modifies the init script so that it now contains the full path to
lsmod and modrpobe. Now, it can be executed with sudo. (BZ#829705)

* Prior to this update, the ipmitool man page did not list the "-b", "-B",
"-l" and "-T" options. In this update, these options are documented in the
ipmitool man page. (BZ#846596)

This update also adds the following enhancement:

* Updates to the Dell-specific IPMI extension: A new vFlash command, which
allows users to display information about extended SD cards; a new setled
command, which allows users to display the backplane LED status; improved
error descriptions; added support for new hardware; and updated
documentation of the ipmitool delloem commands in the ipmitool manual
page. (BZ#797050)

All users of OpenIPMI are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4339</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130123"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130124" severity="medium">
    <xccdf:title>RHSA-2013:0124: net-snmp security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide various libraries and tools for the Simple Network
Management Protocol (SNMP).

An out-of-bounds buffer read flaw was found in the net-snmp agent. A remote
attacker with read privileges to a Management Information Base (MIB)
subtree handled by the "extend" directive (in "/etc/snmp/snmpd.conf") could
use this flaw to crash snmpd via a crafted SNMP GET request.
(CVE-2012-2141)

Bug fixes:

* Devices that used certain file systems were not reported in the
"HOST-RESOURCES-MIB::hrStorageTable" table. As a result, the snmpd daemon
did not recognize devices using tmpfs, ReiserFS, and Oracle Cluster File
System (OCFS2) file systems. This update recognizes these devices and
reports them in the "HOST-RESOURCES-MIB::hrStorageTable" table.
(BZ#754652, BZ#755958, BZ#822061)

* The snmptrapd (8) man page did not correctly describe how to load
multiple configuration files using the "-c" option. This update describes
correctly that multiple configuration files must be separated by a comma.
(BZ#760001)

* Integers truncated from 64 to 32-bit were not correctly evaluated. As a
consequence, the snmpd daemon could enter an endless loop when encoding the
truncated integers to network format. This update modifies the underlying
code so that snmpd correctly checks truncated 64-bit integers. Now, snmpd
avoids an endless loop. (BZ#783892)

* snmpd did not correctly check for interrupted system calls when
enumerating existing IPv6 network prefixes during startup. As a
consequence, snmpd could prematurely exit when receiving a signal during
this enumeration. This update checks the network prefix enumeration code
for interrupted system calls. Now, snmpd no longer terminates when a signal
is received. (BZ#799699)

* snmpd used the wrong length of COUNTER64 values in the AgentX protocol.
As a consequence, snmpd could not decode two consecutive COUNTER64 values
in one AgentX packet. This update uses the correct COUNTER64 size and can
process two or mode COUNTER64 values in AgentX communication. (BZ#803585)

* snmpd ignored the "-e" parameter of the "trapsess" option in the snmpd
configuration file. As a result, outgoing traps were incorrectly sent with
the default EngineID of snmpd when configuring "trapsess" with an explicit
EngineID. This update modifies the underlying code to send outgoing traps
using the EngineID as specified in the "trapsess -e" parameter in the
configuration file. (BZ#805689)

* snmpd did not correctly encode negative Request-IDs in outgoing requests,
for example during trap operations. As a consequence, a 32-bit value could
be encoded in 5 bytes instead of 4, and the outgoing requests were refused
by certain implementations of the SNMP protocol as invalid. With this
update, a Request-ID can no longer become negative and is always encoded in
4 bytes. (BZ#818259)

* snmpd ignored the port number of the "clientaddr" option when specifying
the source address of outgoing SNMP requests. As a consequence, the system
assigned a random address. This update allows to specify both the port
number and the source IP address in the "clientaddr" option. Now,
administrators can increase security with firewall rules and
Security-Enhanced Linux (SELinux) policies by configuring a specific source
port of outgoing traps and other requests. (BZ#828691)

* snmpd did not correctly process responses to internal queries when
initializing monitoring enabled by the "monitor" option in the
"/etc/snmp/snmpd.conf" configuration file. As a consequence, snmpd was not
fully initialized and the error message "failed to run mteTrigger query"
appeared in the system log 30 seconds after the snmpd startup. This update
explicitly checks for responses to internal monitoring queries. (BZ#830042)

Users of net-snmp should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the update,
the snmpd and snmptrapd daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0124</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2141</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130124"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130125" severity="medium">
    <xccdf:title>RHSA-2013:0125: wireshark security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark, previously known as Ethereal, is a network protocol analyzer. It
is used to capture and browse the traffic running on a computer network.

A heap-based buffer overflow flaw was found in the way Wireshark handled
Endace ERF (Extensible Record Format) capture files. If Wireshark opened a
specially-crafted ERF capture file, it could crash or, possibly, execute
arbitrary code as the user running Wireshark. (CVE-2011-4102)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2011-1958, CVE-2011-1959, CVE-2011-2175,
CVE-2011-2698, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066, CVE-2012-0067,
CVE-2012-4285, CVE-2012-4289, CVE-2012-4290, CVE-2012-4291)

The CVE-2011-1958, CVE-2011-1959, CVE-2011-2175, and CVE-2011-4102 issues
were discovered by Huzaifa Sidhpurwala of the Red Hat Security Response
Team.

This update also fixes the following bugs:

* When Wireshark starts with the X11 protocol being tunneled through an SSH
connection, it automatically prepares its capture filter to omit the SSH
packets. If the SSH connection was to a link-local IPv6 address including
an interface name (for example ssh -X [ipv6addr]%eth0), Wireshark parsed
this address erroneously, constructed an incorrect capture filter and
refused to capture packets. The "Invalid capture filter" message was
displayed. With this update, parsing of link-local IPv6 addresses is fixed
and Wireshark correctly prepares a capture filter to omit SSH packets over
a link-local IPv6 connection. (BZ#438473)

* Previously, Wireshark's column editing dialog malformed column names when
they were selected. With this update, the dialog is fixed and no longer
breaks column names. (BZ#493693)

* Previously, TShark, the console packet analyzer, did not properly analyze
the exit code of Dumpcap, Wireshark's packet capturing back end. As a
result, TShark returned exit code 0 when Dumpcap failed to parse its
command-line arguments. In this update, TShark correctly propagates the
Dumpcap exit code and returns a non-zero exit code when Dumpcap fails.
(BZ#580510)

* Previously, the TShark "-s" (snapshot length) option worked only for a
value greater than 68 bytes. If a lower value was specified, TShark
captured just 68 bytes of incoming packets. With this update, the "-s"
option is fixed and sizes lower than 68 bytes work as expected. (BZ#580513)

This update also adds the following enhancement:

* In this update, support for the "NetDump" protocol was added. (BZ#484999)

All users of Wireshark are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add this
enhancement. All running instances of Wireshark must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0041</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4291</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130125"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130126" severity="low">
    <xccdf:title>RHSA-2013:0126: squirrelmail security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SquirrelMail is a standards-based webmail package written in PHP.

The SquirrelMail security update RHSA-2012:0103 did not, unlike the erratum
text stated, correct the CVE-2010-2813 issue, a flaw in the way
SquirrelMail handled failed log in attempts. A user preference file was
created when attempting to log in with a password containing an 8-bit
character, even if the username was not valid. A remote attacker could use
this flaw to eventually consume all hard disk space on the target
SquirrelMail server. (CVE-2012-2124)

This update also fixes the following bugs:

* Prior to this update, SquirrelMail could not decode multi-line subjects
properly. Consequently, the decode header internationalization option did
not properly handle new lines or tabs at the beginning of the lines. This
bug has been fixed and SquirrelMail now works correctly in the described
scenario. (BZ#241861)

* Due to a bug, attachments written in HTML code on the Windows operating
system were not displayed properly when accessed with SquirrelMail; the
"!=null" string was trimmed to "!ull". This bug has been fixed and the
attachments are now displayed correctly in such a case. (BZ#359791)

* Previously, e-mail messages with a Unique Identifier (UID) larger than
2^31 bytes were unreadable when using the squirrelmail package. With this
patch the squirrelmail package is able to read all messages regardless of
the UIDs size. (BZ#450780)

* Due to a bug, a PHP script did not assign the proper character set to
requested variables. Consequently, SquirrelMail could not display any
e-mails. The underlying source code has been modified and now the
squirrelmail package assigns the correct character set. (BZ#475188)

* Due to the incorrect internationalization option located at the i18n.php
file, the squirrelmail package could not use the GB 2312 character set. The
i18n.php file has been fixed and the GB 2312 character set works correctly
in the described scenario. (BZ#508686)

* Previously, the preg_split() function contained a misspelled constant,
PREG_SPLIT_NI_EMPTY, which could cause SquirrelMail to produce error
messages. The name of the constant has been corrected to
PREG_SPLIT_NO_EMPTY, and SquirrelMail no longer produces error messages in
this scenario. (BZ#528758)

* Due to Security-Enhanced Linux (SELinux) settings, sending e-mails from
the SquirrelMail web interface was blocked. This update adds a note to the
SquirrelMail documentation that describes how to set the SELinux options to
allow sending e-mails from the SquirrelMail web interface. (BZ#745380)

* Previously, the squirrelmail package did not comply with the RFC 2822
specification about line length limits. Consequently, attachments with
lines longer than 998 characters could not be forwarded using SquirrelMail.
This patch modifies the underlying source code and now SquirrelMail
complies with the RFC 2822 specification as expected. (BZ#745469)

* Prior to this update, the squirrelmail package required the php-common
script instead of the mod_php script during installation or upgrade of the
package, which led to a dependency error. As a result, attempting to
install or upgrade the squirrelmail package failed on systems using the
php53 packages. With this update, the dependencies of the squirrelmail
package were changed and the installation or upgrade now works correctly in
the described scenario. (BZ#789353)

All users of SquirrelMail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2124</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130127" severity="low">
    <xccdf:title>RHSA-2013:0127: libvirt security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

Bus and device IDs were ignored when attempting to attach multiple USB
devices with identical vendor or product IDs to a guest. This could result
in the wrong device being attached to a guest, giving that guest root
access to the device. (CVE-2012-2693)

This update also fixes the following bugs:

* Previously, the libvirtd library failed to set the autostart flags for
already defined QEMU domains. This bug has been fixed, and the domains can
now be successfully marked as autostarted. (BZ#675319)

* Prior to this update, the virFileAbsPath() function was not taking into
account the slash ("/") directory separator when allocating memory for
combining the cwd() function and a path. This behavior could lead to a
memory corruption. With this update, a transformation to the virAsprintff()
function has been introduced into virFileAbsPath(). As a result, the
aforementioned behavior no longer occurs. (BZ#680289)

* With this update, a man page of the virsh user interface has been
enhanced with information on the "domxml-from-native" and
"domxml-to-native" commands. A correct notation of the format argument has
been clarified. As a result, confusion is avoided when setting the format
argument in the described commands. (BZ#783001)

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130127"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130128" severity="low">
    <xccdf:title>RHSA-2013:0128: conga security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Conga project is a management system for remote workstations. It
consists of luci, which is a secure web-based front end, and ricci, which
is a secure daemon that dispatches incoming messages to underlying
management modules.

It was discovered that luci stored usernames and passwords in session
cookies. This issue prevented the session inactivity timeout feature from
working correctly, and allowed attackers able to get access to a session
cookie to obtain the victim's authentication credentials. (CVE-2012-3359)

Red Hat would like to thank George Hedfors of Cybercom Sweden East AB for
reporting this issue.

This update also fixes the following bugs:

* Prior to this update, luci did not allow the fence_apc_snmp agent to be
configured. As a consequence, users could not configure or view an existing
configuration for fence_apc_snmp. This update adds a new screen that allows
fence_apc_snmp to be configured. (BZ#832181)

* Prior to this update, luci did not allow the SSL operation of the
fence_ilo fence agent to be enabled or disabled. As a consequence, users
could not configure or view an existing configuration for the 'ssl'
attribute for fence_ilo. This update adds a checkbox to show whether the
SSL operation is enabled and allows users to edit that attribute.
(BZ#832183)

* Prior to this update, luci did not allow the "identity_file" attribute of
the fence_ilo_mp fence agent to be viewed or edited. As a consequence,
users could not configure or view an existing configuration for the
"identity_file" attribute of the fence_ilo_mp fence agent. This update adds
a text input box to show the current state of the "identity_file" attribute
of fence_ilo_mp and allows users to edit that attribute. (BZ#832185)

* Prior to this update, redundant files and directories remained on the
file system at /var/lib/luci/var/pts and /usr/lib{,64}/luci/zope/var/pts
when the luci package was uninstalled. This update removes these files
and directories when the luci package is uninstalled. (BZ#835649)

* Prior to this update, the "restart-disable" recovery policy was not
displayed in the recovery policy list from which users could select when
they configure a recovery policy for a failover domain. As a consequence,
the "restart-disable" recovery policy could not be set with the luci GUI.
This update adds the "restart-disable" recovery option to the recovery
policy pulldown list. (BZ#839732)

* Prior to this update, line breaks that were not anticipated in the "yum
list" output could cause package upgrade and/or installation to fail when
creating clusters or adding nodes to existing clusters. As a consequence,
creating clusters and adding cluster nodes to existing clusters could fail.
This update modifies the ricci daemon to be able to correctly handle line
breaks in the "yum list" output. (BZ#842865)

In addition, this update adds the following enhancements:

* This update adds support for configuring the Intel iPDU fence agent to
the luci package. (BZ#741986)

* This update adds support for viewing and changing the state of the new
'nfsrestart' attribute to the FS and Cluster FS resource agent
configuration screens. (BZ#822633)

All users of conga are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements. After installing this
update, the luci and ricci services will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3359</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130128"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130129" severity="medium">
    <xccdf:title>RHSA-2013:0129: ruby security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

It was found that certain methods did not sanitize file names before
passing them to lower layer routines in Ruby. If a Ruby application created
files with names based on untrusted input, it could result in the creation
of files with different names than expected. (CVE-2012-4522)

It was found that the RHSA-2011:0909 update did not correctly fix the
CVE-2011-1005 issue, a flaw in the method for translating an exception
message into a string in the Exception class. A remote attacker could use
this flaw to bypass safe level 4 restrictions, allowing untrusted (tainted)
code to modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2012-4481)

The CVE-2012-4481 issue was discovered by Vit Ondruch of Red Hat.

This update also fixes the following bug:

* Prior to this update, the "rb_syck_mktime" option could, under certain
circumstances, terminate with a segmentation fault when installing
libraries with certain gems. This update modifies the underlying code so
that Ruby gems can be installed as expected. (BZ#834381)

All users of Ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0129</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4522</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130129"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130130" severity="low">
    <xccdf:title>RHSA-2013:0130: httpd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages contain the Apache HTTP Server (httpd), which is the
namesake project of The Apache Software Foundation.

Input sanitization flaws were found in the mod_negotiation module. A remote
attacker able to upload or create files with arbitrary names in a directory
that has the MultiViews options enabled, could use these flaws to conduct
cross-site scripting and HTTP response splitting attacks against users
visiting the site. (CVE-2008-0455, CVE-2008-0456, CVE-2012-2687)

Bug fixes:

* Previously, no check was made to see if the
/etc/pki/tls/private/localhost.key file was a valid key prior to running
the "%post" script for the "mod_ssl" package. Consequently, when
/etc/pki/tls/certs/localhost.crt did not exist and "localhost.key" was
present but invalid, upgrading the Apache HTTP Server daemon (httpd) with
mod_ssl failed. The "%post" script has been fixed to test for an existing
SSL key. As a result, upgrading httpd with mod_ssl now proceeds as
expected. (BZ#752618)

* The "mod_ssl" module did not support operation under FIPS mode.
Consequently, when operating Red Hat Enterprise Linux 5 with FIPS mode
enabled, httpd failed to start. An upstream patch has been applied to
disable non-FIPS functionality if operating under FIPS mode and httpd now
starts as expected. (BZ#773473)

* Prior to this update, httpd exit status codes were not Linux Standard
Base (LSB) compliant. When the command "service httpd reload" was run and
httpd failed, the exit status code returned was "0" and not in the range 1
to 6 as expected. A patch has been applied to the init script and httpd now
returns "1" as an exit status code. (BZ#783242)

* Chunked Transfer Coding is described in RFC 2616. Previously, the
Apache server did not correctly handle a chunked encoded POST request with
a "chunk-size" or "chunk-extension" value of 32 bytes or more.
Consequently, when such a POST request was made the server did not respond.
An upstream patch has been applied and the problem no longer occurs.
(BZ#840845)

* Due to a regression, when mod_cache received a non-cacheable 304
response, the headers were served incorrectly. Consequently, compressed
data could be returned to the client without the cached headers to indicate
the data was compressed. An upstream patch has been applied to merge
response and cached headers before data from the cache is served to the
client. As a result, cached data is now correctly interpreted by the
client. (BZ#845532)

* In a proxy configuration, certain response-line strings were not handled
correctly. If a response-line without a "description" string was received
from the origin server, for a non-standard status code, such as the "450"
status code, a "500 Internal Server Error" would be returned to the client.
This bug has been fixed so that the original response line is returned to
the client. (BZ#853128)

Enhancements:

* The configuration directive "LDAPReferrals" is now supported in addition
to the previously introduced "LDAPChaseReferrals". (BZ#727342)

* The AJP support module for "mod_proxy", "mod_proxy_ajp", now supports the
"ProxyErrorOverride" directive. Consequently, it is now possible to
configure customized error pages for web applications running on a backend
server accessed via AJP. (BZ#767890)

* The "%posttrans" scriptlet which automatically restarts the httpd service
after a package upgrade can now be disabled. If the file
/etc/sysconfig/httpd-disable-posttrans exists, the scriptlet will not
restart the daemon. (BZ#833042)

* The output of "httpd -S" now includes configured alias names for each
virtual host. (BZ#833043)

* New certificate variable names are now exposed by "mod_ssl" using the
"_DN_userID" suffix, such as "SSL_CLIENT_S_DN_userID", which use the
commonly used object identifier (OID) definition of "userID", OID
0.9.2342.19200300.100.1.1. (BZ#840036)

All users of httpd are advised to upgrade to these updated packages, which
fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0130</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2687</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130130"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130131" severity="low">
    <xccdf:title>RHSA-2013:0131: gnome-vfs2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The gnome-vfs2 packages provide the GNOME Virtual File System, which is the
foundation of the Nautilus file manager. neon is an HTTP and WebDAV client
library embedded in the gnome-vfs2 packages.

A denial of service flaw was found in the neon Extensible Markup Language
(XML) parser. Visiting a malicious DAV server with an application using
gnome-vfs2 (such as Nautilus) could possibly cause the application to
consume an excessive amount of CPU and memory. (CVE-2009-2473)

This update also fixes the following bugs:

* When extracted from the Uniform Resource Identifier (URI), gnome-vfs2
returned escaped file paths. If a path, as stored in the URI,
contained non-ASCII characters or ASCII characters which are parsed as
something other than a file path (for example, spaces), the escaped path
was inaccurate. Consequently, files with the described type of URI could
not be processed. With this update, gnome-vfs2 properly unescapes paths
that are required for a system call. As a result, these paths are parsed
properly. (BZ#580855)

* In certain cases, the trash info file was populated by foreign
entries, pointing to live data. Emptying the trash caused an accidental
deletion of valuable data. With this update, a workaround has been applied
in order to prevent the deletion. As a result, the accidental data loss is
prevented, however further information is still gathered to fully fix this
problem. (BZ#586015)

* Due to a wrong test checking for a destination file system, the Nautilus
file manager failed to delete a symbolic link to a folder which was
residing in another file system. With this update, a special test has been
added. As a result, a symbolic link pointing to another file system can be
trashed or deleted properly. (BZ#621394)

* Prior to this update, when directories without a read permission were
marked for copy, the Nautilus file manager skipped these unreadable
directories without notification. With this update, Nautilus displays an
error message and properly informs the user about the aforementioned
problem. (BZ#772307)

* Previously, gnome-vfs2 used the stat() function calls for every file on
the MultiVersion File System (MVFS), used for example by IBM Rational
ClearCase. This behavior significantly slowed down file operations. With
this update, the unnecessary stat() operations have been limited. As a
result, gnome-vfs2 user interfaces, such as Nautilus, are more responsive.
(BZ#822817)

All gnome-vfs2 users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-2473</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130131"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130132" severity="low">
    <xccdf:title>RHSA-2013:0132: autofs security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon. The
automount daemon automatically mounts and unmounts file systems.

A bug fix included in RHBA-2012:0264 introduced a denial of service flaw in
autofs. When using autofs with LDAP, a local user could use this flaw to
crash autofs, preventing future mount requests from being processed until
the autofs service was restarted. Note: This flaw did not impact existing
mounts (except for preventing mount expiration). (CVE-2012-2697)

Red Hat would like to thank Ray Rocker for reporting this issue.

This update also fixes the following bugs:

* The autofs init script sometimes timed out waiting for the automount
daemon to exit and returned a shutdown failure if the daemon failed to exit
in time. To resolve this problem, the amount of time that the init script
waits for the daemon has been increased to allow for cases where servers
are slow to respond or there are many active mounts. (BZ#585058)

* Due to an omission when backporting a change, autofs attempted to
download the entire LDAP map at startup. This mistake has now been
corrected. (BZ#767428)

* A function to check the validity of a mount location was meant to check
only for a small subset of map location errors. A recent modification in
error reporting inverted a logic test in this validating function.
Consequently, the scope of the test was widened, which caused the automount
daemon to report false positive failures. With this update, the faulty
logic test has been corrected and false positive failures no longer occur.
(BZ#798448)

* When there were many attempts to access invalid or non-existent keys, the
automount daemon used excessive CPU resources. As a consequence, systems
sometimes became unresponsive. The code has been improved so that automount
checks for invalid keys earlier in the process which has eliminated a
significant amount of the processing overhead. (BZ#847101)

* The auto.master(5) man page did not document the "-t, --timeout" option
in the FORMAT options section. This update adds this information to the man
page. (BZ#859890)

This update also adds the following enhancement:

* Previously, it was not possible to configure separate timeout values for
individual direct map entries in the autofs master map. This update adds
this functionality. (BZ#690404)

All users of autofs are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2697</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130133" severity="low">
    <xccdf:title>RHSA-2013:0133: hplip3 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Hewlett-Packard Linux Imaging and Printing (HPLIP) provides drivers for
Hewlett-Packard (HP) printers and multifunction peripherals.

It was found that the HP CUPS (Common UNIX Printing System) fax filter in
HPLIP created a temporary file in an insecure way. A local attacker could
use this flaw to perform a symbolic link attack, overwriting arbitrary
files accessible to a process using the fax filter (such as the
hp3-sendfax tool). (CVE-2011-2722)

This update also fixes the following bug:

* Previous modifications of the hplip3 package to allow it to be installed
alongside the original hplip package introduced several problems to fax
support; for example, the hp-sendfax utility could become unresponsive.
These problems have been fixed with this update. (BZ#501834)

All users of hplip3 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0133</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2722</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130133"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130134" severity="low">
    <xccdf:title>RHSA-2013:0134: freeradius2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is an open-source Remote Authentication Dial-In User Service
(RADIUS) server which allows RADIUS clients to perform authentication
against the RADIUS server. The RADIUS server may optionally perform
accounting of its operations using the RADIUS protocol.

It was found that the "unix" module ignored the password expiration
setting in "/etc/shadow". If FreeRADIUS was configured to use this module
for user authentication, this flaw could allow users with an expired
password to successfully authenticate, even though their access should have
been denied. (CVE-2011-4966)

This update also fixes the following bugs:

* After log rotation, the freeradius logrotate script failed to reload the
radiusd daemon and log messages were lost. This update has added a command
to the freeradius logrotate script to reload the radiusd daemon and the
radiusd daemon re-initializes and reopens its log files after log rotation
as expected. (BZ#787111)

* The radtest script with the "eap-md5" option failed because it passed the
IP family argument when invoking the radeapclient utility and the
radeapclient utility did not recognize the IP family. The radeapclient
utility now recognizes the IP family argument and radtest now works with
eap-md5 as expected. (BZ#846476)

* Previously, freeradius was compiled without the "--with-udpfromto"
option. Consequently, with a multihomed server and explicitly specifying
the IP address, freeradius sent the reply with the wrong IP source address.
With this update, freeradius has been built with the "--with-udpfromto"
configuration option and the RADIUS reply is always sourced from the IP
address the request was sent to. (BZ#846471)

* Due to invalid syntax in the PostgreSQL admin schema file, the FreeRADIUS
PostgreSQL tables failed to be created. With this update, the syntax has
been adjusted and the tables are created as expected. (BZ#818885)

* FreeRADIUS has a thread pool that dynamically grows based on load. If
multiple threads using the "rlm_perl()" function are spawned in quick
succession, the FreeRADIUS server sometimes terminated unexpectedly with a
segmentation fault due to parallel calls to the "rlm_perl_clone()"
function. With this update, a mutex for the threads has been added and the
problem no longer occurs. (BZ#846475)

* The man page for "rlm_dbm_parser" was incorrectly installed as
"rlm_dbm_parse", omitting the trailing "r". The man page now correctly
appears as rlm_dbm_parser. (BZ#781877)

All users of freeradius2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. They are also
advised to check for RPM backup files ending in ".rpmnew" or ".rpmsave"
under the /etc/raddb/ directory after the update because the FreeRADIUS
server will attempt to load every file it finds in its configuration
directory. The extra files will often cause the wrong configuration values
to be applied resulting in either unpredictable behavior or the failure of
the server to initialize and run.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0134</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4966</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130134"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130135" severity="low">
    <xccdf:title>RHSA-2013:0135: gtk2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GIMP Toolkit (GTK+) is a multi-platform toolkit for creating graphical user
interfaces.

An integer overflow flaw was found in the X BitMap (XBM) image file loader
in GTK+. A remote attacker could provide a specially-crafted XBM image file
that, when opened in an application linked against GTK+ (such as Nautilus),
would cause the application to crash. (CVE-2012-2370)

This update also fixes the following bugs:

* Due to a bug in the Input Method GTK+ module, the usage of the Taiwanese
Big5 (zh_TW.Big-5) locale led to the unexpected termination of certain
applications, such as the GDM greeter. The bug has been fixed, and the
Taiwanese locale no longer causes applications to terminate unexpectedly.
(BZ#487630)

* When a file was initially selected after the GTK+ file chooser dialog was
opened and the Location field was visible, pressing the Enter key did not
open the file. With this update, the initially selected file is opened
regardless of the visibility of the Location field. (BZ#518483)

* When a file was initially selected after the GTK+ file chooser dialog was
opened and the Location field was visible, pressing the Enter key did not
change into the directory. With this update, the dialog changes into the
initially selected directory regardless of the visibility of the Location
field. (BZ#523657)

* Previously, the GTK Print dialog did not reflect the user-defined printer
preferences stored in the ~/.cups/lpoptions file, such as those set in the
Default Printer preferences panel. Consequently, the first device in the
printer list was always set as a default printer. With this update, the
underlying source code has been enhanced to parse the option file. As a
result, the default values in the print dialog are set to those previously
specified by the user. (BZ#603809)

* The GTK+ file chooser did not properly handle saving of nameless files.
Consequently, attempting to save a file without specifying a file name
caused GTK+ to become unresponsive. With this update, an explicit test for
this condition has been added into the underlying source code. As a result,
GTK+ no longer hangs in the described scenario. (BZ#702342)

* When using certain graphics tablets, the GTK+ library incorrectly
translated the input coordinates. Consequently, an offset occurred between
the position of the pen and the content drawn on the screen. This issue was
limited to the following configuration: a Wacom tablet with input
coordinates bound to a single monitor in a dual head configuration, drawing
with a pen with the pressure sensitivity option enabled. With this update,
the coordinate translation method has been changed, and the offset is no
longer present in the described configuration. (BZ#743658)

* Previously, performing drag and drop operations on tabs in applications
using the GtkNotebook widget could lead to releasing the same resource
twice. Eventually, this behavior caused the applications to terminate with
a segmentation fault. This bug has been fixed, and the applications using
GtkNotebook no longer terminate in the aforementioned scenario. (BZ#830901)

All users of GTK+ are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2370</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130144" severity="high">
    <xccdf:title>RHSA-2013:0144: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-0744, CVE-2013-0746, CVE-2013-0750, CVE-2013-0753,
CVE-2013-0754, CVE-2013-0762, CVE-2013-0766, CVE-2013-0767, CVE-2013-0769)

A flaw was found in the way Chrome Object Wrappers were implemented.
Malicious content could be used to cause Firefox to execute arbitrary code
via plug-ins installed in Firefox. (CVE-2013-0758)

A flaw in the way Firefox displayed URL values in the address bar could
allow a malicious site or user to perform a phishing attack.
(CVE-2013-0759)

An information disclosure flaw was found in the way certain JavaScript
functions were implemented in Firefox. An attacker could use this flaw to
bypass Address Space Layout Randomization (ASLR) and other security
restrictions. (CVE-2013-0748)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 10.0.12 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Atte Kettunen, Boris Zbarsky, pa_kt, regenrecht,
Abhishek Arya, Christoph Diehl, Christian Holler, Mats Palmgren, Chiaki
Ishikawa, Mariusz Mlynski, Masato Kinugawa, and Jesse Ruderman as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 10.0.12 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0754</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0758</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0759</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0762</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0766</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0769</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130144"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130145" severity="high">
    <xccdf:title>RHSA-2013:0145: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-0744,
CVE-2013-0746, CVE-2013-0750, CVE-2013-0753, CVE-2013-0754, CVE-2013-0762,
CVE-2013-0766, CVE-2013-0767, CVE-2013-0769)

A flaw was found in the way Chrome Object Wrappers were implemented.
Malicious content could be used to cause Thunderbird to execute arbitrary
code via plug-ins installed in Thunderbird. (CVE-2013-0758)

A flaw in the way Thunderbird displayed URL values could allow malicious
content or a user to perform a phishing attack. (CVE-2013-0759)

An information disclosure flaw was found in the way certain JavaScript
functions were implemented in Thunderbird. An attacker could use this flaw
to bypass Address Space Layout Randomization (ASLR) and other security
restrictions. (CVE-2013-0748)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Atte Kettunen, Boris Zbarsky, pa_kt, regenrecht,
Abhishek Arya, Christoph Diehl, Christian Holler, Mats Palmgren, Chiaki
Ishikawa, Mariusz Mlynski, Masato Kinugawa, and Jesse Ruderman as the
original reporters of these issues.

Note: All issues except CVE-2013-0744, CVE-2013-0753, and CVE-2013-0754
cannot be exploited by a specially-crafted HTML mail message as JavaScript
is disabled by default for mail messages. They could be exploited another
way in Thunderbird, for example, when viewing the full remote content of an
RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.12 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0746</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0754</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0758</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0759</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0762</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0766</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0769</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130145"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130165" severity="high">
    <xccdf:title>RHSA-2013:0165: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Two improper permission check issues were discovered in the reflection API
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass Java sandbox restrictions. (CVE-2012-3174, CVE-2013-0422)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.4. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0422</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130165"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130168" severity="medium">
    <xccdf:title>RHSA-2013:0168: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the Xen hypervisor implementation did not perform
range checking on the guest provided values in multiple hypercalls. A
privileged guest user could use this flaw to trigger long loops, leading
to a denial of service (Xen hypervisor hang). (CVE-2012-5515, Moderate)

* It was found that when running a 32-bit binary that uses a large number
of shared libraries, one of the libraries would always be loaded at a
predictable address in memory. An attacker could use this flaw to bypass
the Address Space Layout Randomization (ASLR) security feature.
(CVE-2012-1568, Low)

* A flaw was found in the way the Linux kernel's IPv6 implementation
handled overlapping, fragmented IPv6 packets. A remote attacker could
potentially use this flaw to bypass protection mechanisms (such as a
firewall or intrusion detection system (IDS)) when sending network packets
to a target system. (CVE-2012-4444, Low)

Red Hat would like to thank the Xen project for reporting CVE-2012-5515,
and Antonios Atlasis working with Beyond Security's SecuriTeam Secure
Disclosure program and Loganaden Velvindron of AFRINIC for reporting
CVE-2012-4444.

This update also fixes several bugs. Space precludes documenting all of
these changes in this advisory. Documentation for these changes will be
available shortly from the Red Hat Enterprise Linux 5.9 Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0168</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5515</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130168"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130169" severity="medium">
    <xccdf:title>RHSA-2013:0169: vino security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Vino is a Virtual Network Computing (VNC) server for GNOME. It allows
remote users to connect to a running GNOME session using VNC.

It was found that Vino transmitted all clipboard activity on the system
running Vino to all clients connected to port 5900, even those who had not
authenticated. A remote attacker who is able to access port 5900 on a
system running Vino could use this flaw to read clipboard data without
authenticating. (CVE-2012-4429)

Two out-of-bounds memory read flaws were found in the way Vino processed
client framebuffer requests in certain encodings. An authenticated client
could use these flaws to send a specially-crafted request to Vino, causing
it to crash. (CVE-2011-0904, CVE-2011-0905)

In certain circumstances, the vino-preferences dialog box incorrectly
indicated that Vino was only accessible from the local network. This could
confuse a user into believing connections from external networks are not
allowed (even when they are allowed). With this update, vino-preferences no
longer displays connectivity and reachable information. (CVE-2011-1164)

There was no warning that Universal Plug and Play (UPnP) was used to open
ports on a user's network router when the "Configure network automatically
to accept connections" option was enabled (it is disabled by default) in
the Vino preferences. This update changes the option's description to avoid
the risk of a UPnP router configuration change without the user's consent.
(CVE-2011-1165)

All Vino users should upgrade to this updated package, which contains
backported patches to resolve these issues. The GNOME session must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0904</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4429</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130169"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130180" severity="high">
    <xccdf:title>RHSA-2013:0180: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

A stack-based buffer overflow flaw was found in the user permission
checking code in MySQL. An authenticated database user could use this flaw
to crash the mysqld daemon or, potentially, execute arbitrary code with the
privileges of the user running the mysqld daemon. (CVE-2012-5611)

A flaw was found in the way MySQL calculated the key length when creating
a sort order index for certain queries. An authenticated database user
could use this flaw to crash the mysqld daemon. (CVE-2012-2749)

This update also adds a patch for a potential flaw in the MySQL password
checking function, which could allow an attacker to log into any MySQL
account without knowing the correct password. This problem (CVE-2012-2122)
only affected MySQL packages that use a certain compiler and C library
optimization. It did not affect the mysql packages in Red Hat Enterprise
Linux 5. The patch is being added as a preventive measure to ensure this
problem cannot get exposed in future revisions of the mysql packages.
(BZ#814605)

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5611</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130188" severity="high">
    <xccdf:title>RHSA-2013:0188: ipa security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud-based
enterprise environments.

A weakness was found in the way IPA clients communicated with IPA servers
when initially attempting to join IPA domains. As there was no secure way
to provide the IPA server's Certificate Authority (CA) certificate to the
client during a join, the IPA client enrollment process was susceptible to
man-in-the-middle attacks. This flaw could allow an attacker to obtain
access to the IPA server using the credentials provided by an IPA client,
including administrative access to the entire domain if the join was
performed using an administrator's credentials. (CVE-2012-5484)

Note: This weakness was only exposed during the initial client join to the
realm, because the IPA client did not yet have the CA certificate of the
server. Once an IPA client has joined the realm and has obtained the CA
certificate of the IPA server, all further communication is secure. If a
client were using the OTP (one-time password) method to join to the realm,
an attacker could only obtain unprivileged access to the server (enough to
only join the realm).

Red Hat would like to thank Petr Menšík for reporting this issue.

This update must be installed on both the IPA client and IPA server. When
this update has been applied to the client but not the server,
ipa-client-install, in unattended mode, will fail if you do not have the
correct CA certificate locally, noting that you must use the "--force"
option to insecurely obtain the certificate. In interactive mode, the
certificate will try to be obtained securely from LDAP. If this fails, you
will be prompted to insecurely download the certificate via HTTP. In the
same situation when using OTP, LDAP will not be queried and you will be
prompted to insecurely download the certificate via HTTP.

Users of ipa are advised to upgrade to these updated packages, which
correct this issue. After installing the update, changes in LDAP are
handled by ipa-ldap-updater automatically and are effective immediately.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5484</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130188"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130189" severity="high">
    <xccdf:title>RHSA-2013:0189: ipa-client security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud-based
enterprise environments.

A weakness was found in the way IPA clients communicated with IPA servers
when initially attempting to join IPA domains. As there was no secure way
to provide the IPA server's Certificate Authority (CA) certificate to the
client during a join, the IPA client enrollment process was susceptible to
man-in-the-middle attacks. This flaw could allow an attacker to obtain
access to the IPA server using the credentials provided by an IPA client,
including administrative access to the entire domain if the join was
performed using an administrator's credentials. (CVE-2012-5484)

Note: This weakness was only exposed during the initial client join to the
realm, because the IPA client did not yet have the CA certificate of the
server. Once an IPA client has joined the realm and has obtained the CA
certificate of the IPA server, all further communication is secure. If a
client were using the OTP (one-time password) method to join to the realm,
an attacker could only obtain unprivileged access to the server (enough to
only join the realm).

Red Hat would like to thank Petr Menšík for reporting this issue.

When a fix for this flaw has been applied to the client but not yet the
server, ipa-client-install, in unattended mode, will fail if you do not
have the correct CA certificate locally, noting that you must use the
"--force" option to insecurely obtain the certificate. In interactive mode,
the certificate will try to be obtained securely from LDAP. If this fails,
you will be prompted to insecurely download the certificate via HTTP. In
the same situation when using OTP, LDAP will not be queried and you will be
prompted to insecurely download the certificate via HTTP.

Users of ipa-client are advised to upgrade to this updated package, which
corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5484</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130189"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130199" severity="high">
    <xccdf:title>RHSA-2013:0199: libvirt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

A flaw was found in the way libvirtd handled connection cleanup (when a
connection was being closed) under certain error conditions. A remote
attacker able to establish a read-only connection to libvirtd could use
this flaw to crash libvirtd or, potentially, execute arbitrary code with
the privileges of the root user. (CVE-2013-0170)

This issue was discovered by Tingting Zheng of Red Hat.

All users of libvirt are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0170</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130199"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130213" severity="high">
    <xccdf:title>RHSA-2013:0213: nss, nss-util, and nspr security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

It was found that a Certificate Authority (CA) mis-issued two intermediate
certificates to customers. These certificates could be used to launch
man-in-the-middle attacks. This update renders those certificates as
untrusted. This covers all uses of the certificates, including SSL, S/MIME,
and code signing. (BZ#890605)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

In addition, the nss package has been upgraded to upstream version 3.13.6,
the nss-util package has been upgraded to upstream version 3.13.6, and the
nspr package has been upgraded to upstream version 4.9.2. These updates
provide a number of bug fixes and enhancements over the previous versions.
(BZ#891663, BZ#891670, BZ#891661)

Users of NSS, NSPR, and nss-util are advised to upgrade to these updated
packages, which fix these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0743</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130213"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130215" severity="high">
    <xccdf:title>RHSA-2013:0215: abrt and libreport security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. libreport provides an API for reporting different problems
in applications to different bug targets, such as Bugzilla, FTP, and Trac.

It was found that the
/usr/libexec/abrt-action-install-debuginfo-to-abrt-cache tool did not
sufficiently sanitize its environment variables. This could lead to Python
modules being loaded and run from non-standard directories (such as /tmp/).
A local attacker could use this flaw to escalate their privileges to that
of the abrt user. (CVE-2012-5659)

A race condition was found in the way ABRT handled the directories used to
store information about crashes. A local attacker with the privileges of
the abrt user could use this flaw to perform a symbolic link attack,
possibly allowing them to escalate their privileges to root.
(CVE-2012-5660)

Red Hat would like to thank Martin Carpenter of Citco for reporting the
CVE-2012-5660 issue. CVE-2012-5659 was discovered by Miloslav Trmač of Red
Hat.

All users of abrt and libreport are advised to upgrade to these updated
packages, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5660</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130215"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130216" severity="high">
    <xccdf:title>RHSA-2013:0216: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently.

A flaw was found in the way the FreeType font rendering engine processed
certain Glyph Bitmap Distribution Format (BDF) fonts. If a user loaded a
specially-crafted font file with an application linked against FreeType, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2012-5669)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5669</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130216"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130217" severity="high">
    <xccdf:title>RHSA-2013:0217: mingw32-libxml2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the libxml2 library, a development toolbox providing
the implementation of various XML standards, for users of MinGW (Minimalist
GNU for Windows).

IMPORTANT NOTE: The mingw32 packages in Red Hat Enterprise Linux 6 will no
longer be updated proactively and will be deprecated with the release of
Red Hat Enterprise Linux 6.4. These packages were provided to support other
capabilities in Red Hat Enterprise Linux and were not intended for direct
customer use. Customers are advised to not use these packages with
immediate effect. Future updates to these packages will be at Red Hat's
discretion and these packages may be removed in a future minor release.

A heap-based buffer overflow flaw was found in the way libxml2 decoded
entity references with long names. A remote attacker could provide a
specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-3919)

A heap-based buffer underflow flaw was found in the way libxml2 decoded
certain entities. A remote attacker could provide a specially-crafted XML
file that, when opened in an application linked against libxml2, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-5134)

It was found that the hashing routine used by libxml2 arrays was
susceptible to predictable hash collisions. Sending a specially-crafted
message to an XML service could result in longer processing time, which
could lead to a denial of service. To mitigate this issue, randomization
has been added to the hashing function to reduce the chance of an attacker
successfully causing intentional collisions. (CVE-2012-0841)

Multiple flaws were found in the way libxml2 parsed certain XPath (XML Path
Language) expressions. If an attacker were able to supply a
specially-crafted XML file to an application using libxml2, as well as an
XPath expression for that application to run against the crafted file, it
could cause the application to crash. (CVE-2010-4008, CVE-2010-4494,
CVE-2011-2821, CVE-2011-2834)

Two heap-based buffer overflow flaws were found in the way libxml2 decoded
certain XML files. A remote attacker could provide a specially-crafted XML
file that, when opened in an application linked against libxml2, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2011-0216,
CVE-2011-3102)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way libxml2 parsed certain XPath expressions. If an attacker
were able to supply a specially-crafted XML file to an application using
libxml2, as well as an XPath expression for that application to run against
the crafted file, it could cause the application to crash or, possibly,
execute arbitrary code. (CVE-2011-1944)

An out-of-bounds memory read flaw was found in libxml2. A remote attacker
could provide a specially-crafted XML file that, when opened in an
application linked against libxml2, would cause the application to crash.
(CVE-2011-3905)

Red Hat would like to thank the Google Security Team for reporting the
CVE-2010-4008 issue. Upstream acknowledges Bui Quang Minh from Bkis as the
original reporter of CVE-2010-4008.

All users of mingw32-libxml2 are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0217</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1944</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0841</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5134</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130217"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130218" severity="medium">
    <xccdf:title>RHSA-2013:0218: xorg-x11-drv-qxl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xorg-x11-drv-qxl package provides an X11 video driver for the QEMU QXL
video accelerator. This driver makes it possible to use Red Hat Enterprise
Linux 6 as a guest operating system under the KVM kernel module and the
QEMU multi-platform emulator, using the SPICE protocol.

A flaw was found in the way the host's qemu-kvm qxl driver and the guest's
X.Org qxl driver interacted when a SPICE connection terminated. A user able
to initiate a SPICE connection to a guest could use this flaw to make the
guest temporarily unavailable or, potentially (if the sysctl
kernel.softlockup_panic variable was set to "1" in the guest), crash the
guest. (CVE-2013-0241)

All users of xorg-x11-drv-qxl are advised to upgrade to this updated
package, which contains a backported patch to correct this issue. All
running X.Org server instances using the qxl driver must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0241</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130218"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130219" severity="medium">
    <xccdf:title>RHSA-2013:0219: mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2012-0572,
CVE-2012-0574, CVE-2012-1702, CVE-2012-1705, CVE-2013-0375, CVE-2013-0383,
CVE-2013-0384, CVE-2013-0385, CVE-2013-0389)

These updated packages upgrade MySQL to version 5.1.67. Refer to the MySQL
release notes listed in the References section for a full list of changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0572</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0389</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130219"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130223" severity="medium">
    <xccdf:title>RHSA-2013:0223: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that a deadlock could occur in the Out of Memory (OOM)
killer. A process could trigger this deadlock by consuming a large amount
of memory, and then causing request_module() to be called. A local,
unprivileged user could use this flaw to cause a denial of service
(excessive memory consumption). (CVE-2012-4398, Moderate)

* A flaw was found in the way the KVM (Kernel-based Virtual Machine)
subsystem handled guests attempting to run with the X86_CR4_OSXSAVE CPU
feature flag set. On hosts without the XSAVE CPU feature, a local,
unprivileged user could use this flaw to crash the host system. (The
"grep --color xsave /proc/cpuinfo" command can be used to verify if your
system has the XSAVE CPU feature.) (CVE-2012-4461, Moderate)

* A memory disclosure flaw was found in the way the load_script() function
in the binfmt_script binary format handler handled excessive recursions. A
local, unprivileged user could use this flaw to leak kernel stack memory to
user-space by executing specially-crafted scripts. (CVE-2012-4530, Low)

Red Hat would like to thank Tetsuo Handa for reporting CVE-2012-4398, and
Jon Howell for reporting CVE-2012-4461.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4530</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130223"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130241" severity="medium">
    <xccdf:title>RHSA-2013:0241: xen security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A flaw was found in the way libxc, the Xen control library, handled
excessively large kernel and ramdisk images when starting new guests. A
privileged guest user in a para-virtualized guest (a DomU) could create a
crafted kernel or ramdisk image that, when attempting to use it during
guest start, could result in an out-of-memory condition in the privileged
domain (the Dom0). (CVE-2012-4544)

Red Hat would like to thank the Xen project for reporting this issue.

All users of xen are advised to upgrade to these updated packages, which
correct this issue. After installing the updated packages, the xend service
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4544</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130241"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130245" severity="high">
    <xccdf:title>RHSA-2013:0245: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the AWT,
CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-0442, CVE-2013-0445, CVE-2013-0441, CVE-2013-1475,
CVE-2013-1476, CVE-2013-0429, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
CVE-2013-0428)

Multiple flaws were found in the way image parsers in the 2D and AWT
components handled image raster parameters. A specially-crafted image could
cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with the virtual machine privileges.
(CVE-2013-1478, CVE-2013-1480)

A flaw was found in the AWT component's clipboard handling code. An
untrusted Java application or applet could use this flaw to access
clipboard data, bypassing Java sandbox restrictions. (CVE-2013-0432)

The default Java security properties configuration did not restrict access
to certain com.sun.xml.internal packages. An untrusted Java application or
applet could use this flaw to access information, bypassing certain Java
sandbox restrictions. This update lists the whole package as restricted.
(CVE-2013-0435)

Multiple improper permission check issues were discovered in the Libraries,
Networking, and JAXP components. An untrusted Java application or applet
could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2013-0427, CVE-2013-0433, CVE-2013-0434)

It was discovered that the RMI component's CGIHandler class used user
inputs in error messages without any sanitization. An attacker could use
this flaw to perform a cross-site scripting (XSS) attack. (CVE-2013-0424)

It was discovered that the SSL/TLS implementation in the JSSE component
did not properly enforce handshake message ordering, allowing an unlimited
number of handshake restarts. A remote attacker could use this flaw to
make an SSL/TLS server using JSSE consume an excessive amount of CPU by
continuously restarting the handshake. (CVE-2013-0440)

It was discovered that the JSSE component did not properly validate
Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw
to perform a small subgroup attack. (CVE-2013-0443)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0434</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0440</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130245"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130246" severity="high">
    <xccdf:title>RHSA-2013:0246: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the AWT,
CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-0442, CVE-2013-0445, CVE-2013-0441, CVE-2013-1475,
CVE-2013-1476, CVE-2013-0429, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
CVE-2013-0428)

Multiple flaws were found in the way image parsers in the 2D and AWT
components handled image raster parameters. A specially-crafted image could
cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with the virtual machine privileges.
(CVE-2013-1478, CVE-2013-1480)

A flaw was found in the AWT component's clipboard handling code. An
untrusted Java application or applet could use this flaw to access
clipboard data, bypassing Java sandbox restrictions. (CVE-2013-0432)

The default Java security properties configuration did not restrict access
to certain com.sun.xml.internal packages. An untrusted Java application or
applet could use this flaw to access information, bypassing certain Java
sandbox restrictions. This update lists the whole package as restricted.
(CVE-2013-0435)

Multiple improper permission check issues were discovered in the Libraries,
Networking, and JAXP components. An untrusted Java application or applet
could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2013-0427, CVE-2013-0433, CVE-2013-0434)

It was discovered that the RMI component's CGIHandler class used user
inputs in error messages without any sanitization. An attacker could use
this flaw to perform a cross-site scripting (XSS) attack. (CVE-2013-0424)

It was discovered that the SSL/TLS implementation in the JSSE component
did not properly enforce handshake message ordering, allowing an unlimited
number of handshake restarts. A remote attacker could use this flaw to
make an SSL/TLS server using JSSE consume an excessive amount of CPU by
continuously restarting the handshake. (CVE-2013-0440)

It was discovered that the JSSE component did not properly validate
Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw
to perform a small subgroup attack. (CVE-2013-0443)

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0246</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0434</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0440</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130246"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130247" severity="high">
    <xccdf:title>RHSA-2013:0247: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple improper permission check issues were discovered in the AWT,
CORBA, JMX, Libraries, and Beans components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-0442, CVE-2013-0445, CVE-2013-0441, CVE-2013-1475,
CVE-2013-1476, CVE-2013-0429, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
CVE-2013-0428, CVE-2013-0444)

Multiple flaws were found in the way image parsers in the 2D and AWT
components handled image raster parameters. A specially-crafted image could
cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with the virtual machine privileges.
(CVE-2013-1478, CVE-2013-1480)

A flaw was found in the AWT component's clipboard handling code. An
untrusted Java application or applet could use this flaw to access
clipboard data, bypassing Java sandbox restrictions. (CVE-2013-0432)

The default Java security properties configuration did not restrict access
to certain com.sun.xml.internal packages. An untrusted Java application or
applet could use this flaw to access information, bypassing certain Java
sandbox restrictions. This update lists the whole package as restricted.
(CVE-2013-0435)

Multiple improper permission check issues were discovered in the JMX,
Libraries, Networking, and JAXP components. An untrusted Java application
or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2013-0431, CVE-2013-0427, CVE-2013-0433, CVE-2013-0434)

It was discovered that the RMI component's CGIHandler class used user
inputs in error messages without any sanitization. An attacker could use
this flaw to perform a cross-site scripting (XSS) attack. (CVE-2013-0424)

It was discovered that the SSL/TLS implementation in the JSSE component
did not properly enforce handshake message ordering, allowing an unlimited
number of handshake restarts. A remote attacker could use this flaw to
make an SSL/TLS server using JSSE consume an excessive amount of CPU by
continuously restarting the handshake. (CVE-2013-0440)

It was discovered that the JSSE component did not properly validate
Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw
to perform a small subgroup attack. (CVE-2013-0443)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.5. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0434</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0440</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130247"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130250" severity="medium">
    <xccdf:title>RHSA-2013:0250: elinks security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ELinks is a text-based web browser. ELinks does not display any images, but
it does support frames, tables, and most other HTML tags.

It was found that ELinks performed client credentials delegation during the
client-to-server GSS security mechanisms negotiation. A rogue server could
use this flaw to obtain the client's credentials and impersonate that
client to other servers that are using GSSAPI. (CVE-2012-4545)

This issue was discovered by Marko Myllynen of Red Hat.

All ELinks users are advised to upgrade to this updated package, which
contains a backported patch to resolve the issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0250</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4545</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130250"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130269" severity="medium">
    <xccdf:title>RHSA-2013:0269: axis security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

Apache Axis did not verify that the server hostname matched the domain name
in the subject's Common Name (CN) or subjectAltName field in X.509
certificates. This could allow a man-in-the-middle attacker to spoof an SSL
server if they had a certificate that was valid for any domain name.
(CVE-2012-5784)

All users of axis are advised to upgrade to these updated packages, which
correct this issue. Applications using Apache Axis must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0269</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5784</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130269"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130270" severity="medium">
    <xccdf:title>RHSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Jakarta Commons HttpClient component can be used to build HTTP-aware
client applications (such as web browsers and web service clients).

The Jakarta Commons HttpClient component did not verify that the server
hostname matched the domain name in the subject's Common Name (CN) or
subjectAltName field in X.509 certificates. This could allow a
man-in-the-middle attacker to spoof an SSL server if they had a certificate
that was valid for any domain name. (CVE-2012-5783)

All users of jakarta-commons-httpclient are advised to upgrade to these
updated packages, which correct this issue. Applications using the Jakarta
Commons HttpClient component must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5783</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130270"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130271" severity="high">
    <xccdf:title>RHSA-2013:0271: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A
web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user
running Firefox. (CVE-2013-0775, CVE-2013-0780, CVE-2013-0782,
CVE-2013-0783)

It was found that, after canceling a proxy server's authentication
prompt, the address bar continued to show the requested site's address. An
attacker could use this flaw to conduct phishing attacks by tricking a
user into believing they are viewing a trusted site. (CVE-2013-0776)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Nils, Abhishek Arya, Olli Pettay, Christoph Diehl,
Gary Kwong, Jesse Ruderman, Andrew McCreight, Joe Drew, Wayne Mery, and
Michal Zalewski as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.3 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

Note that due to a Kerberos credentials change, the following configuration
steps may be required when using Firefox 17.0.3 ESR with the Enterprise
Identity Management (IPA) web interface:

https://access.redhat.com/knowledge/solutions/294303

Important: Firefox 17 is not completely backwards-compatible with all
Mozilla add-ons and Firefox plug-ins that worked with Firefox 10.0.
Firefox 17 checks compatibility on first-launch, and, depending on the
individual configuration and the installed add-ons and plug-ins, may
disable said Add-ons and plug-ins, or attempt to check for updates and
upgrade them. Add-ons and plug-ins may have to be manually updated.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.3 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0271</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0783</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130271"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130272" severity="high">
    <xccdf:title>RHSA-2013:0272: thunderbird security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-0775,
CVE-2013-0780, CVE-2013-0782, CVE-2013-0783)

It was found that, after canceling a proxy server's authentication
prompt, the address bar continued to show the requested site's address. An
attacker could use this flaw to conduct phishing attacks by tricking a
user into believing they are viewing trusted content. (CVE-2013-0776)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Nils, Abhishek Arya, Olli Pettay, Christoph Diehl,
Gary Kwong, Jesse Ruderman, Andrew McCreight, Joe Drew, Wayne Mery, and
Michal Zalewski as the original reporters of these issues.

Note: All issues cannot be exploited by a specially-crafted HTML mail
message as JavaScript is disabled by default for mail messages. They could
be exploited another way in Thunderbird, for example, when viewing the full
remote content of an RSS feed.

Important: This erratum upgrades Thunderbird to version 17.0.3 ESR.
Thunderbird 17 is not completely backwards-compatible with all Mozilla
add-ons and Thunderbird plug-ins that worked with Thunderbird 10.0.
Thunderbird 17 checks compatibility on first-launch, and, depending on the
individual configuration and the installed add-ons and plug-ins, may
disable said Add-ons and plug-ins, or attempt to check for updates and
upgrade them. Add-ons and plug-ins may have to be manually updated.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.3 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0783</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130272"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130273" severity="high">
    <xccdf:title>RHSA-2013:0273: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

An improper permission check issue was discovered in the JMX component in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass Java sandbox restrictions. (CVE-2013-1486)

It was discovered that OpenJDK leaked timing information when decrypting
TLS/SSL protocol encrypted records when CBC-mode cipher suites were used.
A remote attacker could possibly use this flaw to retrieve plain text from
the encrypted packets by using a TLS/SSL server as a padding oracle.
(CVE-2013-0169)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, CVE-2013-1486 could have been exploited without user interaction
if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.8. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130273"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130274" severity="high">
    <xccdf:title>RHSA-2013:0274: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

An improper permission check issue was discovered in the JMX component in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass Java sandbox restrictions. (CVE-2013-1486)

It was discovered that OpenJDK leaked timing information when decrypting
TLS/SSL protocol encrypted records when CBC-mode cipher suites were used.
A remote attacker could possibly use this flaw to retrieve plain text from
the encrypted packets by using a TLS/SSL server as a padding oracle.
(CVE-2013-0169)

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.8. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130274"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130275" severity="high">
    <xccdf:title>RHSA-2013:0275: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple improper permission check issues were discovered in the JMX and
Libraries components in OpenJDK. An untrusted Java application or applet
could use these flaws to bypass Java sandbox restrictions. (CVE-2013-1486,
CVE-2013-1484)

An improper permission check issue was discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
this flaw to bypass certain Java sandbox restrictions. (CVE-2013-1485)

It was discovered that OpenJDK leaked timing information when decrypting
TLS/SSL protocol encrypted records when CBC-mode cipher suites were used.
A remote attacker could possibly use this flaw to retrieve plain text from
the encrypted packets by using a TLS/SSL server as a padding oracle.
(CVE-2013-0169)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.7. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1486</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130275"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130276" severity="medium">
    <xccdf:title>RHSA-2013:0276: libvirt security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

It was discovered that libvirt made certain invalid assumptions about
dnsmasq's command line options when setting up DNS masquerading for virtual
machines, resulting in dnsmasq incorrectly processing network packets from
network interfaces that were intended to be prohibited. This update
includes the changes necessary to call dnsmasq with a new command line
option, which was introduced to dnsmasq via RHSA-2013:0277. (CVE-2012-3411)

In order for libvirt to be able to make use of the new command line option
(--bind-dynamic), updated dnsmasq packages need to be installed. Refer to
RHSA-2013:0277 for additional information.

These updated libvirt packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 6.4 Technical Notes, linked
to in the References, for information on the most significant of these
changes.

All users of libvirt are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0276</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130276"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130277" severity="medium">
    <xccdf:title>RHSA-2013:0277: dnsmasq security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name
Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

It was discovered that dnsmasq, when used in combination with certain
libvirtd configurations, could incorrectly process network packets from
network interfaces that were intended to be prohibited. A remote,
unauthenticated attacker could exploit this flaw to cause a denial of
service via DNS amplification attacks. (CVE-2012-3411)

In order to fully address this issue, libvirt package users are advised to
install updated libvirt packages. Refer to RHSA-2013:0276 for additional
information.

This update also fixes the following bug:

* Due to a regression, the lease change script was disabled. Consequently,
the "dhcp-script" option in the /etc/dnsmasq.conf configuration file did
not work. This update corrects the problem and the "dhcp-script" option now
works as expected. (BZ#815819)

This update also adds the following enhancements:

* Prior to this update, dnsmasq did not validate that the tftp directory
given actually existed and was a directory. Consequently, configuration
errors were not immediately reported on startup. This update improves the
code to validate the tftp root directory option. As a result, fault finding
is simplified especially when dnsmasq is called by external processes such
as libvirt. (BZ#824214)

* The dnsmasq init script used an incorrect Process Identifier (PID) in the
"stop", "restart", and "condrestart" commands. Consequently, if there were
some dnsmasq instances running besides the system one started by the init
script, then repeated calling of "service dnsmasq" with "stop" or "restart"
would kill all running dnsmasq instances, including ones not started with
the init script. The dnsmasq init script code has been corrected to obtain
the correct PID when calling the "stop", "restart", and "condrestart"
commands. As a result, if there are dnsmasq instances running in addition
to the system one started by the init script, then by calling "service
dnsmasq" with "stop" or "restart" only the system one is stopped or
restarted. (BZ#850944)

* When two or more dnsmasq processes were running with DHCP enabled on one
interface, DHCP RELEASE packets were sometimes lost. Consequently, when two
or more dnsmasq processes were running with DHCP enabled on one interface,
releasing IP addresses sometimes failed. This update sets the
SO_BINDTODEVICE socket option on DHCP sockets if running dnsmasq with DHCP
enabled on one interface. As a result, when two or more dnsmasq processes
are running with DHCP enabled on one interface, they can release IP
addresses as expected. (BZ#887156)

All users of dnsmasq are advised to upgrade to these updated packages,
which fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0277</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3411</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130277"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130496" severity="high">
    <xccdf:title>RHSA-2013:0496: Red Hat Enterprise Linux 6 kernel update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A race condition was found in the way asynchronous I/O and fallocate()
interacted when using the ext4 file system. A local, unprivileged user
could use this flaw to expose random data from an extent whose data blocks
have not yet been written, and thus contain data from a deleted file.
(CVE-2012-4508, Important)

* A flaw was found in the way the vhost kernel module handled descriptors
that spanned multiple regions. A privileged guest user in a KVM guest could
use this flaw to crash the host or, potentially, escalate their privileges
on the host. (CVE-2013-0311, Important)

* It was found that the default SCSI command filter does not accommodate
commands that overlap across device classes. A privileged guest user could
potentially use this flaw to write arbitrary data to a LUN that is
passed-through as read-only. (CVE-2012-4542, Moderate)

* A flaw was found in the way the xen_failsafe_callback() function in the
Linux kernel handled the failed iret (interrupt return) instruction
notification from the Xen hypervisor. An unprivileged user in a 32-bit
para-virtualized guest could use this flaw to crash the guest.
(CVE-2013-0190, Moderate)

* A flaw was found in the way pmd_present() interacted with PROT_NONE
memory ranges when transparent hugepages were in use. A local, unprivileged
user could use this flaw to crash the system. (CVE-2013-0309, Moderate)

* A flaw was found in the way CIPSO (Common IP Security Option) IP options
were validated when set from user mode. A local user able to set CIPSO IP
options on the socket could use this flaw to crash the system.
(CVE-2013-0310, Moderate)

Red Hat would like to thank Theodore Ts'o for reporting CVE-2012-4508, and
Andrew Cooper of Citrix for reporting CVE-2013-0190. Upstream acknowledges
Dmitry Monakhov as the original reporter of CVE-2012-4508. The
CVE-2012-4542 issue was discovered by Paolo Bonzini of Red Hat.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.4 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.4 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0190</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0309</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0311</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130496"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130499" severity="low">
    <xccdf:title>RHSA-2013:0499: xinetd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xinetd package provides a secure replacement for inetd, the Internet
services daemon. xinetd provides access control for all services based on
the address of the remote host and/or on time of access, and can prevent
denial-of-access attacks.

When xinetd services are configured with the "TCPMUX" or "TCPMUXPLUS" type,
and the tcpmux-server service is enabled, those services are accessible via
port 1. It was found that enabling the tcpmux-server service (it is
disabled by default) allowed every xinetd service, including those that are
not configured with the "TCPMUX" or "TCPMUXPLUS" type, to be accessible via
port 1. This could allow a remote attacker to bypass intended firewall
restrictions. (CVE-2012-0862)

Red Hat would like to thank Thomas Swan of FedEx for reporting this issue.

This update also fixes the following bugs:

* Prior to this update, a file descriptor array in the service.c source
file was not handled as expected. As a consequence, some of the descriptors
remained open when xinetd was under heavy load. Additionally, the system
log was filled with a large number of messages that took up a lot of disk
space over time. This update modifies the xinetd code to handle the file
descriptors correctly and messages no longer fill the system log.
(BZ#790036)

* Prior to this update, services were disabled permanently when their CPS
limit was reached. As a consequence, a failed bind operation could occur
when xinetd attempted to restart the service. This update adds additional
logic that attempts to restart the service. Now, the service is only
disabled if xinetd cannot restart the service after 30 attempts.
(BZ#809271)

All users of xinetd are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0862</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130499"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130500" severity="low">
    <xccdf:title>RHSA-2013:0500: hplip security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The hplip packages contain the Hewlett-Packard Linux Imaging and Printing
Project (HPLIP), which provides drivers for Hewlett-Packard printers and
multi-function peripherals.

Several temporary file handling flaws were found in HPLIP. A local attacker
could use these flaws to perform a symbolic link attack, overwriting
arbitrary files accessible to a process using HPLIP. (CVE-2013-0200,
CVE-2011-2722)

The CVE-2013-0200 issues were discovered by Tim Waugh of Red Hat.

The hplip packages have been upgraded to upstream version 3.12.4, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#731900)

This update also fixes the following bugs:

* Previously, the hpijs package required the obsolete cupsddk-drivers
package, which was provided by the cups package. Under certain
circumstances, this dependency caused hpijs installation to fail. This
bug has been fixed and hpijs no longer requires cupsddk-drivers.
(BZ#829453)

* The configuration of the Scanner Access Now Easy (SANE) back end is
located in the /etc/sane.d/dll.d/ directory, however, the hp-check
utility checked only the /etc/sane.d/dll.conf file. Consequently,
hp-check checked for correct installation, but incorrectly reported a
problem with the way the SANE back end was installed. With this update,
hp-check properly checks for installation problems in both locations as
expected. (BZ#683007)

All users of hplip are advised to upgrade to these updated packages, which
fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130500"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130502" severity="low">
    <xccdf:title>RHSA-2013:0502: Core X11 clients security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Core X11 clients packages provide the xorg-x11-utils,
xorg-x11-server-utils, and xorg-x11-apps clients that ship with the X
Window System.

It was found that the x11perfcomp utility included the current working
directory in its PATH environment variable. Running x11perfcomp in an
attacker-controlled directory would cause arbitrary code execution with
the privileges of the user running x11perfcomp. (CVE-2011-2504)

Also with this update, the xorg-x11-utils and xorg-x11-server-utils
packages have been upgraded to upstream version 7.5, and the xorg-x11-apps
package to upstream version 7.6, which provides a number of bug fixes and
enhancements over the previous versions. (BZ#835277, BZ#835278, BZ#835281)

All users of xorg-x11-utils, xorg-x11-server-utils, and xorg-x11-apps are
advised to upgrade to these updated packages, which fix these issues and
add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2504</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130502"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130503" severity="medium">
    <xccdf:title>RHSA-2013:0503: 389-ds-base security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389-ds-base packages provide 389 Directory Server, which is an LDAPv3
compliant server. The base packages include the Lightweight Directory
Access Protocol (LDAP) server and command-line utilities for server
administration.

A flaw was found in the way 389 Directory Server enforced ACLs after
performing an LDAP modify relative distinguished name (modrdn) operation.
After modrdn was used to move part of a tree, the ACLs defined on the moved
(Distinguished Name) were not properly enforced until the server was
restarted. This could allow LDAP users to access information that should be
restricted by the defined ACLs. (CVE-2012-4450)

This issue was discovered by Noriko Hosoi of Red Hat.

These updated 389-ds-base packages include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4
Technical Notes, linked to in the References, for information on the most
significant of these changes.

All users of 389-ds-base are advised to upgrade to these updated packages,
which correct this issue and provide numerous bug fixes and enhancements.
After installing this update, the 389 server service will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4450</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130503"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130504" severity="low">
    <xccdf:title>RHSA-2013:0504: dhcp security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dhcp packages provide the Dynamic Host Configuration Protocol (DHCP)
that allows individual devices on an IP network to get their own network
configuration information, including an IP address, a subnet mask, and a
broadcast address.

A flaw was found in the way the dhcpd daemon handled the expiration time of
IPv6 leases. If dhcpd's configuration was changed to reduce the default
IPv6 lease time, lease renewal requests for previously assigned leases
could cause dhcpd to crash. (CVE-2012-3955)

This update also fixes the following bugs:

* Prior to this update, the DHCP server discovered only the first IP
address of a network interface if the network interface had more than one
configured IP address. As a consequence, the DHCP server failed to
restart if the server was configured to serve only a subnet of the
following IP addresses. This update modifies network interface addresses
discovery code to find all addresses of a network interface. The DHCP
server can also serve subnets of other addresses. (BZ#803540)

* Prior to this update, the dhclient rewrote the /etc/resolv.conf file
with backup data after it was stopped even when the PEERDNS flag was set
to "no" before shut down if the configuration file was changed while the
dhclient ran with PEERDNS=yes. This update removes the backing up and
restoring functions for this configuration file from the dhclient-script.
Now, the dhclient no longer rewrites the /etc/resolv.conf file when
stopped. (BZ#824622)

All users of DHCP are advised to upgrade to these updated packages, which
fix these issues. After installing this update, all DHCP servers will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3955</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130504"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130505" severity="medium">
    <xccdf:title>RHSA-2013:0505: squid security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients that
supports FTP, Gopher, and HTTP data objects.

A denial of service flaw was found in the way the Squid Cache Manager
processed certain requests. A remote attacker who is able to access the
Cache Manager CGI could use this flaw to cause Squid to consume an
excessive amount of memory. (CVE-2012-5643)

This update also fixes the following bugs:

* Due to a bug in the ConnStateData::noteMoreBodySpaceAvailable() function,
child processes of Squid terminated upon encountering a failed assertion.
An upstream patch has been provided and Squid child processes no longer
terminate. (BZ#805879)

* Due to an upstream patch, which renamed the HTTP header controlling
persistent connections from "Proxy-Connection" to "Connection", the NTLM
pass-through authentication does not work, thus preventing login. This
update adds the new "http10" option to the squid.conf file, which can be
used to enable the change in the patch. This option is set to "off" by
default. When set to "on", the NTLM pass-through authentication works
properly, thus allowing login attempts to succeed. (BZ#844723)

* When the IPv6 protocol was disabled and Squid tried to handle an HTTP GET
request containing an IPv6 address, the Squid child process terminated due
to signal 6. This bug has been fixed and such requests are now handled as
expected. (BZ#832484)

* The old "stale if hit" logic did not account for cases where the stored
stale response became fresh due to a successful re-validation with the
origin server. Consequently, incorrect warning messages were returned. Now,
Squid no longer marks elements as stale in the described scenario.
(BZ#847056)

* When squid packages were installed before samba-winbind, the wbpriv group
did not include Squid. Consequently, NTLM authentication calls failed. Now,
Squid correctly adds itself into the wbpriv group if samba-winbind is
installed before Squid, thus fixing this bug. (BZ#797571)

* In FIPS mode, Squid was using private MD5 hash functions for user
authentication and network access. As MD5 is incompatible with FIPS mode,
Squid could fail to start. This update limits the use of the private MD5
functions to local disk file hash identifiers, thus allowing Squid to work
in FIPS mode. (BZ#833086)

* Under high system load, the squid process could terminate unexpectedly
with a segmentation fault during reboot. This update provides better memory
handling during reboot, thus fixing this bug. (BZ#782732)

* Squid incorrectly set the timeout limit for client HTTP connections with
the value for server-side connections, which is much higher, thus creating
unnecessary delays. With this update, Squid uses a proper value for the
client timeout limit. (BZ#798090)

* Squid did not properly release allocated memory when generating error
page contents, which caused memory leaks. Consequently, the Squid proxy
server consumed a lot of memory within a short time period. This update
fixes this memory leak. (BZ#758861)

* Squid did not pass the ident value to a URL rewriter that was configured
using the "url_rewrite_program" directive. Consequently, the URL rewriter
received the dash character ("–") as the user value instead of the correct
user name. Now, the URL rewriter receives the correct user name in the
described scenario. (BZ#797884)

* Squid, used as a transparent proxy, can only handle the HTTP protocol.
Previously, it was possible to define a URL in which the access protocol
contained the asterisk character (*) or an unknown protocol namespace URI.
Consequently, an "Invalid URL" error message was logged to access.log
during reload. This update ensures that "http://" is always used in
transparent proxy URLs, and the error message is no longer logged in this
scenario. (BZ#720504)

All users of squid are advised to upgrade to these updated packages, which
fix these issues. After installing this update, the squid service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130505"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130506" severity="medium">
    <xccdf:title>RHSA-2013:0506: samba4 security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL)
compiler, used to generate code to handle RPC calls. This could result in
code generated by the PIDL compiler to not sufficiently protect against
buffer overflows. (CVE-2012-1182)

The samba4 packages have been upgraded to upstream version 4.0.0, which
provides a number of bug fixes and enhancements over the previous version.
In particular, improved interoperability with Active Directory (AD)
domains. SSSD now uses the libndr-krb5pac library to parse the Privilege
Attribute Certificate (PAC) issued by an AD Key Distribution Center (KDC).

The Cross Realm Kerberos Trust functionality provided by Identity
Management, which relies on the capabilities of the samba4 client library,
is included as a Technology Preview. This functionality and server
libraries, is included as a Technology Preview. This functionality uses the
libndr-nbt library to prepare Connection-less Lightweight Directory Access
Protocol (CLDAP) messages.

Additionally, various improvements have been made to the Local Security
Authority (LSA) and Net Logon services to allow verification of trust
from a Windows system. Because the Cross Realm Kerberos Trust functionality
is considered a Technology Preview, selected samba4 components are
considered to be a Technology Preview. For more information on which Samba
packages are considered a Technology Preview, refer to Table 5.1, "Samba4
Package Support" in the Release Notes, linked to from the References.
(BZ#766333, BZ#882188)

This update also fixes the following bug:

* Prior to this update, if the Active Directory (AD) server was rebooted,
Winbind sometimes failed to reconnect when requested by "wbinfo -n" or
"wbinfo -s" commands. Consequently, looking up users using the wbinfo tool
failed. This update applies upstream patches to fix this problem and now
looking up a Security Identifier (SID) for a username, or a username for a
given SID, works as expected after a domain controller is rebooted.
(BZ#878564)

All users of samba4 are advised to upgrade to these updated packages,
which fix these issues and add these enhancements.

Warning: If you upgrade from Red Hat Enterprise Linux 6.3 to Red Hat
Enterprise Linux 6.4 and you have Samba in use, you should make sure that
you uninstall the package named "samba4" to avoid conflicts during the
upgrade.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130506"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130508" severity="low">
    <xccdf:title>RHSA-2013:0508: sssd security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.

A race condition was found in the way SSSD copied and removed user home
directories. A local attacker who is able to write into the home directory
of a different user who is being removed could use this flaw to perform
symbolic link attacks, possibly allowing them to modify and delete
arbitrary files with the privileges of the root user. (CVE-2013-0219)

Multiple out-of-bounds memory read flaws were found in the way the autofs
and SSH service responders parsed certain SSSD packets. An attacker could
spend a specially-crafted packet that, when processed by the autofs or SSH
service responders, would cause SSSD to crash. This issue only caused a
temporary denial of service, as SSSD was automatically restarted by the
monitor process after the crash. (CVE-2013-0220)

The CVE-2013-0219 and CVE-2013-0220 issues were discovered by Florian
Weimer of the Red Hat Product Security Team.

These updated sssd packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All SSSD users are advised to upgrade to these updated packages, which
upgrade SSSD to upstream version 1.9 to correct these issues, fix these
bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0220</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130508"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130509" severity="low">
    <xccdf:title>RHSA-2013:0509: rdma security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Enterprise Linux includes a collection of InfiniBand and iWARP
utilities, libraries and development packages for writing applications
that use Remote Direct Memory Access (RDMA) technology.

A denial of service flaw was found in the way ibacm managed reference
counts for multicast connections. An attacker could send specially-crafted
multicast packets that would cause the ibacm daemon to crash.
(CVE-2012-4517)

It was found that the ibacm daemon created some files with world-writable
permissions. A local attacker could use this flaw to overwrite the
contents of the ibacm.log or ibacm.port file, allowing them to mask
certain actions from the log or cause ibacm to run on a non-default port.
(CVE-2012-4518)

CVE-2012-4518 was discovered by Florian Weimer of the Red Hat Product
Security Team and Kurt Seifried of the Red Hat Security Response Team.

The InfiniBand/iWARP/RDMA stack components have been upgraded to more
recent upstream versions.

This update also fixes the following bugs:

* Previously, the "ibnodes -h" command did not show a proper usage message.
With this update the problem is fixed and "ibnodes -h" now shows the
correct usage message. (BZ#818606)

* Previously, the ibv_devinfo utility erroneously showed iWARP cxgb3
hardware's physical state as invalid even when the device was working. For
iWARP hardware, the phys_state field has no meaning. This update patches
the utility to not print out anything for this field when the hardware is
iWARP hardware. (BZ#822781)

* Prior to the release of Red Hat Enterprise Linux 6.3, the kernel created
the InfiniBand device files in the wrong place and a udev rules file was
used to force the devices to be created in the proper place. With the
update to 6.3, the kernel was fixed to create the InfiniBand device files
in the proper place, and so the udev rules file was removed as no longer
being necessary. However, a bug in the kernel device creation meant that,
although the devices were now being created in the right place, they had
incorrect permissions. Consequently, when users attempted to run an RDMA
application as a non-root user, the application failed to get the necessary
permissions to use the RDMA device and the application terminated. This
update puts a new udev rules file in place. It no longer attempts to create
the InfiniBand devices since they already exist, but it does correct the
device permissions on the files. (BZ#834428)

* Previously, using the "perfquery -C" command with a host name caused the
perfquery utility to become unresponsive. The list of controllers to
process was never cleared and the process looped infinitely on a single
controller. A patch has been applied to make sure that in the case where
the user passes in the -C option, the controller list is cleared out once
that controller has been processed. As a result, perfquery now works as
expected in the scenario described. (BZ#847129)

* The OpenSM init script did not handle the case where there were no
configuration files under "/etc/rdma/opensm.conf.*". With this update, the
script as been patched and the InfiniBand Subnet Manager, OpenSM, now
starts as expected in the scenario described. (BZ#862857)

This update also adds the following enhancement:

* This update provides an updated mlx4_ib Mellanox driver which includes
Single Root I/O Virtualization (SR-IOV) support. (BZ#869737)

All users of RDMA are advised to upgrade to these updated packages, which
fix these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4518</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130509"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130511" severity="medium">
    <xccdf:title>RHSA-2013:0511: pki-core security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Certificate System is an enterprise software system designed to
manage enterprise public key infrastructure (PKI) deployments. PKI Core
contains fundamental packages required by Red Hat Certificate System, which
comprise the Certificate Authority (CA) subsystem.

Note: The Certificate Authority component provided by this advisory cannot
be used as a standalone server. It is installed and operates as a part of
Identity Management (the IPA component) in Red Hat Enterprise Linux.

Multiple cross-site scripting flaws were discovered in Certificate System.
An attacker could use these flaws to perform a cross-site scripting (XSS)
attack against victims using Certificate System's web interface.
(CVE-2012-4543)

This update also fixes the following bugs:

* Previously, due to incorrect conversion of large integers while
generating a new serial number, some of the most significant bits in the
serial number were truncated. Consequently, the serial number generated for
certificates was sometimes smaller than expected and this incorrect
conversion in turn led to a collision if a certificate with the smaller
number already existed in the database. This update removes the incorrect
integer conversion so that no serial numbers are truncated. As a result,
the installation wizard proceeds as expected. (BZ#841663)

* The certificate authority used a different profile for issuing the audit
certificate than it used for renewing it. The issuing profile was for two
years, and the renewal was for six months. They should both be for two
years. This update sets the default and constraint parameters in the
caSignedLogCert.cfg audit certificate renewal profile to two years.
(BZ#844459)

This update also adds the following enhancements:

* IPA (Identity, Policy and Audit) now provides an improved way to
determine that PKI is up and ready to service requests. Checking the
service status was not sufficient. This update creates a mechanism for
clients to determine that the PKI subsystem is up using the getStatus()
function to query the cs.startup_state in CS.cfg. (BZ#858864)

* This update increases the default root CA validity period from eight
years to twenty years. (BZ#891985) 

All users of pki-core are advised to upgrade to these updated packages,
which fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4543</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130511"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130512" severity="low">
    <xccdf:title>RHSA-2013:0512: httpd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages contain the Apache HTTP Server (httpd), which is the
namesake project of The Apache Software Foundation.

An input sanitization flaw was found in the mod_negotiation Apache HTTP
Server module. A remote attacker able to upload or create files with
arbitrary names in a directory that has the MultiViews options enabled,
could use this flaw to conduct cross-site scripting attacks against users
visiting the site. (CVE-2008-0455, CVE-2012-2687)

It was discovered that mod_proxy_ajp, when used in configurations with
mod_proxy in load balancer mode, would mark a back-end server as failed
when request processing timed out, even when a previous AJP (Apache JServ
Protocol) CPing request was responded to by the back-end. A remote
attacker able to make a back-end use an excessive amount of time to
process a request could cause mod_proxy to not send requests to back-end
AJP servers for the retry timeout period or until all back-end servers
were marked as failed. (CVE-2012-4557)

These updated httpd packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 6.4 Technical Notes, linked
to in the References, for information on the most significant of these
changes.

All users of httpd are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. After installing the updated packages, the httpd daemon will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2008-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4557</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130512"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130514" severity="medium">
    <xccdf:title>RHSA-2013:0514: php security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that PHP did not check for carriage returns in HTTP headers,
allowing intended HTTP response splitting protections to be bypassed.
Depending on the web browser the victim is using, a remote attacker could
use this flaw to perform HTTP response splitting attacks. (CVE-2011-1398)

An integer signedness issue, leading to a heap-based buffer underflow, was
found in the PHP scandir() function. If a remote attacker could upload an
excessively large number of files to a directory the scandir() function
runs on, it could cause the PHP interpreter to crash or, possibly, execute
arbitrary code. (CVE-2012-2688)

It was found that PHP did not correctly handle the magic_quotes_gpc
configuration directive. This could result in magic_quotes_gpc input
escaping not being applied in all cases, possibly making it easier for a
remote attacker to perform SQL injection attacks. (CVE-2012-0831)

These updated php packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All users of php are advised to upgrade to these updated packages, which
fix these issues and add these enhancements. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0514</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2688</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130514"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130515" severity="medium">
    <xccdf:title>RHSA-2013:0515: openchange security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The openchange packages provide libraries to access Microsoft Exchange
servers using native protocols. Evolution-MAPI uses these libraries to
integrate the Evolution PIM application with Microsoft Exchange servers.

A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL)
compiler. As OpenChange uses code generated by PIDL, this could have
resulted in buffer overflows in the way OpenChange handles RPC calls. With
this update, the code has been generated with an updated version of PIDL to
correct this issue. (CVE-2012-1182)

The openchange packages have been upgraded to upstream version 1.0, which
provides a number of bug fixes and enhancements over the previous version,
including support for the rebased samba4 packages and several API changes.
(BZ#767672, BZ#767678)

This update also fixes the following bugs:

* When the user tried to modify a meeting with one required attendee and
himself as the organizer, a segmentation fault occurred in the memcpy()
function. Consequently, the evolution-data-server application terminated
unexpectedly with a segmentation fault. This bug has been fixed and
evolution-data-server no longer crashes in the described scenario.
(BZ#680061)

* Prior to this update, OpenChange 1.0 was unable to send messages with
a large message body or with extensive attachment. This was caused by minor
issues in OpenChange's exchange.idl definitions. This bug has been fixed
and OpenChange now sends extensive messages without complications.
(BZ#870405)

All users of openchange are advised to upgrade to these updated packages,
which fix these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1182</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130515"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130516" severity="low">
    <xccdf:title>RHSA-2013:0516: evolution security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the GNOME mailer, calendar, contact manager and communication
tool. The components which make up Evolution are tightly integrated with
one another and act as a seamless personal information-management tool.

The way Evolution handled mailto URLs allowed any file to be attached to
the new message. This could lead to information disclosure if the user did
not notice the attached file before sending the message. With this update,
mailto URLs cannot be used to attach certain files, such as hidden files or
files in hidden directories, files in the /etc/ directory, or files
specified using a path containing "..". (CVE-2011-3201)

Red Hat would like to thank Matt McCutchen for reporting this issue.

This update also fixes the following bugs:

* Creating a contact list with contact names encoded in UTF-8 caused these
names to be displayed in the contact list editor in the ASCII encoding
instead of UTF-8. This bug has been fixed and the contact list editor now
displays the names in the correct format. (BZ#707526)

* Due to a bug in the evolution-alarm-notify process, calendar appointment
alarms did not appear in some types of calendars. The underlying source
code has been modified and calendar notifications work as expected.
(BZ#805239)

* An attempt to print a calendar month view as a PDF file caused Evolution
to terminate unexpectedly. This update applies a patch to fix this bug and
Evolution no longer crashes in this situation. (BZ#890642)

All evolution users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Evolution must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3201</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130516"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130517" severity="low">
    <xccdf:title>RHSA-2013:0517: util-linux-ng security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The util-linux-ng packages contain a large variety of low-level system
utilities that are necessary for a Linux operating system to function.

An information disclosure flaw was found in the way the mount command
reported errors. A local attacker could use this flaw to determine the
existence of files and directories they do not have access to.
(CVE-2013-0157)

These updated util-linux-ng packages include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All users of util-linux-ng are advised to upgrade to these updated
packages, which contain backported patches to correct these issues and add
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0157</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130517"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130519" severity="medium">
    <xccdf:title>RHSA-2013:0519: openssh security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's Secure Shell (SSH) protocol implementation. These
packages include the core files necessary for the OpenSSH client and
server.

Due to the way the pam_ssh_agent_auth PAM module was built in Red Hat
Enterprise Linux 6, the glibc's error() function was called rather than the
intended error() function in pam_ssh_agent_auth to report errors. As these
two functions expect different arguments, it was possible for an attacker
to cause an application using pam_ssh_agent_auth to crash, disclose
portions of its memory or, potentially, execute arbitrary code.
(CVE-2012-5536)

Note that the pam_ssh_agent_auth module is not used in Red Hat Enterprise
Linux 6 by default.

This update also fixes the following bugs:

* All possible options for the new RequiredAuthentications directive were
not documented in the sshd_config man page. This update improves the man
page to document all the possible options. (BZ#821641)

* When stopping one instance of the SSH daemon (sshd), the sshd init script
(/etc/rc.d/init.d/sshd) stopped all sshd processes regardless of the PID of
the processes. This update improves the init script so that it only kills
processes with the relevant PID. As a result, the init script now works
more reliably in a multi-instance environment. (BZ#826720)

* Due to a regression, the ssh-copy-id command returned an exit status code
of zero even if there was an error in copying the key to a remote host.
With this update, a patch has been applied and ssh-copy-id now returns a
non-zero exit code if there is an error in copying the SSH certificate to a
remote host. (BZ#836650)

* When SELinux was disabled on the system, no on-disk policy was installed,
a user account was used for a connection, and no "~/.ssh" configuration was
present in that user's home directory, the SSH client terminated
unexpectedly with a segmentation fault when attempting to connect to
another system. A patch has been provided to address this issue and the
crashes no longer occur in the described scenario. (BZ#836655)

* The "HOWTO" document /usr/share/doc/openssh-ldap-5.3p1/HOWTO.ldap-keys
incorrectly documented the use of the AuthorizedKeysCommand directive.
This update corrects the document. (BZ#857760)

This update also adds the following enhancements:

* When attempting to enable SSH for use with a Common Access Card (CAC),
the ssh-agent utility read all the certificates in the card even though
only the ID certificate was needed. Consequently, if a user entered their
PIN incorrectly, then the CAC was locked, as a match for the PIN was
attempted against all three certificates. With this update, ssh-add does
not try the same PIN for every certificate if the PIN fails for the first
one. As a result, the CAC will not be disabled if a user enters their PIN
incorrectly. (BZ#782912)

* This update adds a "netcat mode" to SSH. The "ssh -W host:port ..."
command connects standard input and output (stdio) on a client to a single
port on a server. As a result, SSH can be used to route connections via
intermediate servers. (BZ#860809)

* Due to a bug, arguments for the RequiredAuthentications2 directive were
not stored in a Match block. Consequently, parsing of the config file was
not in accordance with the man sshd_config documentation. This update fixes
the bug and users can now use the required authentication feature to
specify a list of authentication methods as expected according to the man
page. (BZ#869903)

All users of openssh are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing this
update, the OpenSSH server daemon (sshd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5536</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130519"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130520" severity="low">
    <xccdf:title>RHSA-2013:0520: dovecot security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server, written with security primarily in mind, for
Linux and other UNIX-like systems. It also contains a small POP3 server. It
supports mail in either of maildir or mbox formats. The SQL drivers and
authentication plug-ins are provided as sub-packages.

Two flaws were found in the way some settings were enforced by the
script-login functionality of Dovecot. A remote, authenticated user could
use these flaws to bypass intended access restrictions or conduct a
directory traversal attack by leveraging login scripts. (CVE-2011-2166,
CVE-2011-2167)

A flaw was found in the way Dovecot performed remote server identity
verification, when it was configured to proxy IMAP and POP3 connections to
remote hosts using TLS/SSL protocols. A remote attacker could use this flaw
to conduct man-in-the-middle attacks using an X.509 certificate issued by
a trusted Certificate Authority (for a different name). (CVE-2011-4318)

This update also fixes the following bug:

* When a new user first accessed their IMAP inbox, Dovecot was, under some
circumstances, unable to change the group ownership of the inbox directory
in the user's Maildir location to match that of the user's mail spool
(/var/mail/$USER). This correctly generated an "Internal error occurred"
message. However, with a subsequent attempt to access the inbox, Dovecot
saw that the directory already existed and proceeded with its operation,
leaving the directory with incorrectly set permissions. This update
corrects the underlying permissions setting error. When a new user now
accesses their inbox for the first time, and it is not possible to set
group ownership, Dovecot removes the created directory and generates an
error message instead of keeping the directory with incorrect group
ownership. (BZ#697620)

Users of dovecot are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the dovecot service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-2167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4318</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130520"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130521" severity="medium">
    <xccdf:title>RHSA-2013:0521: pam security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs to handle authentication.

A stack-based buffer overflow flaw was found in the way the pam_env module
parsed users' "~/.pam_environment" files. If an application's PAM
configuration contained "user_readenv=1" (this is not the default), a
local attacker could use this flaw to crash the application or, possibly,
escalate their privileges. (CVE-2011-3148)

A denial of service flaw was found in the way the pam_env module expanded
certain environment variables. If an application's PAM configuration
contained "user_readenv=1" (this is not the default), a local attacker
could use this flaw to cause the application to enter an infinite loop.
(CVE-2011-3149)

Red Hat would like to thank Kees Cook of the Google ChromeOS Team for
reporting the CVE-2011-3148 and CVE-2011-3149 issues.

These updated pam packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Users
are directed to the Red Hat Enterprise Linux 6.4 Technical Notes, linked
to in the References, for information on the most significant of these
changes.

All pam users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-3149</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130521"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130522" severity="medium">
    <xccdf:title>RHSA-2013:0522: gdb security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Debugger (GDB) allows debugging of programs written in C, C++,
Java, and other languages by executing them in a controlled fashion and
then printing out their data.

GDB tried to auto-load certain files (such as GDB scripts, Python scripts,
and a thread debugging library) from the current working directory when
debugging programs. This could result in the execution of arbitrary code
with the user's privileges when GDB was run in a directory that has
untrusted content. (CVE-2011-4355)

With this update, GDB no longer auto-loads files from the current directory
and only trusts certain system directories by default. The list of trusted
directories can be viewed and modified using the "show auto-load safe-path"
and "set auto-load safe-path" GDB commands. Refer to the GDB manual, linked
to in the References, for further information.

This update also fixes the following bugs:

* When a struct member was at an offset greater than 256 MB, the resulting
bit position within the struct overflowed and caused an invalid memory
access by GDB. With this update, the code has been modified to ensure that
GDB can access such positions. (BZ#795424)

* When a thread list of the core file became corrupted, GDB did not print
this list but displayed the "Cannot find new threads: generic error" error
message instead. With this update, GDB has been modified and it now prints
the thread list of the core file as expected. (BZ#811648)

* GDB did not properly handle debugging of multiple binaries with the
same build ID. This update modifies GDB to use symbolic links created for
particular binaries so that debugging of binaries that share a build ID
now proceeds as expected. Debugging of live programs and core files is
now more user-friendly. (BZ#836966)

All users of gdb are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-4355</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130522"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130523" severity="low">
    <xccdf:title>RHSA-2013:0523: ccid security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Chip/Smart Card Interface Devices (CCID) is a USB smart card reader
standard followed by most modern smart card readers. The ccid package
provides a Generic, USB-based CCID driver for readers, which follow this
standard.

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card's serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting a
specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* Previously, CCID only recognized smart cards with 5V power supply. With
this update, CCID also supports smart cards with different power supply.
(BZ#808115)

All users of ccid are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0523</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4530</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130523"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130525" severity="medium">
    <xccdf:title>RHSA-2013:0525: pcsc-lite security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PC/SC Lite provides a Windows SCard compatible interface for communicating
with smart cards, smart card readers, and other security tokens.

A stack-based buffer overflow flaw was found in the way pcsc-lite decoded
certain attribute values of Answer-to-Reset (ATR) messages. A local
attacker could use this flaw to execute arbitrary code with the privileges
of the user running the pcscd daemon (root, by default), by inserting a
specially-crafted smart card. (CVE-2010-4531)

This update also fixes the following bugs:

* Due to an error in the init script, the chkconfig utility did not
automatically place the pcscd init script after the start of the HAL
daemon. Consequently, the pcscd service did not start automatically at boot
time. With this update, the pcscd init script has been changed to
explicitly start only after HAL is up, thus fixing this bug. (BZ#788474,
BZ#814549)

* Because the chkconfig settings and the startup files in the /etc/rc.d/
directory were not changed during the update described in the
RHBA-2012:0990 advisory, the user had to update the chkconfig settings
manually to fix the problem. Now, the chkconfig settings and the startup
files in the /etc/rc.d/ directory are automatically updated as expected.
(BZ#834803)

* Previously, the SCardGetAttrib() function did not work properly and
always returned the "SCARD_E_INSUFFICIENT_BUFFER" error regardless of the
actual buffer size. This update applies a patch to fix this bug and the
SCardGetAttrib() function now works as expected. (BZ#891852)

All users of pcsc-lite are advised to upgrade to these updated packages,
which fix these issues. After installing this update, the pcscd daemon will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0525</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4531</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130525"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130526" severity="low">
    <xccdf:title>RHSA-2013:0526: automake security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Automake is a tool for automatically generating Makefile.in files compliant
with the GNU Coding Standards.

It was found that the distcheck rule in Automake-generated Makefiles made a
directory world-writable when preparing source archives. If a malicious,
local user could access this directory, they could execute arbitrary code
with the privileges of the user running "make distcheck". (CVE-2012-3386)

Red Hat would like to thank Jim Meyering for reporting this issue. Upstream
acknowledges Stefano Lattarini as the original reporter.

Users of automake are advised to upgrade to this updated package, which
corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3386</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130526"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130528" severity="low">
    <xccdf:title>RHSA-2013:0528: ipa security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud-based
enterprise environments. It integrates components of the Red Hat Directory
Server, MIT Kerberos, Red Hat Certificate System, NTP, and DNS. It provides
web browser and command-line interfaces. Its administration tools allow an
administrator to quickly install, set up, and administer a group of domain
controllers to meet the authentication and identity management requirements
of large-scale Linux and UNIX deployments.

It was found that the current default configuration of IPA servers did not
publish correct CRLs (Certificate Revocation Lists). The default
configuration specifies that every replica is to generate its own CRL;
however, this can result in inconsistencies in the CRL contents provided to
clients from different Identity Management replicas. More specifically, if
a certificate is revoked on one Identity Management replica, it will not
show up on another Identity Management replica. (CVE-2012-4546)

These updated ipa packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

Users are advised to upgrade to these updated ipa packages, which fix these
issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4546</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130528"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130550" severity="medium">
    <xccdf:title>RHSA-2013:0550: bind security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.
DNS64 is used to automatically generate DNS records so IPv6 based clients
can access IPv4 systems through a NAT64 server.

A flaw was found in the DNS64 implementation in BIND when using Response
Policy Zones (RPZ). If a remote attacker sent a specially-crafted query to
a named server that is using RPZ rewrite rules, named could exit
unexpectedly with an assertion failure. Note that DNS64 support is not
enabled by default. (CVE-2012-5689)

This update also adds the following enhancement:

* Previously, it was impossible to configure the the maximum number of
responses sent per second to one client. This allowed remote attackers to
conduct traffic amplification attacks using DNS queries with spoofed source
IP addresses. With this update, it is possible to use the new "rate-limit"
configuration option in named.conf and configure the maximum number of
queries which the server responds to. Refer to the BIND documentation for
more details about the "rate-limit" option. (BZ#906312)

All bind users are advised to upgrade to these updated packages, which
contain patches to correct this issue and add this enhancement. After
installing the update, the BIND daemon (named) will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0550</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5689</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130550"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130567" severity="high">
    <xccdf:title>RHSA-2013:0567: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A race condition was found in the way the Linux kernel's ptrace
implementation handled PTRACE_SETREGS requests when the debuggee was woken
due to a SIGKILL signal instead of being stopped. A local, unprivileged
user could use this flaw to escalate their privileges. (CVE-2013-0871,
Important)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0567</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130567"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130568" severity="high">
    <xccdf:title>RHSA-2013:0568: dbus-glib security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>dbus-glib is an add-on library to integrate the standard D-Bus library with
the GLib main loop and threading model.

A flaw was found in the way dbus-glib filtered the message sender (message
source subject) when the "NameOwnerChanged" signal was received. This
could trick a system service using dbus-glib (such as fprintd) into
believing a signal was sent from a privileged process, when it was not. A
local attacker could use this flaw to escalate their privileges.
(CVE-2013-0292)

All dbus-glib users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against dbus-glib, such as fprintd and NetworkManager, must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0292</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130568"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130580" severity="medium">
    <xccdf:title>RHSA-2013:0580: cups security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Common UNIX Printing System (CUPS) provides a portable printing layer
for Linux, UNIX, and similar operating systems.

It was discovered that CUPS administrative users (members of the
SystemGroups groups) who are permitted to perform CUPS configuration
changes via the CUPS web interface could manipulate the CUPS configuration
to gain unintended privileges. Such users could read or write arbitrary
files with the privileges of the CUPS daemon, possibly allowing them to
run arbitrary code with root privileges. (CVE-2012-5519)

After installing this update, the ability to change certain CUPS
configuration directives remotely will be disabled by default. The newly
introduced ConfigurationChangeRestriction directive can be used to enable
the changing of the restricted directives remotely. Refer to Red Hat
Bugzilla bug 875898 for more details and the list of restricted directives.

All users of cups are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5519</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130580"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130581" severity="medium">
    <xccdf:title>RHSA-2013:0581: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in the way libxml2 performed string
substitutions when entity values for entity references replacement was
enabled. A remote attacker could provide a specially-crafted XML file that,
when processed by an application linked against libxml2, would lead to
excessive CPU consumption. (CVE-2013-0338)

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. The desktop must
be restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0338</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130581"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130587" severity="medium">
    <xccdf:title>RHSA-2013:0587: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that OpenSSL leaked timing information when decrypting
TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites
were used. A remote attacker could possibly use this flaw to retrieve plain
text from the encrypted packets by using a TLS/SSL or DTLS server as a
padding oracle. (CVE-2013-0169)

A NULL pointer dereference flaw was found in the OCSP response verification
in OpenSSL. A malicious OCSP server could use this flaw to crash
applications performing OCSP verification by sending a specially-crafted
response. (CVE-2013-0166)

It was discovered that the TLS/SSL protocol could leak information about
plain text when optional compression was used. An attacker able to control
part of the plain text sent over an encrypted TLS/SSL connection could
possibly use this flaw to recover other portions of the plain text.
(CVE-2012-4929)

Note: This update disables zlib compression, which was previously enabled
in OpenSSL by default. Applications using OpenSSL now need to explicitly
enable zlib compression to use it.

It was found that OpenSSL read certain environment variables even when used
by a privileged (setuid or setgid) application. A local attacker could use
this flaw to escalate their privileges. No application shipped with Red Hat
Enterprise Linux 5 and 6 was affected by this problem. (BZ#839735)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the
system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130587"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130588" severity="medium">
    <xccdf:title>RHSA-2013:0588: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

It was discovered that GnuTLS leaked timing information when decrypting
TLS/SSL protocol encrypted records when CBC-mode cipher suites were used.
A remote attacker could possibly use this flaw to retrieve plain text from
the encrypted packets by using a TLS/SSL server as a padding oracle.
(CVE-2013-1619)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the GnuTLS library must be restarted,
or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0588</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1619</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130588"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130589" severity="medium">
    <xccdf:title>RHSA-2013:0589: git security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Git is a fast, scalable, distributed revision control system.

It was discovered that Git's git-imap-send command, a tool to send a
collection of patches from standard input (stdin) to an IMAP folder, did
not properly perform SSL X.509 v3 certificate validation on the IMAP
server's certificate, as it did not ensure that the server's hostname
matched the one provided in the CN field of the server's certificate. A
rogue server could use this flaw to conduct man-in-the-middle attacks,
possibly leading to the disclosure of sensitive information.
(CVE-2013-0308)

All git users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0589</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0308</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130589"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130590" severity="high">
    <xccdf:title>RHSA-2013:0590: nss-pam-ldapd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The nss-pam-ldapd packages provide the nss-pam-ldapd daemon (nslcd), which
uses a directory server to lookup name service information on behalf of a
lightweight nsswitch module.

An array index error, leading to a stack-based buffer overflow flaw, was
found in the way nss-pam-ldapd managed open file descriptors. An attacker
able to make a process have a large number of open file descriptors and
perform name lookups could use this flaw to cause the process to crash or,
potentially, execute arbitrary code with the privileges of the user running
the process. (CVE-2013-0288)

Red Hat would like to thank Garth Mollett for reporting this issue.

All users of nss-pam-ldapd are advised to upgrade to these updated
packages, which contain a backported patch to fix this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0288</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130590"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130594" severity="low">
    <xccdf:title>RHSA-2013:0594: kernel security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Buffer overflow flaws were found in the udf_load_logicalvol() function in
the Universal Disk Format (UDF) file system implementation in the Linux
kernel. An attacker with physical access to a system could use these flaws
to cause a denial of service or escalate their privileges. (CVE-2012-3400,
Low)

This update also fixes the following bugs:

* Previously, race conditions could sometimes occur in interrupt handling 
on the Emulex BladeEngine 2 (BE2) controllers, causing the network adapter
to become unresponsive. This update provides a series of patches for the 
be2net driver, which prevents the race from occurring. The network cards 
using BE2 chipsets no longer hang due to incorrectly handled interrupt 
events. (BZ#884704)

* A boot-time memory allocation pool (the DMI heap) is used to keep the
list of Desktop Management Interface (DMI) devices during the system boot.
Previously, the size of the DMI heap was only 2048 bytes on the AMD64 and
Intel 64 architectures and the DMI heap space could become easily depleted
on some systems, such as the IBM System x3500 M2. A subsequent OOM failure
could, under certain circumstances, lead to a NULL pointer entry being
stored in the DMI device list. Consequently, scanning of such a corrupted
DMI device list resulted in a kernel panic. The boot-time memory allocation
pool for the AMD64 and Intel 64 architectures has been enlarged to 4096
bytes and the routines responsible for populating the DMI device list have
been modified to skip entries if their name string is NULL. The kernel no
longer panics in this scenario. (BZ#902683)

* The size of the buffer used to print the kernel taint output on kernel
panic was too small, which resulted in the kernel taint output not being
printed completely sometimes. With this update, the size of the buffer has
been adjusted and the kernel taint output is now displayed properly.
(BZ#905829)

* The code to print the kernel taint output contained a typographical
error. Consequently, the kernel taint output, which is displayed on kernel
panic, could not provide taint error messages for unsupported hardware.
This update fixes the typo and the kernel taint output is now displayed
correctly. (BZ#885063)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0594</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3400</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130594"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130599" severity="high">
    <xccdf:title>RHSA-2013:0599: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A flaw was found in the way QEMU emulated the e1000 network interface card
when the host was configured to accept jumbo network frames, and a
fully-virtualized guest using the e1000 emulated driver was not. A remote
attacker could use this flaw to crash the guest or, potentially, execute
arbitrary code with root privileges in the guest. (CVE-2012-6075)

All users of xen are advised to upgrade to these updated packages, which
correct this issue. After installing the updated packages, all running
fully-virtualized guests must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6075</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130599"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130602" severity="high">
    <xccdf:title>RHSA-2013:0602: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

An integer overflow flaw was found in the way the 2D component handled
certain sample model instances. A specially-crafted sample model instance
could cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

It was discovered that the 2D component did not properly reject certain
malformed images. Specially-crafted raster parameters could cause Java
Virtual Machine memory corruption and, possibly, lead to arbitrary code
execution with virtual machine privileges. (CVE-2013-1493)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.8. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130602"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130603" severity="high">
    <xccdf:title>RHSA-2013:0603: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

An integer overflow flaw was found in the way the 2D component handled
certain sample model instances. A specially-crafted sample model instance
could cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

It was discovered that the 2D component did not properly reject certain
malformed images. Specially-crafted raster parameters could cause Java
Virtual Machine memory corruption and, possibly, lead to arbitrary code
execution with virtual machine privileges. (CVE-2013-1493)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.8. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130603"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130604" severity="high">
    <xccdf:title>RHSA-2013:0604: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

An integer overflow flaw was found in the way the 2D component handled
certain sample model instances. A specially-crafted sample model instance
could cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

It was discovered that the 2D component did not properly reject certain
malformed images. Specially-crafted raster parameters could cause Java
Virtual Machine memory corruption and, possibly, lead to arbitrary code
execution with virtual machine privileges. (CVE-2013-1493)

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.9. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130604"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130605" severity="high">
    <xccdf:title>RHSA-2013:0605: java-1.6.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

An integer overflow flaw was found in the way the 2D component handled
certain sample model instances. A specially-crafted sample model instance
could cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

It was discovered that the 2D component did not properly reject certain
malformed images. Specially-crafted raster parameters could cause Java
Virtual Machine memory corruption and, possibly, lead to arbitrary code
execution with virtual machine privileges. (CVE-2013-1493)

Note: If your system has not yet been upgraded to Red Hat Enterprise Linux
6.4 and the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website. Thus, this
update has been rated as having critical security impact as a one time
exception. The icedtea-web package as provided with Red Hat Enterprise
Linux 6.4 uses OpenJDK 7 instead.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.9. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130605"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130608" severity="high">
    <xccdf:title>RHSA-2013:0608: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way QEMU-KVM emulated the e1000 network interface
card when the host was configured to accept jumbo network frames, and a
guest using the e1000 emulated driver was not. A remote attacker could use
this flaw to crash the guest or, potentially, execute arbitrary code with
root privileges in the guest. (CVE-2012-6075)

All users of kvm are advised to upgrade to these updated packages, which
contain backported patches to correct this issue. Note that the procedure
in the Solution section must be performed before this update will take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6075</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130608"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130609" severity="high">
    <xccdf:title>RHSA-2013:0609: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

A flaw was found in the way QEMU-KVM emulated the e1000 network interface
card when the host was configured to accept jumbo network frames, and a
guest using the e1000 emulated driver was not. A remote attacker could use
this flaw to crash the guest or, potentially, execute arbitrary code with
root privileges in the guest. (CVE-2012-6075)

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6075</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130609"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130611" severity="medium">
    <xccdf:title>RHSA-2013:0611: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

It was discovered that Ruby's REXML library did not properly restrict XML
entity expansion. An attacker could use this flaw to cause a denial of
service by tricking a Ruby application using REXML to read text nodes from
specially-crafted XML content, which will result in REXML consuming large
amounts of system memory. (CVE-2013-1821)

All users of Ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0611</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1821</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130611"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130612" severity="medium">
    <xccdf:title>RHSA-2013:0612: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

It was discovered that Ruby's REXML library did not properly restrict XML
entity expansion. An attacker could use this flaw to cause a denial of
service by tricking a Ruby application using REXML to read text nodes from
specially-crafted XML content, which will result in REXML consuming large
amounts of system memory. (CVE-2013-1821)

It was found that the RHSA-2011:0910 update did not correctly fix the
CVE-2011-1005 issue, a flaw in the method for translating an exception
message into a string in the Exception class. A remote attacker could use
this flaw to bypass safe level 4 restrictions, allowing untrusted (tainted)
code to modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2012-4481)

The CVE-2012-4481 issue was discovered by Vit Ondruch of Red Hat.

All users of Ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1821</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130612"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130614" severity="high">
    <xccdf:title>RHSA-2013:0614: xulrunner security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>XULRunner provides the XUL Runtime environment for applications using the
Gecko layout engine.

A flaw was found in the way XULRunner handled malformed web content. A web
page containing malicious content could cause an application linked against
XULRunner (such as Mozilla Firefox) to crash or execute arbitrary code with
the privileges of the user running the application. (CVE-2013-0787)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges VUPEN Security via the TippingPoint Zero Day
Initiative project as the original reporter.

For technical details regarding this flaw, refer to the Mozilla security
advisories. You can find a link to the Mozilla advisories in the References
section of this erratum.

All XULRunner users should upgrade to these updated packages, which correct
this issue. After installing the update, applications using XULRunner must
be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0614</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0787</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130614"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130621" severity="high">
    <xccdf:title>RHSA-2013:0621: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way file permission checks for the
"/dev/cpu/[x]/msr" files were performed in restricted root environments 
(for example, when using a capability-based security model). A local user 
with the ability to write to these files could use this flaw to escalate 
their privileges to kernel level, for example, by writing to the 
SYSENTER_EIP_MSR register. (CVE-2013-0268, Important)

* A race condition was found in the way the Linux kernel's ptrace
implementation handled PTRACE_SETREGS requests when the debuggee was woken
due to a SIGKILL signal instead of being stopped. A local, unprivileged
user could use this flaw to escalate their privileges. (CVE-2013-0871,
Important)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0268</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0871</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130621"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130623" severity="high">
    <xccdf:title>RHSA-2013:0623: tomcat6 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container.

It was found that when an application used FORM authentication, along with
another component that calls request.setUserPrincipal() before the call to
FormAuthenticator#authenticate() (such as the Single-Sign-On valve), it was
possible to bypass the security constraint checks in the FORM authenticator
by appending "/j_security_check" to the end of a URL. A remote attacker
with an authenticated session on an affected application could use this
flaw to circumvent authorization controls, and thereby access resources not
permitted by the roles associated with their authenticated session.
(CVE-2012-3546)

A flaw was found in the way Tomcat handled sendfile operations when using
the HTTP NIO (Non-Blocking I/O) connector and HTTPS. A remote attacker
could use this flaw to cause a denial of service (infinite loop). The HTTP
blocking IO (BIO) connector, which is not vulnerable to this issue, is used
by default in Red Hat Enterprise Linux 6. (CVE-2012-4534)

Multiple weaknesses were found in the Tomcat DIGEST authentication
implementation, effectively reducing the security normally provided by
DIGEST authentication. A remote attacker could use these flaws to perform
replay attacks in some circumstances. (CVE-2012-5885, CVE-2012-5886,
CVE-2012-5887)

Users of Tomcat should upgrade to these updated packages, which correct
these issues. Tomcat must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5886</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5887</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130623"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130627" severity="high">
    <xccdf:title>RHSA-2013:0627: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the processing of malformed content. Malicious content
could cause Thunderbird to crash or execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2013-0787)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges VUPEN Security via the TippingPoint Zero Day
Initiative project as the original reporter.

Note: This issue cannot be exploited by a specially-crafted HTML mail
message as JavaScript is disabled by default for mail messages. It could
be exploited another way in Thunderbird, for example, when viewing the full
remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
corrects this issue. After installing the update, Thunderbird must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0787</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130627"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130628" severity="medium">
    <xccdf:title>RHSA-2013:0628: 389-ds-base security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

A flaw was found in the way LDAPv3 control data was handled by 389
Directory Server. If a malicious user were able to bind to the directory
(even anonymously) and send an LDAP request containing crafted LDAPv3
control data, they could cause the server to crash, denying service to the
directory. (CVE-2013-0312)

The CVE-2013-0312 issue was discovered by Thierry Bordaz of Red Hat.

This update also fixes the following bugs:

* After an upgrade from Red Hat Enterprise Linux 6.3 to version 6.4, the
upgrade script did not update the schema file for the PamConfig object
class. Consequently, new features for PAM such as configuration of multiple
instances and pamFilter attribute could not be used because of the schema
violation. With this update, the upgrade script updates the schema file for
the PamConfig object class and new features function properly. (BZ#910994)

* Previously, the valgrind test suite reported recurring memory leaks in
the modify_update_last_modified_attr() function. The size of the leaks
averaged between 60-80 bytes per modify call. In environments where modify
operations were frequent, this caused significant problems. Now, memory
leaks no longer occur in the modify_update_last_modified_attr() function.
(BZ#910995)

* The Directory Server (DS) failed when multi-valued attributes were
replaced. The problem occurred when replication was enabled, while the
server executing the modification was configured as a single master and
there was at least one replication agreement. Consequently, the
modification requests were refused by the master server, which returned a
code 20 "Type or value exists" error message. These requests were
replacements of multi-valued attributes, and the error only occurred when
one of the new values matched one of the current values of the attribute,
but had a different letter case. Now, modification requests function
properly and no longer return code 20 errors. (BZ#910996)

* The DNA (distributed numeric assignment) plug-in, under certain
conditions, could log error messages with the "DB_LOCK_DEADLOCK" error
code when attempting to create an entry with a uidNumber attribute. Now,
DNA handles this case properly and errors no longer occur during attempts
to create entries with uidNumber attributes. (BZ#911467)

* Posix Winsync plugin was calling an internal modify function which was
not necessary. The internal modify call failed and logged an error message
"slapi_modify_internal_set_pb: NULL parameter" which was not clear. This
patch stops calling the internal modify function if it is not necessary and
the cryptic error message is not observed. (BZ#911468)

* Previously, under certain conditions, the dse.ldif file had 0 bytes after
a server termination or when the machine was powered off. Consequently,
after the system was brought up, a DS or IdM system could be unable to
restart, leading to production server outages. Now, the server mechanism by
which the dse.ldif is written is more robust, and tries all available
backup dse.ldif files, and outages no longer occur. (BZ#911469)

* Due to an incorrect interpretation of an error code, a directory server
considered an invalid chaining configuration setting as the disk full error
and shut down unexpectedly. Now, a more appropriate error code is in use
and the server no longer shuts down from invalid chaining configuration
settings. (BZ#911474)

* While trying to remove a tombstone entry, the ns-slapd daemon terminated
unexpectedly with a segmentation fault. With this update, removal of
tombstone entries no longer causes crashes. (BZ#914305)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0312</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130628"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130630" severity="high">
    <xccdf:title>RHSA-2013:0630: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the xen_iret() function in the Linux kernel
used the DS (the CPU's Data Segment) register. A local, unprivileged user
in a 32-bit, para-virtualized Xen hypervisor guest could use this flaw to
crash the guest or, potentially, escalate their privileges. (CVE-2013-0228,
Important)

* A flaw was found in the way file permission checks for the
"/dev/cpu/[x]/msr" files were performed in restricted root environments
(for example, when using a capability-based security model). A local user
with the ability to write to these files could use this flaw to escalate
their privileges to kernel level, for example, by writing to the
SYSENTER_EIP_MSR register. (CVE-2013-0268, Important)

The CVE-2013-0228 issue was discovered by Andrew Jones of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0630</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0268</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130630"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130640" severity="high">
    <xccdf:title>RHSA-2013:0640: tomcat5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container.

It was found that when an application used FORM authentication, along with
another component that calls request.setUserPrincipal() before the call to
FormAuthenticator#authenticate() (such as the Single-Sign-On valve), it was
possible to bypass the security constraint checks in the FORM authenticator
by appending "/j_security_check" to the end of a URL. A remote attacker
with an authenticated session on an affected application could use this
flaw to circumvent authorization controls, and thereby access resources not
permitted by the roles associated with their authenticated session.
(CVE-2012-3546)

Multiple weaknesses were found in the Tomcat DIGEST authentication
implementation, effectively reducing the security normally provided by
DIGEST authentication. A remote attacker could use these flaws to perform
replay attacks in some circumstances. (CVE-2012-5885, CVE-2012-5886,
CVE-2012-5887)

Users of Tomcat should upgrade to these updated packages, which correct
these issues. Tomcat must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5886</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5887</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130640"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130646" severity="medium">
    <xccdf:title>RHSA-2013:0646: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A stack-based buffer overflow flaw was found in the Pidgin MXit protocol
plug-in. A malicious server or a remote attacker could use this flaw to
crash Pidgin by sending a specially-crafted HTTP request. (CVE-2013-0272)

A buffer overflow flaw was found in the Pidgin Sametime protocol plug-in.
A malicious server or a remote attacker could use this flaw to crash Pidgin
by sending a specially-crafted username. (CVE-2013-0273)

A buffer overflow flaw was found in the way Pidgin processed certain UPnP
responses. A remote attacker could send a specially-crafted UPnP response
that, when processed, would crash Pidgin. (CVE-2013-0274)

Red Hat would like to thank the Pidgin project for reporting the above
issues. Upstream acknowledges Daniel Atallah as the original reporter of
CVE-2013-0272.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0646</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0274</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130646"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130656" severity="medium">
    <xccdf:title>RHSA-2013:0656: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

When a client attempts to use PKINIT to obtain credentials from the KDC,
the client can specify, using an issuer and serial number, which of the
KDC's possibly-many certificates the client has in its possession, as a
hint to the KDC that it should use the corresponding key to sign its
response. If that specification was malformed, the KDC could attempt to
dereference a NULL pointer and crash. (CVE-2013-1415)

When a client attempts to use PKINIT to obtain credentials from the KDC,
the client will typically format its request to conform to the
specification published in RFC 4556. For interoperability reasons, clients
and servers also provide support for an older, draft version of that
specification. If a client formatted its request to conform to this older
version of the specification, with a non-default key agreement option, it
could cause the KDC to attempt to dereference a NULL pointer and crash.
(CVE-2012-1016)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1415</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130656"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130663" severity="medium">
    <xccdf:title>RHSA-2013:0663: sssd security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SSSD (System Security Services Daemon) provides a set of daemons to manage
access to remote directories and authentication mechanisms. It provides
NSS (Name Service Switch) and PAM (Pluggable Authentication Modules)
interfaces toward the system and a pluggable back end system to connect to
multiple different account sources.

When SSSD was configured as a Microsoft Active Directory client by using
the new Active Directory provider (introduced in RHSA-2013:0508), the
Simple Access Provider ("access_provider = simple" in
"/etc/sssd/sssd.conf") did not handle access control correctly. If any
groups were specified with the "simple_deny_groups" option (in sssd.conf),
all users were permitted access. (CVE-2013-0287)

The CVE-2013-0287 issue was discovered by Kaushik Banerjee of Red Hat.

This update also fixes the following bugs:

* If a group contained a member whose Distinguished Name (DN) pointed out
of any of the configured search bases, the search request that was
processing this particular group never ran to completion. To the user, this
bug manifested as a long timeout between requesting the group data and
receiving the result. A patch has been provided to address this bug and
SSSD now processes group search requests without delays. (BZ#907362)

* The pwd_expiration_warning should have been set for seven days, but
instead it was set to zero for Kerberos. This incorrect zero setting
returned the "always display warning if the server sends one" error message
and users experienced problems in environments like IPA or Active
Directory. Currently, the value setting for Kerberos is modified and this
issue no longer occurs. (BZ#914671)

All users of sssd are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0663</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0287</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130663"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130668" severity="medium">
    <xccdf:title>RHSA-2013:0668: boost security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The boost packages provide free, peer-reviewed, portable C++ source
libraries with emphasis on libraries which work well with the C++ Standard
Library.

A flaw was found in the way the ordered_malloc() routine in Boost sanitized
the 'next_size' and 'max_size' parameters when allocating memory. If an
application used the Boost C++ libraries for memory allocation, and
performed memory allocation based on user-supplied input, an attacker could
use this flaw to crash the application or, potentially, execute arbitrary
code with the privileges of the user running the application.
(CVE-2012-2677)

All users of boost are advised to upgrade to these updated packages, which
contain a backported patch to fix this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0668</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2677</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130668"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130669" severity="medium">
    <xccdf:title>RHSA-2013:0669: qt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

It was discovered that the QSharedMemory class implementation of the Qt
toolkit created shared memory segments with insecure permissions. A local
attacker could use this flaw to read or alter the contents of a particular
shared memory segment, possibly leading to their ability to obtain
sensitive information or influence the behavior of a process that is using
the shared memory segment. (CVE-2013-0254)

Red Hat would like to thank the Qt project for reporting this issue.
Upstream acknowledges Tim Brown and Mark Lowe of Portcullis Computer
Security Ltd. as the original reporters.

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications linked
against Qt libraries must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0254</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130669"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130683" severity="medium">
    <xccdf:title>RHSA-2013:0683: axis security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

Apache Axis did not verify that the server hostname matched the domain name
in the subject's Common Name (CN) or subjectAltName field in X.509
certificates. This could allow a man-in-the-middle attacker to spoof an SSL
server if they had a certificate that was valid for any domain name.
(CVE-2012-5784)

All users of axis are advised to upgrade to these updated packages, which
correct this issue. Applications using Apache Axis must be restarted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5784</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130683"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130685" severity="medium">
    <xccdf:title>RHSA-2013:0685: perl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Perl is a high-level programming language commonly used for system
administration utilities and web programming.

A heap overflow flaw was found in Perl. If a Perl application allowed
user input to control the count argument of the string repeat operator, an
attacker could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-5195)

A denial of service flaw was found in the way Perl's rehashing code
implementation, responsible for recalculation of hash keys and
redistribution of hash content, handled certain input. If an attacker
supplied specially-crafted input to be used as hash keys by a Perl
application, it could cause excessive memory consumption. (CVE-2013-1667)

It was found that the Perl CGI module, used to handle Common Gateway
Interface requests and responses, incorrectly sanitized the values for
Set-Cookie and P3P headers. If a Perl application using the CGI module
reused cookies values and accepted untrusted input from web browsers, a
remote attacker could use this flaw to alter member items of the cookie or
add new items. (CVE-2012-5526)

It was found that the Perl Locale::Maketext module, used to localize Perl
applications, did not properly handle backslashes or fully-qualified method
names. An attacker could possibly use this flaw to execute arbitrary Perl
code with the privileges of a Perl application that uses untrusted
Locale::Maketext templates. (CVE-2012-6329)

Red Hat would like to thank the Perl project for reporting CVE-2012-5195
and CVE-2013-1667. Upstream acknowledges Tim Brown as the original
reporter of CVE-2012-5195 and Yves Orton as the original reporter of
CVE-2013-1667.

All Perl users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running Perl programs
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0685</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130685"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130687" severity="medium">
    <xccdf:title>RHSA-2013:0687: pixman security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pixman is a pixel manipulation library for the X Window System and Cairo.

An integer overflow flaw was discovered in one of pixman's manipulation
routines. If a remote attacker could trick an application using pixman into
performing a certain manipulation, it could cause the application to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-1591)

Users are advised to upgrade to these updated packages, which contain
a backported patch to correct this issue. All applications using
pixman must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1591</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130687"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130689" severity="high">
    <xccdf:title>RHSA-2013:0689: bind security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the libdns library. A remote attacker
could use this flaw to send a specially-crafted DNS query to named that,
when processed, would cause named to use an excessive amount of memory, or
possibly crash. (CVE-2013-2266)

Note: This update disables the syntax checking of NAPTR (Naming Authority
Pointer) resource records.

This update also fixes the following bug:

* Previously, rebuilding the bind-dyndb-ldap source RPM failed with a
"/usr/include/dns/view.h:76:21: error: dns/rrl.h: No such file or
directory" error. (BZ#928439)

All bind users are advised to upgrade to these updated packages, which
contain patches to correct these issues. After installing the update, the
BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130689"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130690" severity="high">
    <xccdf:title>RHSA-2013:0690: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the libdns library. A remote attacker
could use this flaw to send a specially-crafted DNS query to named that,
when processed, would cause named to use an excessive amount of memory, or
possibly crash. (CVE-2013-2266)

Note: This update disables the syntax checking of NAPTR (Naming Authority
Pointer) resource records.

All bind97 users are advised to upgrade to these updated packages, which
contain a patch to correct this issue. After installing the update, the
BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130690"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130696" severity="high">
    <xccdf:title>RHSA-2013:0696: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-0788)

A flaw was found in the way Same Origin Wrappers were implemented in
Firefox. A malicious site could use this flaw to bypass the same-origin
policy and execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-0795)

A flaw was found in the embedded WebGL library in Firefox. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
Note: This issue only affected systems using the Intel Mesa graphics
drivers. (CVE-2013-0796)

An out-of-bounds write flaw was found in the embedded Cairo library in
Firefox. A web page containing malicious content could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2013-0800)

A flaw was found in the way Firefox handled the JavaScript history
functions. A malicious site could cause a web page to be displayed that has
a baseURI pointing to a different site, allowing cross-site scripting (XSS)
and phishing attacks. (CVE-2013-0793)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian
Holler, Milan Sreckovic, Joe Drew, Cody Crews, miaubiz, Abhishek Arya, and
Mariusz Mlynski as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.5 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.5 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0696</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0795</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0796</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0800</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130696"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130697" severity="high">
    <xccdf:title>RHSA-2013:0697: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-0788)

A flaw was found in the way Same Origin Wrappers were implemented in
Thunderbird. Malicious content could use this flaw to bypass the
same-origin policy and execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2013-0795)

A flaw was found in the embedded WebGL library in Thunderbird. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. Note: This issue
only affected systems using the Intel Mesa graphics drivers.
(CVE-2013-0796)

An out-of-bounds write flaw was found in the embedded Cairo library in
Thunderbird. Malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2013-0800)

A flaw was found in the way Thunderbird handled the JavaScript history
functions. Malicious content could cause a page to be displayed that
has a baseURI pointing to a different site, allowing cross-site scripting
(XSS) and phishing attacks. (CVE-2013-0793)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian
Holler, Milan Sreckovic, Joe Drew, Cody Crews, miaubiz, Abhishek Arya, and
Mariusz Mlynski as the original reporters of these issues.

Note: All issues except CVE-2013-0800 cannot be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.5 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0697</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0795</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0796</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0800</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130697"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130714" severity="medium">
    <xccdf:title>RHSA-2013:0714: stunnel security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>stunnel is a socket wrapper which can provide SSL (Secure Sockets Layer)
support to ordinary applications. For example, it can be used in
conjunction with imapd to create an SSL-secure IMAP server.

An integer conversion issue was found in stunnel when using Microsoft NT
LAN Manager (NTLM) authentication with the HTTP CONNECT tunneling method.
With this configuration, and using stunnel in SSL client mode on a 64-bit
system, an attacker could possibly execute arbitrary code with the
privileges of the stunnel process via a man-in-the-middle attack or by
tricking a user into using a malicious proxy. (CVE-2013-1762)

All stunnel users should upgrade to this updated package, which contains a
backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1762</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130714"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130727" severity="high">
    <xccdf:title>RHSA-2013:0727: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A flaw was found in the way KVM handled guest time updates when the buffer
the guest registered by writing to the MSR_KVM_SYSTEM_TIME machine state
register (MSR) crossed a page boundary. A privileged guest user could use
this flaw to crash the host or, potentially, escalate their privileges,
allowing them to execute arbitrary code at the host kernel level.
(CVE-2013-1796)

A potential use-after-free flaw was found in the way KVM handled guest time
updates when the GPA (guest physical address) the guest registered by
writing to the MSR_KVM_SYSTEM_TIME machine state register (MSR) fell into a
movable or removable memory region of the hosting user-space process (by
default, QEMU-KVM) on the host. If that memory region is deregistered from
KVM using KVM_SET_USER_MEMORY_REGION and the allocated virtual memory
reused, a privileged guest user could potentially use this flaw to
escalate their privileges on the host. (CVE-2013-1797)

A flaw was found in the way KVM emulated IOAPIC (I/O Advanced Programmable
Interrupt Controller). A missing validation check in the
ioapic_read_indirect() function could allow a privileged guest user to
crash the host, or read a substantial portion of host kernel memory.
(CVE-2013-1798)

Red Hat would like to thank Andrew Honig of Google for reporting all of
these issues.

All users of kvm are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Note that the procedure
in the Solution section must be performed before this update will take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1796</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1798</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130727"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130737" severity="medium">
    <xccdf:title>RHSA-2013:0737: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled PROPFIND requests on activity URLs. A remote attacker could use
this flaw to cause the httpd process serving the request to crash.
(CVE-2013-1849)

A flaw was found in the way the mod_dav_svn module handled large numbers
of properties (such as those set with the "svn propset" command). A
malicious, remote user could use this flaw to cause the httpd process
serving the request to consume an excessive amount of system memory.
(CVE-2013-1845)

Two NULL pointer dereference flaws were found in the way the mod_dav_svn
module handled LOCK requests on certain types of URLs. A malicious, remote
user could use these flaws to cause the httpd process serving the request
to crash. (CVE-2013-1846, CVE-2013-1847)

Note: The CVE-2013-1849, CVE-2013-1846, and CVE-2013-1847 issues only
caused a temporary denial of service, as the Apache HTTP Server started a
new process to replace the crashed child process. When using prefork MPM,
the crash only affected the attacker. When using worker (threaded) MPM, the
connections of other users may have been interrupted.

Red Hat would like to thank the Apache Subversion project for reporting
these issues. Upstream acknowledges Alexander Klink as the original
reporter of CVE-2013-1845; Ben Reser as the original reporter of
CVE-2013-1846; and Philip Martin and Ben Reser as the original reporters of
CVE-2013-1847.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1845</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1846</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1849</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130737"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130742" severity="low">
    <xccdf:title>RHSA-2013:0742: 389-ds-base security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.
 
It was found that the 389 Directory Server did not properly restrict access
to entries when the "nsslapd-allow-anonymous-access" configuration setting
was set to "rootdse". An anonymous user could connect to the LDAP database
and, if the search scope is set to BASE, obtain access to information
outside of the rootDSE. (CVE-2013-1897)

This issue was discovered by Martin Kosek of Red Hat.

This update also fixes the following bugs:

* Previously, the schema-reload plug-in was not thread-safe. Consequently,
executing the schema-reload.pl script under heavy load could have caused
the ns-slapd process to terminate unexpectedly with a segmentation fault.
Currently, the schema-reload plug-in is re-designed so that it is
thread-safe, and the schema-reload.pl script can be executed along with
other LDAP operations. (BZ#929107)

* An out of scope problem for a local variable, in some cases, caused the
modrdn operation to terminate unexpectedly with a segmentation fault. This
update declares the local variable at the proper place of the function so
it does not go out of scope, and the modrdn operation no longer crashes.
(BZ#929111)

* A task manually constructed an exact value to be removed from the
configuration if the "replica-force-cleaning" option was used.
Consequently, the task configuration was not cleaned up, and every time the
server was restarted, the task behaved in the described manner. This update
searches the configuration for the exact value to delete, instead of
manually building the value, and the task does not restart when the server
is restarted. (BZ#929114)

* Previously, a NULL pointer dereference could have occurred when
attempting to get effective rights on an entry that did not exist, leading
to an unexpected termination due to a segmentation fault. This update
checks for NULL entry pointers and returns the appropriate error. Now,
attempts to get effective rights on an entry that does not exist no longer
causes crashes, and the server returns the appropriate error message.
(BZ#929115)

* A problem in the lock timing in the DNA plug-in caused a deadlock if the
DNA operation was executed with other plug-ins. This update moves the
release timing of the problematic lock, and the DNA plug-in does not cause
the deadlock. (BZ#929196)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1897</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130742"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130744" severity="high">
    <xccdf:title>RHSA-2013:0744: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Security:

* An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the Intel i915 driver in the Linux kernel handled the
allocation of the buffer used for relocation copies. A local user with
console access could use this flaw to cause a denial of service or escalate
their privileges. (CVE-2013-0913, Important)

* A buffer overflow flaw was found in the way UTF-8 characters were
converted to UTF-16 in the utf8s_to_utf16s() function of the Linux kernel's
FAT file system implementation. A local user able to mount a FAT file
system with the "utf8=1" option could use this flaw to crash the system or,
potentially, to escalate their privileges. (CVE-2013-1773, Important)

* A flaw was found in the way KVM handled guest time updates when the
buffer the guest registered by writing to the MSR_KVM_SYSTEM_TIME machine
state register (MSR) crossed a page boundary. A privileged guest user could
use this flaw to crash the host or, potentially, escalate their privileges,
allowing them to execute arbitrary code at the host kernel level.
(CVE-2013-1796, Important)

* A potential use-after-free flaw was found in the way KVM handled guest
time updates when the GPA (guest physical address) the guest registered by
writing to the MSR_KVM_SYSTEM_TIME machine state register (MSR) fell into a
movable or removable memory region of the hosting user-space process (by
default, QEMU-KVM) on the host. If that memory region is deregistered from
KVM using KVM_SET_USER_MEMORY_REGION and the allocated virtual memory
reused, a privileged guest user could potentially use this flaw to
escalate their privileges on the host. (CVE-2013-1797, Important)

* A flaw was found in the way KVM emulated IOAPIC (I/O Advanced
Programmable Interrupt Controller). A missing validation check in the
ioapic_read_indirect() function could allow a privileged guest user to
crash the host, or read a substantial portion of host kernel memory.
(CVE-2013-1798, Important)

* A race condition in install_user_keyrings(), leading to a NULL pointer
dereference, was found in the key management facility. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2013-1792, Moderate)

* A NULL pointer dereference in the XFRM implementation could allow a local
user who has the CAP_NET_ADMIN capability to cause a denial of service.
(CVE-2013-1826, Moderate)

* A NULL pointer dereference in the Datagram Congestion Control Protocol
(DCCP) implementation could allow a local user to cause a denial of
service. (CVE-2013-1827, Moderate)

* Information leak flaws in the XFRM implementation could allow a local
user who has the CAP_NET_ADMIN capability to leak kernel stack memory to
user-space. (CVE-2012-6537, Low)

* Two information leak flaws in the Asynchronous Transfer Mode (ATM)
subsystem could allow a local, unprivileged user to leak kernel stack
memory to user-space. (CVE-2012-6546, Low)

* An information leak was found in the TUN/TAP device driver in the
networking implementation. A local user with access to a TUN/TAP virtual
interface could use this flaw to leak kernel stack memory to user-space.
(CVE-2012-6547, Low)

* An information leak in the Bluetooth implementation could allow a local
user who has the CAP_NET_ADMIN capability to leak kernel stack memory to
user-space. (CVE-2013-0349, Low)

* A use-after-free flaw was found in the tmpfs implementation. A local user
able to mount and unmount a tmpfs file system could use this flaw to cause
a denial of service or, potentially, escalate their privileges.
(CVE-2013-1767, Low)

* A NULL pointer dereference was found in the Linux kernel's USB Inside Out
Edgeport Serial Driver implementation. An attacker with physical access to
a system could use this flaw to cause a denial of service. (CVE-2013-1774,
Low)

Red Hat would like to thank Andrew Honig of Google for reporting
CVE-2013-1796, CVE-2013-1797, and CVE-2013-1798. CVE-2013-1792 was
discovered by Mateusz Guzik of Red Hat EMEA GSS SEG Team.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0744</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0349</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1773</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1792</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1796</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1826</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1827</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130744"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130747" severity="medium">
    <xccdf:title>RHSA-2013:0747: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the Xen netback driver implementation in the Linux
kernel. A privileged guest user with access to a para-virtualized network
device could use this flaw to cause a long loop in netback, leading to a
denial of service that could potentially affect the entire system.
(CVE-2013-0216, Moderate)

* A flaw was found in the Xen PCI device back-end driver implementation in
the Linux kernel. A privileged guest user in a guest that has a PCI
passthrough device could use this flaw to cause a denial of service that
could potentially affect the entire system. (CVE-2013-0231, Moderate)

* A NULL pointer dereference flaw was found in the IP packet transformation
framework (XFRM) implementation in the Linux kernel. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause a denial of
service. (CVE-2013-1826, Moderate)

* Information leak flaws were found in the XFRM implementation in the
Linux kernel. A local user who has the CAP_NET_ADMIN capability could use
these flaws to leak kernel stack memory to user-space. (CVE-2012-6537, Low)

* An information leak flaw was found in the logical link control (LLC)
implementation in the Linux kernel. A local, unprivileged user could use
this flaw to leak kernel stack memory to user-space. (CVE-2012-6542, Low)

* Two information leak flaws were found in the Linux kernel's Asynchronous
Transfer Mode (ATM) subsystem. A local, unprivileged user could use these
flaws to leak kernel stack memory to user-space. (CVE-2012-6546, Low)

* An information leak flaw was found in the TUN/TAP device driver in the
Linux kernel's networking implementation. A local user with access to a
TUN/TAP virtual interface could use this flaw to leak kernel stack memory
to user-space. (CVE-2012-6547, Low)

Red Hat would like to thank the Xen project for reporting the CVE-2013-0216
and CVE-2013-0231 issues.

This update also fixes the following bugs:

* The IPv4 code did not correctly update the Maximum Transfer Unit (MTU) of
the designed interface when receiving ICMP Fragmentation Needed packets.
Consequently, a remote host did not respond correctly to ping attempts.
With this update, the IPv4 code has been modified so the MTU of the
designed interface is adjusted as expected in this situation. The ping
command now provides the expected output. (BZ#923353)

* Previously, the be2net code expected the last word of an MCC completion
message from the firmware to be transferred by direct memory access (DMA)
at once. However, this is not always true, and could therefore cause the
BUG_ON() macro to be triggered in the be_mcc_compl_is_new() function,
consequently leading to a kernel panic. The BUG_ON() macro has been
removed from be_mcc_compl_is_new(), and the kernel panic no longer occurs
in this scenario. (BZ#923910)

* Previously, the NFSv3 server incorrectly converted 64-bit cookies to
32-bit. Consequently, the cookies became invalid, which affected all file
system operations depending on these cookies, such as the READDIR operation
that is used to read entries from a directory. This led to various
problems, such as exported directories being empty or displayed
incorrectly, or an endless loop of the READDIRPLUS procedure which could
potentially cause a buffer overflow. This update modifies knfsd code so
that 64-bit cookies are now handled correctly and all file system
operations work as expected. (BZ#924087)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6546</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1826</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130747"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130748" severity="medium">
    <xccdf:title>RHSA-2013:0748: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed certain TGS (Ticket-granting Server) requests. A remote,
authenticated attacker could use this flaw to crash the KDC via a
specially-crafted TGS request. (CVE-2013-1416)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1416</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130748"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130751" severity="high">
    <xccdf:title>RHSA-2013:0751: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple flaws were discovered in the font layout engine in the 2D
component. An untrusted Java application or applet could possibly use these
flaws to trigger Java Virtual Machine memory corruption. (CVE-2013-1569,
CVE-2013-2383, CVE-2013-2384)

Multiple improper permission check issues were discovered in the Beans,
Libraries, JAXP, and RMI components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-1558, CVE-2013-2422, CVE-2013-2436, CVE-2013-1518,
CVE-2013-1557)

The previous default value of the java.rmi.server.useCodebaseOnly property
permitted the RMI implementation to automatically load classes from
remotely specified locations. An attacker able to connect to an application
using RMI could use this flaw to make the application execute arbitrary
code. (CVE-2013-1537)

Note: The fix for CVE-2013-1537 changes the default value of the property
to true, restricting class loading to the local CLASSPATH and locations
specified in the java.rmi.server.codebase property. Refer to Red Hat
Bugzilla bug 952387 for additional details.

The 2D component did not properly process certain images. An untrusted Java
application or applet could possibly use this flaw to trigger Java Virtual
Machine memory corruption. (CVE-2013-2420)

It was discovered that the Hotspot component did not properly handle
certain intrinsic frames, and did not correctly perform access checks and
MethodHandle lookups. An untrusted Java application or applet could
use these flaws to bypass Java sandbox restrictions. (CVE-2013-2431,
CVE-2013-2421, CVE-2013-2423)

It was discovered that JPEGImageReader and JPEGImageWriter in the ImageIO
component did not protect against modification of their state while
performing certain native code operations. An untrusted Java application or
applet could possibly use these flaws to trigger Java Virtual Machine
memory corruption. (CVE-2013-2429, CVE-2013-2430)

The JDBC driver manager could incorrectly call the toString() method in
JDBC drivers, and the ConcurrentHashMap class could incorrectly call the
defaultReadObject() method. An untrusted Java application or applet could
possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2013-1488, CVE-2013-2426)

The sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly
invoke the system class loader. An untrusted Java application or applet
could possibly use this flaw to bypass certain Java sandbox restrictions.
(CVE-2013-0401)

Flaws were discovered in the Network component's InetAddress serialization,
and the 2D component's font handling. An untrusted Java application or
applet could possibly use these flaws to crash the Java Virtual Machine.
(CVE-2013-2417, CVE-2013-2419)

The MBeanInstantiator class implementation in the OpenJDK JMX component did
not properly check class access before creating new instances. An untrusted
Java application or applet could use this flaw to create instances of
non-public classes. (CVE-2013-2424)

It was discovered that JAX-WS could possibly create temporary files with
insecure permissions. A local attacker could use this flaw to access
temporary files created by an application using JAX-WS. (CVE-2013-2415)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.9. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2436</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130751"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130752" severity="high">
    <xccdf:title>RHSA-2013:0752: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple flaws were discovered in the font layout engine in the 2D
component. An untrusted Java application or applet could possibly use these
flaws to trigger Java Virtual Machine memory corruption. (CVE-2013-1569,
CVE-2013-2383, CVE-2013-2384)

Multiple improper permission check issues were discovered in the Beans,
Libraries, JAXP, and RMI components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-1558, CVE-2013-2422, CVE-2013-2436, CVE-2013-1518,
CVE-2013-1557)

The previous default value of the java.rmi.server.useCodebaseOnly property
permitted the RMI implementation to automatically load classes from
remotely specified locations. An attacker able to connect to an application
using RMI could use this flaw to make the application execute arbitrary
code. (CVE-2013-1537)

Note: The fix for CVE-2013-1537 changes the default value of the property
to true, restricting class loading to the local CLASSPATH and locations
specified in the java.rmi.server.codebase property. Refer to Red Hat
Bugzilla bug 952387 for additional details.

The 2D component did not properly process certain images. An untrusted Java
application or applet could possibly use this flaw to trigger Java Virtual
Machine memory corruption. (CVE-2013-2420)

It was discovered that the Hotspot component did not properly handle
certain intrinsic frames, and did not correctly perform access checks and
MethodHandle lookups. An untrusted Java application or applet could
use these flaws to bypass Java sandbox restrictions. (CVE-2013-2431,
CVE-2013-2421, CVE-2013-2423)

It was discovered that JPEGImageReader and JPEGImageWriter in the ImageIO
component did not protect against modification of their state while
performing certain native code operations. An untrusted Java application or
applet could possibly use these flaws to trigger Java Virtual Machine
memory corruption. (CVE-2013-2429, CVE-2013-2430)

The JDBC driver manager could incorrectly call the toString() method in
JDBC drivers, and the ConcurrentHashMap class could incorrectly call the
defaultReadObject() method. An untrusted Java application or applet could
possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2013-1488, CVE-2013-2426)

The sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly
invoke the system class loader. An untrusted Java application or applet
could possibly use this flaw to bypass certain Java sandbox restrictions.
(CVE-2013-0401)

Flaws were discovered in the Network component's InetAddress serialization,
and the 2D component's font handling. An untrusted Java application or
applet could possibly use these flaws to crash the Java Virtual Machine.
(CVE-2013-2417, CVE-2013-2419)

The MBeanInstantiator class implementation in the OpenJDK JMX component did
not properly check class access before creating new instances. An untrusted
Java application or applet could use this flaw to create instances of
non-public classes. (CVE-2013-2424)

It was discovered that JAX-WS could possibly create temporary files with
insecure permissions. A local attacker could use this flaw to access
temporary files created by an application using JAX-WS. (CVE-2013-2415)

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.9. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2436</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130752"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130753" severity="medium">
    <xccdf:title>RHSA-2013:0753: icedtea-web security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

It was discovered that the IcedTea-Web plug-in incorrectly used the same
class loader instance for applets with the same value of the codebase
attribute, even when they originated from different domains. A malicious
applet could use this flaw to gain information about and possibly
manipulate applets from different domains currently running in the browser.
(CVE-2013-1926)

The IcedTea-Web plug-in did not properly check the format of the downloaded
Java Archive (JAR) files. This could cause the plug-in to execute code
hidden in a file in a different format, possibly allowing attackers to
execute code in the context of web sites that allow uploads of specific
file types, known as a GIFAR attack. (CVE-2013-1927)

The CVE-2013-1926 issue was discovered by Jiri Vanek of the Red Hat OpenJDK
Team, and CVE-2013-1927 was discovered by the Red Hat Security Response
Team.

This erratum also upgrades IcedTea-Web to version 1.2.3. Refer to the NEWS
file, linked to in the References, for further information.

All IcedTea-Web users should upgrade to these updated packages, which
resolve these issues. Web browsers using the IcedTea-Web browser plug-in
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1927</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130753"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130769" severity="low">
    <xccdf:title>RHSA-2013:0769: glibc security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

It was found that getaddrinfo() did not limit the amount of stack memory
used during name resolution. An attacker able to make an application
resolve an attacker-controlled hostname or IP address could possibly cause
the application to exhaust all stack memory and crash. (CVE-2013-1914)

A flaw was found in the regular expression matching routines that process
multibyte character input. If an application utilized the glibc regular
expression matching mechanism, an attacker could provide specially-crafted
input that, when processed, would cause the application to crash.
(CVE-2013-0242)

This update also fixes the following bugs:

* The improvements RHSA-2012:1207 made to the accuracy of floating point
functions in the math library caused performance regressions for those
functions. The performance regressions were analyzed and a fix was applied
that retains the current accuracy but reduces the performance penalty to
acceptable levels. Refer to Red Hat Knowledge solution 229993, linked
to in the References, for further information. (BZ#950535)

* It was possible that a memory location freed by the localization code
could be accessed immediately after, resulting in a crash. The fix ensures
that the application does not crash by avoiding the invalid memory access.
(BZ#951493)

Users of glibc are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0769</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1914</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130769"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130770" severity="high">
    <xccdf:title>RHSA-2013:0770: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple flaws were discovered in the font layout engine in the 2D
component. An untrusted Java application or applet could possibly use these
flaws to trigger Java Virtual Machine memory corruption. (CVE-2013-1569,
CVE-2013-2383, CVE-2013-2384)

Multiple improper permission check issues were discovered in the Beans,
Libraries, JAXP, and RMI components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-1558, CVE-2013-2422, CVE-2013-1518, CVE-2013-1557)

The previous default value of the java.rmi.server.useCodebaseOnly property
permitted the RMI implementation to automatically load classes from
remotely specified locations. An attacker able to connect to an application
using RMI could use this flaw to make the application execute arbitrary
code. (CVE-2013-1537)

Note: The fix for CVE-2013-1537 changes the default value of the property
to true, restricting class loading to the local CLASSPATH and locations
specified in the java.rmi.server.codebase property. Refer to Red Hat
Bugzilla bug 952387 for additional details.

The 2D component did not properly process certain images. An untrusted Java
application or applet could possibly use this flaw to trigger Java Virtual
Machine memory corruption. (CVE-2013-2420)

It was discovered that the Hotspot component did not properly handle
certain intrinsic frames, and did not correctly perform MethodHandle
lookups. An untrusted Java application or applet could use these flaws to
bypass Java sandbox restrictions. (CVE-2013-2431, CVE-2013-2421)

It was discovered that JPEGImageReader and JPEGImageWriter in the ImageIO
component did not protect against modification of their state while
performing certain native code operations. An untrusted Java application or
applet could possibly use these flaws to trigger Java Virtual Machine
memory corruption. (CVE-2013-2429, CVE-2013-2430)

The JDBC driver manager could incorrectly call the toString() method in
JDBC drivers, and the ConcurrentHashMap class could incorrectly call the
defaultReadObject() method. An untrusted Java application or applet could
possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2013-1488, CVE-2013-2426)

The sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly
invoke the system class loader. An untrusted Java application or applet
could possibly use this flaw to bypass certain Java sandbox restrictions.
(CVE-2013-0401)

Flaws were discovered in the Network component's InetAddress serialization,
and the 2D component's font handling. An untrusted Java application or
applet could possibly use these flaws to crash the Java Virtual Machine.
(CVE-2013-2417, CVE-2013-2419)

The MBeanInstantiator class implementation in the OpenJDK JMX component did
not properly check class access before creating new instances. An untrusted
Java application or applet could use this flaw to create instances of
non-public classes. (CVE-2013-2424)

It was discovered that JAX-WS could possibly create temporary files with
insecure permissions. A local attacker could use this flaw to access
temporary files created by an application using JAX-WS. (CVE-2013-2415)

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.10. Refer
to the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0770</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2431</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130770"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130771" severity="medium">
    <xccdf:title>RHSA-2013:0771: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

A flaw was found in the way libcurl matched domains associated with
cookies. This could lead to cURL or an application linked against libcurl
sending the wrong cookie if only part of the domain name matched the domain
associated with the cookie, disclosing the cookie to unrelated hosts.
(CVE-2013-1944)

Red Hat would like to thank the cURL project for reporting this issue.
Upstream acknowledges YAMADA Yasuharu as the original reporter.

Users of curl should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1944</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130771"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130772" severity="high">
    <xccdf:title>RHSA-2013:0772: mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2012-5614,
CVE-2013-1506, CVE-2013-1521, CVE-2013-1531, CVE-2013-1532, CVE-2013-1544,
CVE-2013-1548, CVE-2013-1552, CVE-2013-1555, CVE-2013-2375, CVE-2013-2378,
CVE-2013-2389, CVE-2013-2391, CVE-2013-2392)

These updated packages upgrade MySQL to version 5.1.69. Refer to the MySQL
release notes listed in the References section for a full list of changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5614</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3808</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130772"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130788" severity="medium">
    <xccdf:title>RHSA-2013:0788: subscription-manager security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The subscription-manager packages provide programs and libraries to allow
users to manage subscriptions and yum repositories from the Red Hat
Entitlement platform.

It was discovered that the rhn-migrate-classic-to-rhsm tool did not verify
the Red Hat Network Classic server's X.509 certificate when migrating
system profiles registered with Red Hat Network Classic to
Certificate-based Red Hat Network. An attacker could use this flaw to
conduct man-in-the-middle attacks, allowing them to obtain the user's Red
Hat Network credentials. (CVE-2012-6137)

This issue was discovered by Florian Weimer of the Red Hat Product Security
Team.

All users of subscription-manager are advised to upgrade to these updated
packages, which contain a backported patch to fix this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6137</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130788"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130807" severity="low">
    <xccdf:title>RHSA-2013:0807: hypervkvpd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The hypervkvpd package contains hypervkvpd, the guest Microsoft Hyper-V
Key-Value Pair (KVP) daemon. The daemon passes basic information to the
host through VMBus, such as the guest IP address, fully qualified domain
name, operating system name, and operating system release number.

A denial of service flaw was found in the way hypervkvpd processed certain
Netlink messages. A local, unprivileged user in a guest (running on
Microsoft Hyper-V) could send a Netlink message that, when processed, would
cause the guest's hypervkvpd daemon to exit. (CVE-2012-5532)

The CVE-2012-5532 issue was discovered by Florian Weimer of the Red Hat
Product Security Team.

This update also fixes the following bug:

* The hypervkvpd daemon did not close the file descriptors for pool files
when they were updated. This could eventually lead to hypervkvpd crashing
with a "KVP: Failed to open file, pool: 1" error after consuming all
available file descriptors. With this update, the file descriptors are
closed, correcting this issue. (BZ#953502)

Users of hypervkvpd are advised to upgrade to this updated package, which
contains backported patches to correct these issues. After installing the
update, it is recommended to reboot all guest machines.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5532</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130807"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130815" severity="medium">
    <xccdf:title>RHSA-2013:0815: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

Cross-site scripting (XSS) flaws were found in the mod_proxy_balancer
module's manager web interface. If a remote attacker could trick a user,
who was logged into the manager web interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's manager interface session. (CVE-2012-4558)

It was found that mod_rewrite did not filter terminal escape sequences from
its log file. If mod_rewrite was configured with the RewriteLog directive,
a remote attacker could use specially-crafted HTTP requests to inject
terminal escape sequences into the mod_rewrite log file. If a victim viewed
the log file with a terminal emulator, it could result in arbitrary command
execution with the privileges of that user. (CVE-2013-1862)

Cross-site scripting (XSS) flaws were found in the mod_info, mod_status,
mod_imagemap, mod_ldap, and mod_proxy_ftp modules. An attacker could
possibly use these flaws to perform XSS attacks if they were able to make
the victim's browser generate an HTTP request with a specially-crafted Host
header. (CVE-2012-3499)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1862</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130815"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130820" severity="high">
    <xccdf:title>RHSA-2013:0820: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-0801, CVE-2013-1674, CVE-2013-1675, CVE-2013-1676,
CVE-2013-1677, CVE-2013-1678, CVE-2013-1679, CVE-2013-1680, CVE-2013-1681)

A flaw was found in the way Firefox handled Content Level Constructors. A
malicious site could use this flaw to perform cross-site scripting (XSS)
attacks. (CVE-2013-1670)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christoph Diehl, Christian Holler, Jesse Ruderman,
Timothy Nikkel, Jeff Walden, Nils, Ms2ger, Abhishek Arya, and Cody Crews
as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.6 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.6 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1681</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130820"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130821" severity="high">
    <xccdf:title>RHSA-2013:0821: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-0801,
CVE-2013-1674, CVE-2013-1675, CVE-2013-1676, CVE-2013-1677, CVE-2013-1678,
CVE-2013-1679, CVE-2013-1680, CVE-2013-1681)

A flaw was found in the way Thunderbird handled Content Level Constructors.
Malicious content could use this flaw to perform cross-site scripting (XSS)
attacks. (CVE-2013-1670)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christoph Diehl, Christian Holler, Jesse Ruderman,
Timothy Nikkel, Jeff Walden, Nils, Ms2ger, Abhishek Arya, and Cody Crews as
the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.6 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1681</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130821"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130827" severity="high">
    <xccdf:title>RHSA-2013:0827: openswan security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. When using Opportunistic
Encryption, Openswan's pluto IKE daemon requests DNS TXT records to obtain
public RSA keys of itself and its peers.

A buffer overflow flaw was found in Openswan. If Opportunistic Encryption
were enabled ("oe=yes" in "/etc/ipsec.conf") and an RSA key configured, an
attacker able to cause a system to perform a DNS lookup for an
attacker-controlled domain containing malicious records (such as by sending
an email that triggers a DKIM or SPF DNS record lookup) could cause
Openswan's pluto IKE daemon to crash or, potentially, execute arbitrary
code with root privileges. With "oe=yes" but no RSA key configured, the
issue can only be triggered by attackers on the local network who can
control the reverse DNS entry of the target system. Opportunistic
Encryption is disabled by default. (CVE-2013-2053)

This issue was discovered by Florian Weimer of the Red Hat Product Security
Team.

All users of openswan are advised to upgrade to these updated packages,
which contain backported patches to correct this issue. After installing
this update, the ipsec service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2053</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130827"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130830" severity="high">
    <xccdf:title>RHSA-2013:0830: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that the Red Hat Enterprise Linux 6.1 kernel update
(RHSA-2011:0542) introduced an integer conversion issue in the Linux
kernel's Performance Events implementation. This led to a user-supplied
index into the perf_swevent_enabled array not being validated properly,
resulting in out-of-bounds kernel memory access. A local, unprivileged user
could use this flaw to escalate their privileges. (CVE-2013-2094,
Important)

A public exploit that affects Red Hat Enterprise Linux 6 is available.

Refer to Red Hat Knowledge Solution 373743, linked to in the References,
for further information and mitigation instructions for users who are
unable to immediately apply this update.

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2094</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130830"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130831" severity="medium">
    <xccdf:title>RHSA-2013:0831: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

It was found that libvirtd leaked file descriptors when listing all volumes
for a particular pool. A remote attacker able to establish a read-only
connection to libvirtd could use this flaw to cause libvirtd to consume all
available file descriptors, preventing other users from using libvirtd
services (such as starting a new guest) until libvirtd is restarted.
(CVE-2013-1962)

Red Hat would like to thank Edoardo Comar of IBM for reporting this issue.

This update also fixes the following bugs:

* Previously, libvirt made control group (cgroup) requests on files that
it should not have. With older kernels, such nonsensical cgroup requests
were ignored; however, newer kernels are stricter, resulting in libvirt
logging spurious warnings and failures to the libvirtd and audit logs. The
audit log failures displayed by the ausearch tool were similar to the
following:

root    [date] - failed     cgroup     allow     path     rw     /dev/kqemu

With this update, libvirt no longer attempts the nonsensical cgroup
actions, leaving only valid attempts in the libvirtd and audit logs (making
it easier to search for real cases of failure). (BZ#958837)

* Previously, libvirt used the wrong variable when constructing audit
messages. This led to invalid audit messages, causing ausearch to format
certain entries as having "path=(null)" instead of the correct path. This
could prevent ausearch from locating events related to cgroup device ACL
modifications for guests managed by libvirt. With this update, the audit
messages are generated correctly, preventing loss of audit coverage.
(BZ#958839)

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1962</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130831"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130847" severity="medium">
    <xccdf:title>RHSA-2013:0847: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the way the Xen hypervisor AMD IOMMU driver handled
interrupt remapping entries. By default, a single interrupt remapping
table is used, and old interrupt remapping entries are not cleared,
potentially allowing a privileged guest user in a guest that has a
passed-through, bus-mastering capable PCI device to inject interrupt
entries into others guests, including the privileged management domain
(Dom0), leading to a denial of service. (CVE-2013-0153, Moderate)

Red Hat would like to thank the Xen project for reporting the CVE-2013-0153
issue.

This update also fixes the following bugs:

* When a process is opening a file over NFSv4, sometimes an OPEN call can
succeed while the following GETATTR operation fails with an NFS4ERR_DELAY
error. The NFSv4 code did not handle such a situation correctly and allowed
an NFSv4 client to attempt to use the buffer that should contain the
GETATTR information. However, the buffer did not contain the valid GETATTR
information, which caused the client to return a "-ENOTDIR" error.
Consequently, the process failed to open the requested file. This update
backports a patch that adds a test condition verifying validity of the
GETATTR information. If the GETATTR information is invalid, it is obtained
later and the process opens the requested file as expected. (BZ#947736)

* Previously, the xdr routines in NFS version 2 and 3 conditionally updated
the res-&gt;count variable. Read retry attempts after a short NFS read() call
could fail to update the res-&gt;count variable, resulting in truncated read
data being returned. With this update, the res-&gt;count variable is updated
unconditionally so this bug can no longer occur. (BZ#952098)

* When handling requests from Intelligent Platform Management Interface
(IPMI) clients, the IPMI driver previously used two different locks for an
IPMI request. If two IPMI clients sent their requests at the same time,
each request could receive one of the locks and then wait for the second
lock to become available. This resulted in a deadlock situation and the
system became unresponsive. The problem could occur more likely in
environments with many IPMI clients. This update modifies the IPMI driver
to handle the received messages using tasklets so the driver now uses a
safe locking technique when handling IPMI requests and the mentioned
deadlock can no longer occur. (BZ#953435)

* Incorrect locking around the cl_state_owners list could cause the NFSv4
state reclaimer thread to enter an infinite loop while holding the Big
Kernel Lock (BLK). As a consequence, the NFSv4 client became unresponsive.
With this update, safe list iteration is used, which prevents the NFSv4
client from hanging in this scenario. (BZ#954296)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0847</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0153</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130847"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130868" severity="medium">
    <xccdf:title>RHSA-2013:0868: haproxy security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HAProxy provides high availability, load balancing, and proxying for TCP
and HTTP-based applications.

A buffer overflow flaw was found in the way HAProxy handled pipelined HTTP
requests. A remote attacker could send pipelined HTTP requests that would
cause HAProxy to crash or, potentially, execute arbitrary code with the
privileges of the user running HAProxy. This issue only affected systems
using all of the following combined configuration options: HTTP keep alive
enabled, HTTP keywords in TCP inspection rules, and request appending
rules. (CVE-2013-1912)

Red Hat would like to thank Willy Tarreau of HAProxy upstream for reporting
this issue. Upstream acknowledges Yves Lafon from the W3C as the original
reporter.

HAProxy is released as a Technology Preview in Red Hat Enterprise Linux 6.
More information about Red Hat Technology Previews is available at
https://access.redhat.com/support/offerings/techpreview/

All users of haproxy are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1912</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130868"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130869" severity="high">
    <xccdf:title>RHSA-2013:0869: tomcat6 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A flaw was found in the way the tomcat6 init script handled the
tomcat6-initd.log log file. A malicious web application deployed on Tomcat
could use this flaw to perform a symbolic link attack to change the
ownership of an arbitrary system file to that of the tomcat user, allowing
them to escalate their privileges to root. (CVE-2013-1976)

Note: With this update, tomcat6-initd.log has been moved from
/var/log/tomcat6/ to the /var/log/ directory.

It was found that the RHSA-2013:0623 update did not correctly fix
CVE-2012-5887, a weakness in the Tomcat DIGEST authentication
implementation. A remote attacker could use this flaw to perform replay
attacks in some circumstances. Additionally, this problem also prevented
users from being able to authenticate using DIGEST authentication.
(CVE-2013-2051)

Red Hat would like to thank Simon Fayer of Imperial College London for
reporting the CVE-2013-1976 issue.

Users of Tomcat are advised to upgrade to these updated packages, which
correct these issues. Tomcat must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2051</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130869"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130870" severity="high">
    <xccdf:title>RHSA-2013:0870: tomcat5 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A flaw was found in the way the tomcat5 init script handled the
catalina.out log file. A malicious web application deployed on Tomcat
could use this flaw to perform a symbolic link attack to change the
ownership of an arbitrary system file to that of the tomcat user, allowing
them to escalate their privileges to root. (CVE-2013-1976)

Note: With this update, /var/log/tomcat5/catalina.out has been moved to the
/var/log/tomcat5-initd.log file.

Red Hat would like to thank Simon Fayer of Imperial College London for
reporting this issue.

Users of Tomcat are advised to upgrade to these updated packages, which
correct this issue. Tomcat must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1976</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130870"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130883" severity="high">
    <xccdf:title>RHSA-2013:0883: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

It was discovered that the fix for the CVE-2013-1619 issue released via
RHSA-2013:0588 introduced a regression in the way GnuTLS decrypted TLS/SSL
encrypted records when CBC-mode cipher suites were used. A remote attacker
could possibly use this flaw to crash a server or client application that
uses GnuTLS. (CVE-2013-2116)

Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2116</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130883"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130884" severity="medium">
    <xccdf:title>RHSA-2013:0884: libtirpc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide a transport-independent RPC (remote procedure call)
implementation.

A flaw was found in the way libtirpc decoded RPC requests. A
specially-crafted RPC request could cause libtirpc to attempt to free a
buffer provided by an application using the library, even when the buffer
was not dynamically allocated. This could cause an application using
libtirpc, such as rpcbind, to crash. (CVE-2013-1950)

Red Hat would like to thank Michael Armstrong for reporting this issue.

Users of libtirpc should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libtirpc must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1950</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130884"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130896" severity="medium">
    <xccdf:title>RHSA-2013:0896: qemu-kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that QEMU Guest Agent (the "qemu-ga" service) created
certain files with world-writable permissions when run in daemon mode
(the default mode). An unprivileged guest user could use this flaw to
consume all free space on the partition containing the qemu-ga log file, or
modify the contents of the log. When a UNIX domain socket transport was
explicitly configured to be used (not the default), an unprivileged guest
user could potentially use this flaw to escalate their privileges in the
guest. This update requires manual action. Refer below for details.
(CVE-2013-2007)

This update does not change the permissions of the existing log file or
the UNIX domain socket. For these to be changed, stop the qemu-ga service,
and then manually remove all "group" and "other" permissions on the
affected files, or remove the files.

Note that after installing this update, files created by the
guest-file-open QEMU Monitor Protocol (QMP) command will still continue to
be created with world-writable permissions for backwards compatibility.

This issue was discovered by Laszlo Ersek of Red Hat.

This update also fixes the following bugs:

* Previously, due to integer overflow in code calculations, the qemu-kvm
utility was reporting incorrect memory size on QMP events when using the
virtio balloon driver with more than 4 GB of memory. This update fixes the
overflow in the code and qemu-kvm works as expected in the described
scenario. (BZ#958750)

* When the set_link flag is set to "off" to change the status of a network
card, the status is changed to "down" on the respective guest. Previously,
with certain network cards, when such a guest was restarted, the status of
the network card was unexpectedly reset to "up", even though the network
was unavailable. A patch has been provided to address this bug and the link
status change is now preserved across restarts for all network cards.
(BZ#927591)

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2007</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130896"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130897" severity="high">
    <xccdf:title>RHSA-2013:0897: mesa security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mesa provides a 3D graphics API that is compatible with Open Graphics
Library (OpenGL). It also provides hardware-accelerated drivers for many
popular graphics chips.

An out-of-bounds access flaw was found in Mesa. If an application using
Mesa exposed the Mesa API to untrusted inputs (Mozilla Firefox does
this), an attacker could cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-1872)

It was found that Mesa did not correctly validate messages from the X
server. A malicious X server could cause an application using Mesa to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-1993)

All users of Mesa are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against Mesa must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0897</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1993</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130897"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130898" severity="medium">
    <xccdf:title>RHSA-2013:0898: mesa security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mesa provides a 3D graphics API that is compatible with Open Graphics
Library (OpenGL). It also provides hardware-accelerated drivers for many
popular graphics chips.

It was found that Mesa did not correctly validate messages from the X
server. A malicious X server could cause an application using Mesa to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-1993)

All users of Mesa are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against Mesa must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1993</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130898"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130911" severity="high">
    <xccdf:title>RHSA-2013:0911: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way KVM (Kernel-based Virtual Machine)
initialized a guest's registered pv_eoi (paravirtualized end-of-interrupt)
indication flag when entering the guest. An unprivileged guest user could
potentially use this flaw to crash the host. (CVE-2013-1935, Important)

* A missing sanity check was found in the kvm_set_memory_region() function
in KVM, allowing a user-space process to register memory regions pointing
to the kernel address space. A local, unprivileged user could use this flaw
to escalate their privileges. (CVE-2013-1943, Important)

* A double free flaw was found in the Linux kernel's Virtual Ethernet
Tunnel driver (veth). A remote attacker could possibly use this flaw to
crash a target system. (CVE-2013-2017, Moderate)

Red Hat would like to thank IBM for reporting the CVE-2013-1935 issue and
Atzm WATANABE of Stratosphere Inc. for reporting the CVE-2013-2017 issue.
The CVE-2013-1943 issue was discovered by Michael S. Tsirkin of Red Hat.

This update also fixes several bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add this enhancement. The system must
be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0911</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2017</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2188</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130911"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130942" severity="medium">
    <xccdf:title>RHSA-2013:0942: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

It was found that kadmind's kpasswd service did not perform any validation
on incoming network packets, causing it to reply to all requests. A remote
attacker could use this flaw to send spoofed packets to a kpasswd
service that appear to come from kadmind on a different server, causing the
services to keep replying packets to each other, consuming network
bandwidth and CPU. (CVE-2002-2443)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the krb5kdc and kadmind daemons will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2002-2443</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130942"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130957" severity="high">
    <xccdf:title>RHSA-2013:0957: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple flaws were discovered in the ImagingLib and the image attribute,
channel, layout and raster processing in the 2D component. An untrusted
Java application or applet could possibly use these flaws to trigger Java
Virtual Machine memory corruption. (CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-2463, CVE-2013-2465, CVE-2013-2469)

Integer overflow flaws were found in the way AWT processed certain input.
An attacker could use these flaws to execute arbitrary code with the
privileges of the user running an untrusted Java applet or application.
(CVE-2013-2459)

Multiple improper permission check issues were discovered in the Sound,
JDBC, Libraries, JMX, and Serviceability components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass Java
sandbox restrictions. (CVE-2013-2448, CVE-2013-2454, CVE-2013-2458,
CVE-2013-2457, CVE-2013-2453, CVE-2013-2460)

Multiple flaws in the Serialization, Networking, Libraries and CORBA
components can be exploited by an untrusted Java application or applet to
gain access to potentially sensitive information. (CVE-2013-2456,
CVE-2013-2447, CVE-2013-2455, CVE-2013-2452, CVE-2013-2443, CVE-2013-2446)

It was discovered that the Hotspot component did not properly handle
out-of-memory errors. An untrusted Java application or applet could
possibly use these flaws to terminate the Java Virtual Machine.
(CVE-2013-2445)

It was discovered that the AWT component did not properly manage certain
resources and that the ObjectStreamClass of the Serialization component
did not properly handle circular references. An untrusted Java application
or applet could possibly use these flaws to cause a denial of service.
(CVE-2013-2444, CVE-2013-2450)

It was discovered that the Libraries component contained certain errors
related to XML security and the class loader. A remote attacker could
possibly exploit these flaws to bypass intended security mechanisms or
disclose potentially sensitive information and cause a denial of service.
(CVE-2013-2407, CVE-2013-2461)

It was discovered that JConsole did not properly inform the user when
establishing an SSL connection failed. An attacker could exploit this flaw
to gain access to potentially sensitive information. (CVE-2013-2412)

It was discovered that GnomeFileTypeDetector did not check for read
permissions when accessing files. An untrusted Java application or applet
could possibly use this flaw to disclose potentially sensitive information.
(CVE-2013-2449)

It was found that documentation generated by Javadoc was vulnerable to a
frame injection attack. If such documentation was accessible over a
network, and a remote attacker could trick a user into visiting a
specially-crafted URL, it would lead to arbitrary web content being
displayed next to the documentation. This could be used to perform a
phishing attack by providing frame content that spoofed a login form on
the site hosting the vulnerable documentation. (CVE-2013-1571)

It was discovered that the 2D component created shared memory segments with
insecure permissions. A local attacker could use this flaw to read or write
to the shared memory segment. (CVE-2013-1500)

Red Hat would like to thank Tim Brown for reporting CVE-2013-1500, and
US-CERT for reporting CVE-2013-1571. US-CERT acknowledges Oracle as the
original reporter of CVE-2013-1571.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

After installing this update, users of icedtea-web must install
RHBA-2013:0959 for icedtea-web to continue functioning.

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.10. Refer to
the NEWS file, linked to in the References, for further information.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0957</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2473</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130957"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130958" severity="high">
    <xccdf:title>RHSA-2013:0958: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple flaws were discovered in the ImagingLib and the image attribute,
channel, layout and raster processing in the 2D component. An untrusted
Java application or applet could possibly use these flaws to trigger Java
Virtual Machine memory corruption. (CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-2463, CVE-2013-2465, CVE-2013-2469)

Integer overflow flaws were found in the way AWT processed certain input.
An attacker could use these flaws to execute arbitrary code with the
privileges of the user running an untrusted Java applet or application.
(CVE-2013-2459)

Multiple improper permission check issues were discovered in the Sound,
JDBC, Libraries, JMX, and Serviceability components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass Java
sandbox restrictions. (CVE-2013-2448, CVE-2013-2454, CVE-2013-2458,
CVE-2013-2457, CVE-2013-2453, CVE-2013-2460)

Multiple flaws in the Serialization, Networking, Libraries and CORBA
components can be exploited by an untrusted Java application or applet to
gain access to potentially sensitive information. (CVE-2013-2456,
CVE-2013-2447, CVE-2013-2455, CVE-2013-2452, CVE-2013-2443, CVE-2013-2446)

It was discovered that the Hotspot component did not properly handle
out-of-memory errors. An untrusted Java application or applet could
possibly use these flaws to terminate the Java Virtual Machine.
(CVE-2013-2445)

It was discovered that the AWT component did not properly manage certain
resources and that the ObjectStreamClass of the Serialization component
did not properly handle circular references. An untrusted Java application
or applet could possibly use these flaws to cause a denial of service.
(CVE-2013-2444, CVE-2013-2450)

It was discovered that the Libraries component contained certain errors
related to XML security and the class loader. A remote attacker could
possibly exploit these flaws to bypass intended security mechanisms or
disclose potentially sensitive information and cause a denial of service.
(CVE-2013-2407, CVE-2013-2461)

It was discovered that JConsole did not properly inform the user when
establishing an SSL connection failed. An attacker could exploit this flaw
to gain access to potentially sensitive information. (CVE-2013-2412)

It was discovered that GnomeFileTypeDetector did not check for read
permissions when accessing files. An untrusted Java application or applet
could possibly use this flaw to disclose potentially sensitive information.
(CVE-2013-2449)

It was found that documentation generated by Javadoc was vulnerable to a
frame injection attack. If such documentation was accessible over a
network, and a remote attacker could trick a user into visiting a
specially-crafted URL, it would lead to arbitrary web content being
displayed next to the documentation. This could be used to perform a
phishing attack by providing frame content that spoofed a login form on
the site hosting the vulnerable documentation. (CVE-2013-1571)

It was discovered that the 2D component created shared memory segments with
insecure permissions. A local attacker could use this flaw to read or write
to the shared memory segment. (CVE-2013-1500)

Red Hat would like to thank Tim Brown for reporting CVE-2013-1500, and
US-CERT for reporting CVE-2013-1571. US-CERT acknowledges Oracle as the
original reporter of CVE-2013-1571.

This erratum also upgrades the OpenJDK package to IcedTea7 2.3.10. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0958</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2473</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130958"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130964" severity="medium">
    <xccdf:title>RHSA-2013:0964: tomcat6 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A session fixation flaw was found in the Tomcat FormAuthenticator module.
During a narrow window of time, if a remote attacker sent requests while a
user was logging in, it could possibly result in the attacker's requests
being processed as if they were sent by the user. (CVE-2013-2067)

Users of Tomcat are advised to upgrade to these updated packages, which
correct this issue. Tomcat must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0964</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2067</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130964"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130981" severity="high">
    <xccdf:title>RHSA-2013:0981: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-1682, CVE-2013-1684, CVE-2013-1685, CVE-2013-1686,
CVE-2013-1687, CVE-2013-1690)

It was found that Firefox allowed data to be sent in the body of
XMLHttpRequest (XHR) HEAD requests. In some cases this could allow
attackers to conduct Cross-Site Request Forgery (CSRF) attacks.
(CVE-2013-1692)

Timing differences in the way Firefox processed SVG image files could
allow an attacker to read data across domains, potentially leading to
information disclosure. (CVE-2013-1693)

Two flaws were found in the way Firefox implemented some of its internal
structures (called wrappers). An attacker could use these flaws to bypass
some restrictions placed on them. This could lead to unexpected behavior or
a potentially exploitable crash. (CVE-2013-1694, CVE-2013-1697)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Jesse Ruderman, Andrew McCreight,
Abhishek Arya, Mariusz Mlynski, Nils, Johnathan Kuskos, Paul Stone, Boris
Zbarsky, and moz_bug_r_a4 as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla
security advisories for Firefox 17.0.7 ESR. You can find a link to the
Mozilla advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.7 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1684</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1685</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1686</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1692</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1693</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1697</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130982" severity="high">
    <xccdf:title>RHSA-2013:0982: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-1682,
CVE-2013-1684, CVE-2013-1685, CVE-2013-1686, CVE-2013-1687, CVE-2013-1690)

It was found that Thunderbird allowed data to be sent in the body of
XMLHttpRequest (XHR) HEAD requests. In some cases this could allow
attackers to conduct Cross-Site Request Forgery (CSRF) attacks.
(CVE-2013-1692)

Timing differences in the way Thunderbird processed SVG image files could
allow an attacker to read data across domains, potentially leading to
information disclosure. (CVE-2013-1693)

Two flaws were found in the way Thunderbird implemented some of its
internal structures (called wrappers). An attacker could use these flaws to
bypass some restrictions placed on them. This could lead to unexpected
behavior or a potentially exploitable crash. (CVE-2013-1694, CVE-2013-1697)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Jesse Ruderman, Andrew McCreight,
Abhishek Arya, Mariusz Mlynski, Nils, Johnathan Kuskos, Paul Stone, Boris
Zbarsky, and moz_bug_r_a4 as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.7 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1684</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1685</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1686</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1692</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1693</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1697</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130982"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20130983" severity="medium">
    <xccdf:title>RHSA-2013:0983: curl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

A heap-based buffer overflow flaw was found in the way libcurl unescaped
URLs. A remote attacker could provide a specially-crafted URL that, when
processed by an application using libcurl that handles untrusted URLs,
would possibly cause it to crash or, potentially, execute arbitrary code.
(CVE-2013-2174)

Red Hat would like to thank the cURL project for reporting this issue.
Upstream acknowledges Timo Sirainen as the original reporter.

Users of curl should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libcurl must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:0983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2174</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20130983"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131014" severity="high">
    <xccdf:title>RHSA-2013:1014: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple flaws were discovered in the ImagingLib and the image attribute,
channel, layout and raster processing in the 2D component. An untrusted
Java application or applet could possibly use these flaws to trigger Java
Virtual Machine memory corruption. (CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-2463, CVE-2013-2465, CVE-2013-2469)

Integer overflow flaws were found in the way AWT processed certain input.
An attacker could use these flaws to execute arbitrary code with the
privileges of the user running an untrusted Java applet or application.
(CVE-2013-2459)

Multiple improper permission check issues were discovered in the Sound and
JMX components in OpenJDK. An untrusted Java application or applet could
use these flaws to bypass Java sandbox restrictions. (CVE-2013-2448,
CVE-2013-2457, CVE-2013-2453)

Multiple flaws in the Serialization, Networking, Libraries and CORBA
components can be exploited by an untrusted Java application or applet to
gain access to potentially sensitive information. (CVE-2013-2456,
CVE-2013-2447, CVE-2013-2455, CVE-2013-2452, CVE-2013-2443, CVE-2013-2446)

It was discovered that the Hotspot component did not properly handle
out-of-memory errors. An untrusted Java application or applet could
possibly use these flaws to terminate the Java Virtual Machine.
(CVE-2013-2445)

It was discovered that the AWT component did not properly manage certain
resources and that the ObjectStreamClass of the Serialization component
did not properly handle circular references. An untrusted Java application
or applet could possibly use these flaws to cause a denial of service.
(CVE-2013-2444, CVE-2013-2450)

It was discovered that the Libraries component contained certain errors
related to XML security and the class loader. A remote attacker could
possibly exploit these flaws to bypass intended security mechanisms or
disclose potentially sensitive information and cause a denial of service.
(CVE-2013-2407, CVE-2013-2461)

It was discovered that JConsole did not properly inform the user when
establishing an SSL connection failed. An attacker could exploit this flaw
to gain access to potentially sensitive information. (CVE-2013-2412)

It was found that documentation generated by Javadoc was vulnerable to a
frame injection attack. If such documentation was accessible over a
network, and a remote attacker could trick a user into visiting a
specially-crafted URL, it would lead to arbitrary web content being
displayed next to the documentation. This could be used to perform a
phishing attack by providing frame content that spoofed a login form on
the site hosting the vulnerable documentation. (CVE-2013-1571)

It was discovered that the 2D component created shared memory segments with
insecure permissions. A local attacker could use this flaw to read or write
to the shared memory segment. (CVE-2013-1500)

Red Hat would like to thank US-CERT for reporting CVE-2013-1571, and Tim
Brown for reporting CVE-2013-1500. US-CERT acknowledges Oracle as the
original reporter of CVE-2013-1571.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1014</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2473</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131014"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131034" severity="low">
    <xccdf:title>RHSA-2013:1034: kernel security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Information leaks in the Linux kernel could allow a local, unprivileged
user to leak kernel memory to user-space. (CVE-2012-6544, CVE-2012-6545,
CVE-2013-3222, CVE-2013-3224, CVE-2013-3231, CVE-2013-3235, Low)

* An information leak was found in the Linux kernel's POSIX signals
implementation. A local, unprivileged user could use this flaw to bypass
the Address Space Layout Randomization (ASLR) security feature.
(CVE-2013-0914, Low)

* A heap-based buffer overflow in the way the tg3 Ethernet driver parsed
the vital product data (VPD) of devices could allow an attacker with
physical access to a system to cause a denial of service or, potentially,
escalate their privileges. (CVE-2013-1929, Low)

This update also fixes the following bugs:

* Previously on system boot, devices with associated Reserved Memory Region
Reporting (RMRR) information had lost their RMRR information after they
were removed from the static identity (SI) domain. Consequently, a system
unexpectedly terminated in an endless loop due to unexpected NMIs triggered
by DMA errors. This problem was observed on HP ProLiant Generation 7 (G7)
and 8 (Gen8) systems. This update prevents non-USB devices that have RMRR
information associated with them from being placed into the SI domain
during system boot. HP ProLiant G7 and Gen8 systems that contain devices
with the RMRR information now boot as expected. (BZ#957606)

* Previously, the kernel's futex wait code used timeouts that had
granularity in milliseconds. Also, when passing these timeouts to system
calls, the kernel converted the timeouts to "jiffies". Consequently,
programs could time out inaccurately which could lead to significant
latency problems in certain environments. This update modifies the futex
wait code to use a high-resolution timer (hrtimer) so the timeout
granularity is now in microseconds. Timeouts are no longer converted to
"jiffies" when passed to system calls. Timeouts passed to programs are now
accurate and the programs time out as expected. (BZ#958021)

* A recent change modified the size of the task_struct structure in the
floating point unit (fpu) counter. However, on Intel Itanium systems, this
change caused the kernel Application Binary Interface (kABI) to stop
working properly when a previously compiled module was loaded, resulting in
a kernel panic. With this update the change causing this bug has been
reverted so the bug can no longer occur. (BZ#966878)

* The cxgb4 driver previously did not clear data structures used for
firmware requests. Consequently, when initializing some Chelsio's
Terminator 4 (T4) adapters, a probe request could fail because the request
was incompatible with the adapter's firmware. This update modifies the
cxgb4 driver to properly initialize firmware request structures before
sending a request to the firmware and the problem no longer occurs.
(BZ#971872)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1034</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0914</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131034"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131049" severity="high">
    <xccdf:title>RHSA-2013:1049: php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the way PHP parsed deeply nested XML
documents. If a PHP application used the xml_parse_into_struct() function
to parse untrusted XML content, an attacker able to supply
specially-crafted XML could use this flaw to crash the application or,
possibly, execute arbitrary code with the privileges of the user running
the PHP interpreter. (CVE-2013-4113)

All php users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4113</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131049"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131050" severity="high">
    <xccdf:title>RHSA-2013:1050: php53 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the way PHP parsed deeply nested XML
documents. If a PHP application used the xml_parse_into_struct() function
to parse untrusted XML content, an attacker able to supply
specially-crafted XML could use this flaw to crash the application or,
possibly, execute arbitrary code with the privileges of the user running
the PHP interpreter. (CVE-2013-4113)

All php53 users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1050</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4113</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131050"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131051" severity="medium">
    <xccdf:title>RHSA-2013:1051: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the tcp_read_sock() function in the Linux kernel's
IPv4 TCP/IP protocol suite implementation in the way socket buffers (skb)
were handled. A local, unprivileged user could trigger this issue via a
call to splice(), leading to a denial of service. (CVE-2013-2128,
Moderate)

* Information leak flaws in the Linux kernel could allow a local,
unprivileged user to leak kernel memory to user-space. (CVE-2012-6548,
CVE-2013-2634, CVE-2013-2635, CVE-2013-3222, CVE-2013-3224, CVE-2013-3225,
Low)

* An information leak was found in the Linux kernel's POSIX signals
implementation. A local, unprivileged user could use this flaw to bypass
the Address Space Layout Randomization (ASLR) security feature.
(CVE-2013-0914, Low)

* A format string flaw was found in the ext3_msg() function in the Linux
kernel's ext3 file system implementation. A local user who is able to mount
an ext3 file system could use this flaw to cause a denial of service or,
potentially, escalate their privileges. (CVE-2013-1848, Low)

* A format string flaw was found in the b43_do_request_fw() function in the
Linux kernel's b43 driver implementation. A local user who is able to
specify the "fwpostfix" b43 module parameter could use this flaw to cause a
denial of service or, potentially, escalate their privileges.
(CVE-2013-2852, Low)

* A NULL pointer dereference flaw was found in the Linux kernel's ftrace
and function tracer implementations. A local user who has the CAP_SYS_ADMIN
capability could use this flaw to cause a denial of service.
(CVE-2013-3301, Low)

Red Hat would like to thank Kees Cook for reporting CVE-2013-2852.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6548</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0914</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2128</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2635</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2852</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3225</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3301</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131051"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131090" severity="medium">
    <xccdf:title>RHSA-2013:1090: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language.
It has features to process text files and to do system management tasks.

A flaw was found in Ruby's SSL client's hostname identity check when
handling certificates that contain hostnames with NULL bytes. An attacker
could potentially exploit this flaw to conduct man-in-the-middle attacks to
spoof SSL servers. Note that to exploit this issue, an attacker would need
to obtain a carefully-crafted certificate signed by an authority that the
client trusts. (CVE-2013-4073)

All users of Ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4073</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131100" severity="high">
    <xccdf:title>RHSA-2013:1100: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

An unquoted search path flaw was found in the way the QEMU Guest Agent
service installation was performed on Windows. Depending on the permissions
of the directories in the unquoted search path, a local, unprivileged user
could use this flaw to have a binary of their choosing executed with SYSTEM
privileges. (CVE-2013-2231)

This issue was discovered by Lev Veyde of Red Hat.

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2231</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131100"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131114" severity="high">
    <xccdf:title>RHSA-2013:1114: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in BIND. A remote attacker could use
this flaw to send a specially-crafted DNS query to named that, when
processed, would cause named to crash when rejecting the malformed query.
(CVE-2013-4854)

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4854</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131114"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131115" severity="high">
    <xccdf:title>RHSA-2013:1115: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server (named); a
resolver library (routines for applications to use when interfacing with
DNS); and tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in BIND. A remote attacker could use
this flaw to send a specially-crafted DNS query to named that, when
processed, would cause named to crash when rejecting the malformed query.
(CVE-2013-4854)

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4854</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131115"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131119" severity="medium">
    <xccdf:title>RHSA-2013:1119: 389-ds-base security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not honor defined
attribute access controls when evaluating search filter expressions. A
remote attacker (with permission to query the Directory Server) could use
this flaw to determine the values of restricted attributes via a series of
search queries with filter conditions that used restricted attributes.
(CVE-2013-2219)

This issue was discovered by Ludwig Krispenz of Red Hat.

This update also fixes the following bugs:

* Previously, the disk monitoring feature did not function properly. If
logging functionality was set to critical and logging was disabled, rotated
logs would be deleted. If the attribute "nsslapd-errorlog-level" was
explicitly set to any value, even zero, the disk monitoring feature would
not stop the Directory Server when it was supposed to. This update
corrects the disk monitoring feature settings, and it no longer
malfunctions in the described scenarios. (BZ#972930)

* Previously, setting the "nsslapd-disk-monitoring-threshold" attribute via
ldapmodify to a large value worked as expected; however, a bug in
ldapsearch caused such values for the option to be displayed as negative
values. This update corrects the bug in ldapsearch and correct values are
now displayed. (BZ#984970)

* If logging functionality was not set to critical, then the mount point
for the logs directory was incorrectly skipped during the disk space check.
(BZ#987850)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1119</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2219</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131119"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131120" severity="medium">
    <xccdf:title>RHSA-2013:1120: haproxy security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HAProxy provides high availability, load balancing, and proxying for TCP
and HTTP-based applications.

A flaw was found in the way HAProxy handled requests when the proxy's
configuration ("/etc/haproxy/haproxy.cfg") had certain rules that use the
hdr_ip criterion. A remote attacker could use this flaw to crash HAProxy
instances that use the affected configuration. (CVE-2013-2175)

Red Hat would like to thank HAProxy upstream for reporting this issue.
Upstream acknowledges David Torgerson as the original reporter.

HAProxy is released as a Technology Preview in Red Hat Enterprise Linux 6.
More information about Red Hat Technology Previews is available at
https://access.redhat.com/support/offerings/techpreview/

All users of haproxy are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1120</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2175</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131120"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131121" severity="low">
    <xccdf:title>RHSA-2013:1121: sos security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sos package contains a set of tools that gather information from system
hardware, logs and configuration files. The information can then be used
for diagnostic purposes and debugging.

The sosreport utility collected the Kickstart configuration file
("/root/anaconda-ks.cfg"), but did not remove the root user's password from
it before adding the file to the resulting archive of debugging
information. An attacker able to access the archive could possibly use this
flaw to obtain the root user's password. "/root/anaconda-ks.cfg" usually
only contains a hash of the password, not the plain text password.
(CVE-2012-2664)

Note: This issue affected all installations, not only systems installed via
Kickstart. A "/root/anaconda-ks.cfg" file is created by all installation
types.

The utility also collects yum repository information from
"/etc/yum.repos.d" which in uncommon configurations may contain passwords.
Any http_proxy password specified in these files will now be automatically
removed. Passwords embedded within URLs in these files should be manually
removed or the files excluded from the archive.

All users of sos are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1121</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2664</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131121"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131135" severity="medium">
    <xccdf:title>RHSA-2013:1135: nss and nspr security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

It was discovered that NSS leaked timing information when decrypting
TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites
were used. A remote attacker could possibly use this flaw to retrieve plain
text from the encrypted packets by using a TLS/SSL or DTLS server as a
padding oracle. (CVE-2013-1620)

An out-of-bounds memory read flaw was found in the way NSS decoded certain
certificates. If an application using NSS decoded a malformed certificate,
it could cause the application to crash. (CVE-2013-0791)

Red Hat would like to thank the Mozilla project for reporting
CVE-2013-0791. Upstream acknowledges Ambroz Bizjak as the original reporter
of CVE-2013-0791.

This update also fixes the following bugs:

* A defect in the FreeBL library implementation of the Diffie-Hellman (DH)
protocol previously caused Openswan to drop connections. (BZ#958023)

 * A memory leak in the nssutil_ReadSecmodDB() function has been fixed.
(BZ#986969)

In addition, the nss package has been upgraded to upstream version 3.14.3,
and the nspr package has been upgraded to upstream version 4.9.5. These
updates provide a number of bug fixes and enhancements over the previous
versions. (BZ#949845, BZ#924741)

Note that while upstream NSS version 3.14 prevents the use of certificates
that have an MD5 signature, this erratum includes a patch that allows such
certificates by default. To prevent the use of certificates that have an
MD5 signature, set the "NSS_HASH_ALG_SUPPORT" environment variable
to "-MD5".

Users of NSS and NSPR are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing this
update, applications using NSS or NSPR must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1620</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131140" severity="high">
    <xccdf:title>RHSA-2013:1140: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-1701)

A flaw was found in the way Firefox generated Certificate Request Message
Format (CRMF) requests. An attacker could use this flaw to perform
cross-site scripting (XSS) attacks or execute arbitrary code with the
privileges of the user running Firefox. (CVE-2013-1710)

A flaw was found in the way Firefox handled the interaction between frames
and browser history. An attacker could use this flaw to trick Firefox into
treating malicious content as if it came from the browser history, allowing
for XSS attacks. (CVE-2013-1709)

It was found that the same-origin policy could be bypassed due to the way
Uniform Resource Identifiers (URI) were checked in JavaScript. An attacker
could use this flaw to perform XSS attacks, or install malicious add-ons
from third-party pages. (CVE-2013-1713)

It was found that web workers could bypass the same-origin policy. An
attacker could use this flaw to perform XSS attacks. (CVE-2013-1714)

It was found that, in certain circumstances, Firefox incorrectly handled
Java applets. If a user launched an untrusted Java applet via Firefox, the
applet could use this flaw to obtain read-only access to files on the
user's local system. (CVE-2013-1717)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jeff Gilbert, Henrik Skupin, moz_bug_r_a4, Cody
Crews, Federico Lanusse, and Georgi Guninski as the original reporters of
these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.8 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.8 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1717</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131142" severity="high">
    <xccdf:title>RHSA-2013:1142: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-1701)

A flaw was found in the way Thunderbird generated Certificate Request
Message Format (CRMF) requests. An attacker could use this flaw to perform
cross-site scripting (XSS) attacks or execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2013-1710)

A flaw was found in the way Thunderbird handled the interaction between
frames and browser history. An attacker could use this flaw to trick
Thunderbird into treating malicious content as if it came from the browser
history, allowing for XSS attacks. (CVE-2013-1709)

It was found that the same-origin policy could be bypassed due to the way
Uniform Resource Identifiers (URI) were checked in JavaScript. An attacker
could use this flaw to perform XSS attacks, or install malicious add-ons
from third-party pages. (CVE-2013-1713)

It was found that web workers could bypass the same-origin policy. An
attacker could use this flaw to perform XSS attacks. (CVE-2013-1714)

It was found that, in certain circumstances, Thunderbird incorrectly
handled Java applets. If a user launched an untrusted Java applet via
Thunderbird, the applet could use this flaw to obtain read-only access to
files on the user's local system. (CVE-2013-1717)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jeff Gilbert, Henrik Skupin, moz_bug_r_a4, Cody
Crews, Federico Lanusse, and Georgi Guninski as the original reporters of
these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.8 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1717</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131142"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131144" severity="medium">
    <xccdf:title>RHSA-2013:1144: nss, nss-util, nss-softokn, and nspr security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities. nss-softokn provides
an NSS softoken cryptographic module.

It was discovered that NSS leaked timing information when decrypting
TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites
were used. A remote attacker could possibly use this flaw to retrieve plain
text from the encrypted packets by using a TLS/SSL or DTLS server as a
padding oracle. (CVE-2013-1620)

An out-of-bounds memory read flaw was found in the way NSS decoded certain
certificates. If an application using NSS decoded a malformed certificate,
it could cause the application to crash. (CVE-2013-0791)

Red Hat would like to thank the Mozilla project for reporting
CVE-2013-0791. Upstream acknowledges Ambroz Bizjak as the original reporter
of CVE-2013-0791.

This update also fixes the following bugs:

* The RHBA-2013:0445 update (which upgraded NSS to version 3.14) prevented
the use of certificates that have an MD5 signature. This caused problems in
certain environments. With this update, certificates that have an MD5
signature are once again allowed. To prevent the use of certificates that
have an MD5 signature, set the "NSS_HASH_ALG_SUPPORT" environment variable
to "-MD5". (BZ#957603)

* Previously, the sechash.h header file was missing, preventing certain
source RPMs (such as firefox and xulrunner) from building. (BZ#948715)

* A memory leak in the nssutil_ReadSecmodDB() function has been fixed.
(BZ#984967)

In addition, the nss package has been upgraded to upstream version 3.14.3,
the nss-util package has been upgraded to upstream version 3.14.3, the
nss-softokn package has been upgraded to upstream version 3.14.3, and the
nspr package has been upgraded to upstream version 4.9.5. These updates
provide a number of bug fixes and enhancements over the previous versions.
(BZ#927157, BZ#927171, BZ#927158, BZ#927186)

Users of NSS, NSPR, nss-util, and nss-softokn are advised to upgrade to
these updated packages, which fix these issues and add these enhancements.
After installing this update, applications using NSS, NSPR, nss-util, or
nss-softokn must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1620</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131144"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131156" severity="medium">
    <xccdf:title>RHSA-2013:1156: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache HTTP Server is a popular web server.

A flaw was found in the way the mod_dav module of the Apache HTTP Server
handled merge requests. An attacker could use this flaw to send a crafted
merge request that contains URIs that are not configured for DAV, causing
the httpd child process to crash. (CVE-2013-1896)

All httpd users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1156</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1896</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131156"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131166" severity="high">
    <xccdf:title>RHSA-2013:1166: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Linux kernel's Stream Control
Transmission Protocol (SCTP) implementation handled duplicate cookies. If a
local user queried SCTP connection information at the same time a remote
attacker has initialized a crafted SCTP connection to the system, it could
trigger a NULL pointer dereference, causing the system to crash.
(CVE-2013-2206, Important)

* It was found that the fix for CVE-2012-3552 released via RHSA-2012:1540
introduced an invalid free flaw in the Linux kernel's TCP/IP protocol suite
implementation. A local, unprivileged user could use this flaw to corrupt
kernel memory via crafted sendmsg() calls, allowing them to cause a denial
of service or, potentially, escalate their privileges on the system.
(CVE-2013-2224, Important)

* An invalid pointer dereference flaw was found in the Linux kernel's
TCP/IP protocol suite implementation. A local, unprivileged user could use
this flaw to crash the system or, potentially, escalate their privileges on
the system by using sendmsg() with an IPv6 socket connected to an IPv4
destination. (CVE-2013-2232, Moderate)

* Information leak flaws in the Linux kernel could allow a privileged,
local user to leak kernel memory to user-space. (CVE-2013-2164,
CVE-2013-2147, CVE-2013-2234, CVE-2013-2237, Low)

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2237</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131173" severity="high">
    <xccdf:title>RHSA-2013:1173: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Linux kernel's Stream Control
Transmission Protocol (SCTP) implementation handled duplicate cookies. If a
local user queried SCTP connection information at the same time a remote
attacker has initialized a crafted SCTP connection to the system, it could
trigger a NULL pointer dereference, causing the system to crash.
(CVE-2013-2206, Important)

* It was found that the fix for CVE-2012-3552 released via RHSA-2012:1304
introduced an invalid free flaw in the Linux kernel's TCP/IP protocol suite
implementation. A local, unprivileged user could use this flaw to corrupt
kernel memory via crafted sendmsg() calls, allowing them to cause a denial
of service or, potentially, escalate their privileges on the system.
(CVE-2013-2224, Important)

* A flaw was found in the Linux kernel's Performance Events implementation.
On systems with certain Intel processors, a local, unprivileged user could
use this flaw to cause a denial of service by leveraging the perf subsystem
to write into the reserved bits of the OFFCORE_RSP_0 and OFFCORE_RSP_1
model-specific registers. (CVE-2013-2146, Moderate)

* An invalid pointer dereference flaw was found in the Linux kernel's
TCP/IP protocol suite implementation. A local, unprivileged user could use
this flaw to crash the system or, potentially, escalate their privileges on
the system by using sendmsg() with an IPv6 socket connected to an IPv4
destination. (CVE-2013-2232, Moderate)

* Information leak flaws in the Linux kernel's Bluetooth implementation
could allow a local, unprivileged user to leak kernel memory to user-space.
(CVE-2012-6544, Low)

* An information leak flaw in the Linux kernel could allow a privileged,
local user to leak kernel memory to user-space. (CVE-2013-2237, Low)

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2237</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131173"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131182" severity="high">
    <xccdf:title>RHSA-2013:1182: 389-ds-base security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not properly handle the
receipt of certain MOD operations with a bogus Distinguished Name (DN). A
remote, unauthenticated attacker could use this flaw to cause the 389
Directory Server to crash. (CVE-2013-4283)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4283</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131182"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131192" severity="medium">
    <xccdf:title>RHSA-2013:1192: spice-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A flaw was found in the way concurrent access to the clients ring buffer
was performed in the spice-server library. A remote user able to initiate a
SPICE connection to an application acting as a SPICE server could use this
flaw to crash the application. (CVE-2013-4130)

This issue was discovered by David Gibson of Red Hat.

Users of spice-server are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. Applications acting as a
SPICE server must be restarted for this update to take effect. Note that
QEMU-KVM guests providing SPICE console access must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1192</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4130</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131192"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131213" severity="high">
    <xccdf:title>RHSA-2013:1213: gdm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNOME Display Manager (GDM) provides the graphical login screen, shown
shortly after boot up, log out, and when user-switching.

A race condition was found in the way GDM handled the X server sockets
directory located in the system temporary directory. An unprivileged user
could use this flaw to perform a symbolic link attack, giving them write
access to any file, allowing them to escalate their privileges to root.
(CVE-2013-4169)

Note that this erratum includes an updated initscripts package. To fix
CVE-2013-4169, the vulnerable code was removed from GDM and the initscripts
package was modified to create the affected directory safely during the
system boot process. Therefore, this update will appear on all systems,
however systems without GDM installed are not affected by this flaw.

Red Hat would like to thank the researcher with the nickname vladz for
reporting this issue.

All users should upgrade to these updated packages, which correct this
issue. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131213"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131268" severity="high">
    <xccdf:title>RHSA-2013:1268: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A
web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2013-1718, CVE-2013-1722, CVE-2013-1725, CVE-2013-1730,
CVE-2013-1732, CVE-2013-1735, CVE-2013-1736)

A flaw was found in the way Firefox handled certain DOM JavaScript objects.
An attacker could use this flaw to make JavaScript client or add-on code
make incorrect, security sensitive decisions. (CVE-2013-1737)

Red Hat would like to thank the Mozilla project for reporting these
issues. Upstream acknowledges André Bargull, Scoobidiver, Bobby Holley,
Reuben Morais, Abhishek Arya, Ms2ger, Sachin Shinde, Aki Helin, Nils, and
Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.9 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.9 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1268</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1737</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131268"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131269" severity="high">
    <xccdf:title>RHSA-2013:1269: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-1718,
CVE-2013-1722, CVE-2013-1725, CVE-2013-1730, CVE-2013-1732, CVE-2013-1735,
CVE-2013-1736)

A flaw was found in the way Thunderbird handled certain DOM JavaScript
objects. An attacker could use this flaw to make JavaScript client or
add-on code make incorrect, security sensitive decisions. (CVE-2013-1737)

Red Hat would like to thank the Mozilla project for reporting these
issues. Upstream acknowledges André Bargull, Scoobidiver, Bobby Holley,
Reuben Morais, Abhishek Arya, Ms2ger, Sachin Shinde, Aki Helin, Nils, and
Boris Zbarsky as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.9 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1269</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1730</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1737</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131269"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131270" severity="high">
    <xccdf:title>RHSA-2013:1270: polkit security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PolicyKit is a toolkit for defining and handling authorizations.

A race condition was found in the way the PolicyKit pkcheck utility
checked process authorization when the process was specified by its process
ID via the --process option. A local user could use this flaw to bypass
intended PolicyKit authorizations and escalate their privileges.
(CVE-2013-4288)

Note: Applications that invoke pkcheck with the --process option need to be
modified to use the pid,pid-start-time,uid argument for that option, to
allow pkcheck to check process authorization correctly.

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
reporting this issue.

All polkit users should upgrade to these updated packages, which contain a
backported patch to correct this issue. The system must be rebooted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4288</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131270"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131272" severity="high">
    <xccdf:title>RHSA-2013:1272: libvirt security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

libvirt invokes the PolicyKit pkcheck utility to handle authorization. A
race condition was found in the way libvirt used this utility, allowing a
local user to bypass intended PolicyKit authorizations or execute arbitrary
commands with root privileges. (CVE-2013-4311)

Note: With this update, libvirt has been rebuilt to communicate with
PolicyKit via a different API that is not vulnerable to the race condition.
The polkit RHSA-2013:1270 advisory must also be installed to fix the
CVE-2013-4311 issue.

An invalid free flaw was found in libvirtd's
remoteDispatchDomainMemoryStats function. An attacker able to establish a
read-only connection to libvirtd could use this flaw to crash libvirtd.
(CVE-2013-4296)

The CVE-2013-4296 issue was discovered by Daniel P. Berrange of Red Hat.

This update also fixes the following bugs:

* Prior to this update, the libvirtd daemon leaked memory in the
virCgroupMoveTask() function. A fix has been provided which prevents
libvirtd from incorrect management of memory allocations. (BZ#984556)

* Previously, the libvirtd daemon was accessing one byte before the array
in the virCgroupGetValueStr() function. This bug has been fixed and
libvirtd now stays within the array bounds. (BZ#984561)

* When migrating, libvirtd leaked the migration URI (Uniform Resource
Identifier) on destination. A patch has been provided to fix this bug and
the migration URI is now freed correctly. (BZ#984578)

* Updating a network interface using virDomainUpdateDeviceFlags API failed
when a boot order was set for that interface. The update failed even if the
boot order was set in the provided device XML. The
virDomainUpdateDeviceFlags API has been fixed to correctly parse the boot
order specification from the provided device XML and updating network
interfaces with boot orders now works as expected. (BZ#1003934)

Users of libvirt are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4311</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131272"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131273" severity="high">
    <xccdf:title>RHSA-2013:1273: spice-gtk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The spice-gtk packages provide a GIMP Toolkit (GTK+) widget for SPICE
(Simple Protocol for Independent Computing Environments) clients. Both
Virtual Machine Manager and Virtual Machine Viewer can make use of this
widget to access virtual machines using the SPICE protocol.

spice-gtk communicated with PolicyKit for authorization via an API that is
vulnerable to a race condition. This could lead to intended PolicyKit
authorizations being bypassed. This update modifies spice-gtk to
communicate with PolicyKit via a different API that is not vulnerable to
the race condition. (CVE-2013-4324)

All users of spice-gtk are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4324</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131273"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131274" severity="high">
    <xccdf:title>RHSA-2013:1274: hplip security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The hplip packages contain the Hewlett-Packard Linux Imaging and Printing
Project (HPLIP), which provides drivers for Hewlett-Packard printers and
multi-function peripherals.

HPLIP communicated with PolicyKit for authorization via a D-Bus API that is
vulnerable to a race condition. This could lead to intended PolicyKit
authorizations being bypassed. This update modifies HPLIP to communicate
with PolicyKit via a different API that is not vulnerable to the race
condition. (CVE-2013-4325)

All users of hplip are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4325</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131274"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131282" severity="high">
    <xccdf:title>RHSA-2013:1282: rtkit security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>RealtimeKit is a D-Bus system service that changes the scheduling policy of
user processes/threads to SCHED_RR (that is, realtime scheduling mode) on
request. It is intended to be used as a secure mechanism to allow real-time
scheduling to be used by normal user processes.

It was found that RealtimeKit communicated with PolicyKit for authorization
using a D-Bus API that is vulnerable to a race condition. This could have
led to intended PolicyKit authorizations being bypassed. This update
modifies RealtimeKit to communicate with PolicyKit via a different API that
is not vulnerable to the race condition. (CVE-2013-4326)

All rtkit users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1282</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4326</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131282"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131292" severity="medium">
    <xccdf:title>RHSA-2013:1292: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A use-after-free flaw was found in the madvise() system call
implementation in the Linux kernel. A local, unprivileged user could use
this flaw to cause a denial of service or, potentially, escalate their
privileges. (CVE-2012-3511, Moderate)

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled IPv6 sockets that used the UDP_CORK option. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2013-4162, Moderate)

* An information leak flaw in the Linux kernel could allow a local,
unprivileged user to leak kernel memory to user-space. (CVE-2013-2141, Low)

Red Hat would like to thank Hannes Frederic Sowa for reporting
CVE-2013-4162.

This update also fixes the following bugs:

* A bug in the be2net driver prevented communication between NICs using
be2net. This update applies a patch addressing this problem along with
several other upstream patches that fix various other problems. Traffic
between NICs using the be2net driver now proceeds as expected. (BZ#983864)

* A recent patch fixing a problem that prevented communication between
NICs using the be2net driver caused the firmware of NICs to become
unresponsive, and thus triggered a kernel panic. The problem was caused by
unnecessary usage of a hardware workaround that allows skipping VLAN tag
insertion. A patch has been applied and the workaround is now used only
when the multi-channel configuration is enabled on the NIC. Note that the
bug only affected the NICs with firmware version 4.2.xxxx. (BZ#999819)

* A bug in the autofs4 mount expiration code could cause the autofs4
module to falsely report a busy tree of NFS mounts as "not in use".
Consequently, automount attempted to unmount the tree and failed with
a "failed to umount offset" error, leaving the mount tree to appear as
empty directories. A patch has been applied to remove an incorrectly used
autofs dentry mount check and the aforementioned problem no longer occurs.
(BZ#1001488)

* A race condition in the be_open function in the be2net driver could
trigger the BUG_ON() macro, which resulted in a kernel panic. A patch
addressing this problem has been applied and the race condition is now
avoided by enabling polling before enabling interrupts globally. The
kernel no longer panics in this situation. (BZ#1005239)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4162</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131292"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131302" severity="low">
    <xccdf:title>RHSA-2013:1302: xinetd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xinetd package provides a secure replacement for inetd, the Internet
services daemon. xinetd provides access control for all services based on
the address of the remote host and/or on time of access, and can prevent
denial-of-access attacks.

When xinetd services are configured with the "TCPMUX" or "TCPMUXPLUS" type,
and the tcpmux-server service is enabled, those services are accessible via
port 1. It was found that enabling the tcpmux-server service (it is
disabled by default) allowed every xinetd service, including those that are
not configured with the "TCPMUX" or "TCPMUXPLUS" type, to be accessible via
port 1. This could allow a remote attacker to bypass intended firewall
restrictions. (CVE-2012-0862)

Red Hat would like to thank Thomas Swan of FedEx for reporting this issue.

This update also fixes the following bugs:

* Prior to this update, a file descriptor array in the service.c source
file was not handled as expected. As a consequence, some of the descriptors
remained open when xinetd was under heavy load. Additionally, the system
log was filled with a large number of messages that took up a lot of disk
space over time. This update modifies the xinetd code to handle the file
descriptors correctly and messages no longer fill the system log.
(BZ#852274)

* Prior to this update, services were disabled permanently when their CPS
limit was reached. As a consequence, a failed bind operation could occur
when xinetd attempted to restart the service. This update adds additional
logic that attempts to restart the service. Now, the service is only
disabled if xinetd cannot restart the service after 30 attempts.
(BZ#811000)

All users of xinetd are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1302</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0862</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131302"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131307" severity="medium">
    <xccdf:title>RHSA-2013:1307: php53 security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that PHP did not properly handle file names with a NULL
character. A remote attacker could possibly use this flaw to make a PHP
script access unexpected files and bypass intended file system access
restrictions. (CVE-2006-7243)

It was found that PHP did not check for carriage returns in HTTP headers,
allowing intended HTTP response splitting protections to be bypassed.
Depending on the web browser the victim is using, a remote attacker could
use this flaw to perform HTTP response splitting attacks. (CVE-2011-1398)

A flaw was found in PHP's SSL client's hostname identity check when
handling certificates that contain hostnames with NULL bytes. If an
attacker was able to get a carefully crafted certificate signed by a
trusted Certificate Authority, the attacker could use the certificate to
conduct man-in-the-middle attacks to spoof SSL servers. (CVE-2013-4248)

An integer signedness issue, leading to a heap-based buffer underflow, was
found in the PHP scandir() function. If a remote attacker could upload an
excessively large number of files to a directory the scandir() function
runs on, it could cause the PHP interpreter to crash or, possibly, execute
arbitrary code. (CVE-2012-2688)

It was found that PHP did not correctly handle the magic_quotes_gpc
configuration directive. This could result in magic_quotes_gpc input
escaping not being applied in all cases, possibly making it easier for a
remote attacker to perform SQL injection attacks. (CVE-2012-0831)

It was found that the PHP SOAP parser allowed the expansion of external XML
entities during SOAP message parsing. A remote attacker could possibly use
this flaw to read arbitrary files that are accessible to a PHP application
using a SOAP extension. (CVE-2013-1643)

These updated php53 packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 5.10 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All PHP users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. After installing the updated packages, the httpd daemon must
be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131310" severity="medium">
    <xccdf:title>RHSA-2013:1310: samba3x security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim's
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the Samba
server.

Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.

These updated samba3x packages also include numerous bug fixes. Space
precludes documenting all of these changes in this advisory. Users are
directed to the Red Hat Enterprise Linux 5.10 Technical Notes, linked to in
the References, for information on the most significant of these changes.

All samba3x users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4124</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131310"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131319" severity="low">
    <xccdf:title>RHSA-2013:1319: sssd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SSSD (System Security Services Daemon) provides a set of daemons to manage
access to remote directories and authentication mechanisms. It provides NSS
(Name Service Switch) and PAM (Pluggable Authentication Modules) interfaces
toward the system and a pluggable back end system to connect to multiple
different account sources.

A race condition was found in the way SSSD copied and removed user home
directories. A local attacker who is able to write into the home directory
of a different user who is being removed could use this flaw to perform
symbolic link attacks, possibly allowing them to modify and delete
arbitrary files with the privileges of the root user. (CVE-2013-0219)

The CVE-2013-0219 issue war discovered by Florian Weimer of the Red Hat
Product Security Team.

This update also fixes the following bugs:

* After a paging control was used, memory in the sssd_be process was never
freed which led to the growth of the sssd_be process memory usage over
time. To fix this bug, the paging control was deallocated after use, and
thus the memory usage of the sssd_be process no longer grows. (BZ#820908)

* If the sssd_be process was terminated and recreated while there were
authentication requests pending, the sssd_pam process did not recover
correctly and did not reconnect to the new sssd_be process. Consequently,
the sssd_pam process was seemingly blocked and did not accept any new
authentication requests. The sssd_pam process has been fixes so that it
reconnects to the new instance of the sssd_be process after the original
one terminated unexpectedly. Even after a crash and reconnect, the sssd_pam
process now accepts new authentication requests. (BZ#882414)

* When the sssd_be process hung for a while, it was terminated and a new
instance was created. If the old instance did not respond to the TERM
signal and continued running, SSSD terminated unexpectedly. As a
consequence, the user could not log in. SSSD now keeps track of sssd_be
subprocesses more effectively, making the restarts of sssd_be more reliable
in such scenarios. Users can now log in whenever the sssd_be is restarted
and becomes unresponsive. (BZ#886165)

* In case the processing of an LDAP request took longer than the client
timeout upon completing the request (60 seconds by default), the PAM client
could have accessed memory that was previously freed due to the client
timeout being reached. As a result, the sssd_pam process terminated
unexpectedly with a segmentation fault. SSSD now ignores an LDAP request
result when it detects that the set timeout of this request has been
reached. The sssd_pam process no longer crashes in the aforementioned
scenario. (BZ#923813)

* When there was a heavy load of users and groups to be saved in cache,
SSSD experienced a timeout. Consequently, NSS did not start the backup
process properly and it was impossible to log in. A patch has been provided
to fix this bug. The SSSD daemon now remains responsive and the login
continues as expected. (BZ#805729)

* SSSD kept the file descriptors to the log files open.  Consequently, on
occasions like moving the actual log file and restarting the back end, SSSD
still kept the file descriptors open. SSSD now closes the file descriptor
after the child process execution; after a successful back end start, the
file descriptor to log files is closed. (BZ#961680)

* While performing access control in the Identity Management back end, SSSD
erroneously downloaded the "member" attribute from the server and then
attempted to use it in the cache verbatim. Consequently, the cache
attempted to use the "member" attribute values as if they were pointing to
the local cache which was CPU intensive. The member attribute when
processing host groups is no longer downloaded and processed. Moreover, the
login process is reasonably fast even with large host groups. (BZ#979047)

All sssd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1319</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0219</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131319"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131323" severity="low">
    <xccdf:title>RHSA-2013:1323: ccid security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Chip/Smart Card Interface Devices (CCID) is a USB smart card reader
standard followed by most modern smart card readers. The ccid package
provides a Generic, USB-based CCID driver for readers, which follow this
standard.

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card's serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting a
specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
"IFDHPowerICC() PowerUp failed" error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is processed
properly, and the card is powered on as expected. (BZ#907821)

All ccid users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-4530</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131348" severity="medium">
    <xccdf:title>RHSA-2013:1348: Red Hat Enterprise Linux 5 kernel update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* It was found that a deadlock could occur in the Out of Memory (OOM)
killer. A process could trigger this deadlock by consuming a large amount
of memory, and then causing request_module() to be called. A local,
unprivileged user could use this flaw to cause a denial of service
(excessive memory consumption). (CVE-2012-4398, Moderate)

Red Hat would like to thank Tetsuo Handa for reporting this issue.

This update also fixes numerous bugs and adds various enhancements. Refer
to the Red Hat Enterprise Linux 5.10 Release Notes for information on the
most significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which correct this issue, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 5.10 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4398</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131348"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131353" severity="low">
    <xccdf:title>RHSA-2013:1353: sudo security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled time stamp files. An attacker able
to run code as a local user and with the ability to control the system
clock could possibly gain additional privileges by running commands that
the victim user was allowed to run via sudo, without knowing the victim's
password. (CVE-2013-1775)

It was found that sudo did not properly validate the controlling terminal
device when the tty_tickets option was enabled in the /etc/sudoers file. An
attacker able to run code as a local user could possibly gain additional
privileges by running commands that the victim user was allowed to run via
sudo, without knowing the victim's password. (CVE-2013-1776, CVE-2013-2776)

This update also fixes the following bugs:

* Due to a bug in the cycle detection algorithm of the visudo utility,
visudo incorrectly evaluated certain alias definitions in the /etc/sudoers
file as cycles. Consequently, a warning message about undefined aliases
appeared. This bug has been fixed, /etc/sudoers is now parsed correctly by
visudo and the warning message no longer appears. (BZ#849679)

* Previously, the 'sudo -l' command did not parse the /etc/sudoers file
correctly if it contained an Active Directory (AD) group. The file was
parsed only up to the first AD group information and then the parsing
failed with the following message:

    sudo: unable to cache group ADDOM\admingroup, already exists

With this update, the underlying code has been modified and 'sudo -l' now
parses /etc/sudoers containing AD groups correctly. (BZ#855836)

* Previously, the sudo utility did not escape the backslash characters
contained in user names properly. Consequently, if a system used sudo
integrated with LDAP or Active Directory (AD) as the primary authentication
mechanism, users were not able to authenticate on that system. With this
update, sudo has been modified to process LDAP and AD names correctly and
the authentication process now works as expected. (BZ#869287)

* Prior to this update, the 'visudo -s (strict)' command incorrectly parsed
certain alias definitions. Consequently, an error message was issued. The
bug has been fixed, and parsing errors no longer occur when using 'visudo
-s'. (BZ#905624)

All sudo users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2776</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131353"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131409" severity="medium">
    <xccdf:title>RHSA-2013:1409: xinetd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xinetd package provides a secure replacement for inetd, the Internet
services daemon. xinetd provides access control for all services based on
the address of the remote host and/or on time of access, and can prevent
denial-of-access attacks.

It was found that xinetd ignored the user and group configuration
directives for services running under the tcpmux-server service. This flaw
could cause the associated services to run as root. If there was a flaw in
such a service, a remote attacker could use it to execute arbitrary code
with the privileges of the root user. (CVE-2013-4342)

Red Hat would like to thank Thomas Swan of FedEx for reporting this issue.

All xinetd users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4342</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131409"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131411" severity="medium">
    <xccdf:title>RHSA-2013:1411: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in glibc's memory allocator functions (pvalloc, valloc, and
memalign). If an application used such a function, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2013-4332)

This update also fixes the following bug:

* Prior to this update, the size of the L3 cache in certain CPUs for SMP
(Symmetric Multiprocessing) servers was not correctly detected. The
incorrect cache size detection resulted in less than optimal performance
for routines that used this information, including the memset() function.
To fix this bug, the cache size detection has been corrected and core
routines including memset() have their performance restored to expected
levels. (BZ#1011424)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4332</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131411"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131418" severity="medium">
    <xccdf:title>RHSA-2013:1418: libtar security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtar package contains a C library for manipulating tar archives. The
library supports both the strict POSIX tar format and many of the commonly
used GNU extensions.

Two heap-based buffer overflow flaws were found in the way libtar handled
certain archives. If a user were tricked into expanding a specially-crafted
archive, it could cause the libtar executable or an application using
libtar to crash or, potentially, execute arbitrary code. (CVE-2013-4397)

Note: This issue only affected 32-bit builds of libtar.

Red Hat would like to thank Timo Warns for reporting this issue.

All libtar users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4397</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131418"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131426" severity="high">
    <xccdf:title>RHSA-2013:1426: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A use-after-free flaw was found in the way the X.Org server handled
ImageText requests. A malicious, authorized client could use this flaw to
crash the X.Org server or, potentially, execute arbitrary code with root
privileges. (CVE-2013-4396)

Red Hat would like to thank the X.Org security team for reporting this
issue. Upstream acknowledges Pedro Ribeiro as the original reporter.

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4396</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131426"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131436" severity="medium">
    <xccdf:title>RHSA-2013:1436: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled IPv6 sockets that used the UDP_CORK option. A local,
unprivileged user could use this flaw to cause a denial of
service. (CVE-2013-4162, Moderate)

* An information leak flaw was found in the way Linux kernel's device
mapper subsystem, under certain conditions, interpreted data written to
snapshot block devices. An attacker could use this flaw to read data from
disk blocks in free space, which are normally inaccessible. (CVE-2013-4299,
Moderate)

Red Hat would like to thank Hannes Frederic Sowa for reporting
CVE-2013-4162; and Fujitsu for reporting CVE-2013-4299.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4162</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4299</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131436"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131441" severity="medium">
    <xccdf:title>RHSA-2013:1441: rubygems security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>RubyGems is the Ruby standard for publishing and managing third-party
libraries.

It was found that RubyGems did not verify SSL connections. This could lead
to man-in-the-middle attacks. (CVE-2012-2126)

It was found that, when using RubyGems, the connection could be redirected
from HTTPS to HTTP. This could lead to a user believing they are installing
a gem via HTTPS, when the connection may have been silently downgraded to
HTTP. (CVE-2012-2125)

It was discovered that the rubygems API validated version strings using an
unsafe regular expression. An application making use of this API to process
a version string from an untrusted source could be vulnerable to a denial
of service attack through CPU exhaustion. (CVE-2013-4287)

Red Hat would like to thank Rubygems upstream for reporting CVE-2013-4287.
Upstream acknowledges Damir Sharipov as the original reporter.

All rubygems users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2125</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4287</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131441"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131447" severity="high">
    <xccdf:title>RHSA-2013:1447: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

Multiple input checking flaws were found in the 2D component native image
parsing code. A specially crafted image file could trigger a Java Virtual
Machine memory corruption and, possibly, lead to arbitrary code execution
with the privileges of the user running the Java Virtual Machine.
(CVE-2013-5782)

The class loader did not properly check the package access for non-public
proxy classes. A remote attacker could possibly use this flaw to execute
arbitrary code with the privileges of the user running the Java Virtual
Machine. (CVE-2013-5830)

Multiple improper permission check issues were discovered in the 2D, CORBA,
JNDI, and Libraries components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2013-5829, CVE-2013-5814, CVE-2013-5817, CVE-2013-5842, CVE-2013-5850,
CVE-2013-5838)

Multiple input checking flaws were discovered in the JPEG image reading and
writing code in the 2D component. An untrusted Java application or applet
could use these flaws to corrupt the Java Virtual Machine memory and bypass
Java sandbox restrictions. (CVE-2013-5809)

The FEATURE_SECURE_PROCESSING setting was not properly honored by the
javax.xml.transform package transformers. A remote attacker could use this
flaw to supply a crafted XML that would be processed without the intended
security restrictions. (CVE-2013-5802)

Multiple errors were discovered in the way the JAXP and Security components
processes XML inputs. A remote attacker could create a crafted XML that
would cause a Java application to use an excessive amount of CPU and memory
when processed. (CVE-2013-5825, CVE-2013-4002, CVE-2013-5823)

Multiple improper permission check issues were discovered in the Libraries,
Swing, JAX-WS, JAXP, JGSS, AWT, Beans, and Scripting components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2013-3829, CVE-2013-5840,
CVE-2013-5774, CVE-2013-5783, CVE-2013-5820, CVE-2013-5851, CVE-2013-5800,
CVE-2013-5849, CVE-2013-5790, CVE-2013-5784)

It was discovered that the 2D component image library did not properly
check bounds when performing image conversions. An untrusted Java
application or applet could use this flaw to disclose portions of the Java
Virtual Machine memory. (CVE-2013-5778)

Multiple input sanitization flaws were discovered in javadoc. When javadoc
documentation was generated from an untrusted Java source code and hosted
on a domain not controlled by the code author, these issues could make it
easier to perform cross-site scripting attacks. (CVE-2013-5804,
CVE-2013-5797)

Various OpenJDK classes that represent cryptographic keys could leak
private key information by including sensitive data in strings returned by
toString() methods. These flaws could possibly lead to an unexpected
exposure of sensitive key data. (CVE-2013-5780)

The Java Heap Analysis Tool (jhat) failed to properly escape all data added
into the HTML pages it generated. Crafted content in the memory of a Java
program analyzed using jhat could possibly be used to conduct cross-site
scripting attacks. (CVE-2013-5772)

The Kerberos implementation in OpenJDK did not properly parse KDC
responses. A malformed packet could cause a Java application using JGSS to
exit. (CVE-2013-5803)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5817</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5850</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5851</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131447"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131449" severity="medium">
    <xccdf:title>RHSA-2013:1449: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel handled the creation of
temporary IPv6 addresses. If the IPv6 privacy extension was enabled
(/proc/sys/net/ipv6/conf/eth0/use_tempaddr is set to '2'), an attacker on
the local network could disable IPv6 temporary address generation, leading
to a potential information disclosure. (CVE-2013-0343, Moderate)

* An information leak flaw was found in the way Linux kernel's device
mapper subsystem, under certain conditions, interpreted data written to
snapshot block devices. An attacker could use this flaw to read data from
disk blocks in free space, which are normally inaccessible. (CVE-2013-4299,
Moderate)

* An off-by-one flaw was found in the way the ANSI CPRNG implementation in
the Linux kernel processed non-block size aligned requests. This could lead
to random numbers being generated with less bits of entropy than expected
when ANSI CPRNG was used. (CVE-2013-4345, Moderate)

* An information leak flaw was found in the way Xen hypervisor emulated the
OUTS instruction for 64-bit paravirtualized guests. A privileged guest user
could use this flaw to leak hypervisor stack memory to the guest.
(CVE-2013-4368, Moderate)

Red Hat would like to thank Fujitsu for reporting CVE-2013-4299, Stephan
Mueller for reporting CVE-2013-4345, and the Xen project for reporting
CVE-2013-4368.

This update also fixes the following bug:

* A bug in the GFS2 code prevented glock work queues from freeing
glock-related memory while the glock memory shrinker repeatedly queued a
large number of demote requests, for example when performing a simultaneous
backup of several live GFS2 volumes with a large file count. As a
consequence, the glock work queues became overloaded which resulted in a
high CPU usage and the GFS2 file systems being unresponsive for a
significant amount of time. A patch has been applied to alleviate this
problem by calling the yield() function after scheduling a certain amount
of tasks on the glock work queues. The problem can now occur only with
extremely high work loads. (BZ#1014714)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4299</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4368</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131449"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131451" severity="high">
    <xccdf:title>RHSA-2013:1451: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple input checking flaws were found in the 2D component native image
parsing code. A specially crafted image file could trigger a Java Virtual
Machine memory corruption and, possibly, lead to arbitrary code execution
with the privileges of the user running the Java Virtual Machine.
(CVE-2013-5782)

The class loader did not properly check the package access for non-public
proxy classes. A remote attacker could possibly use this flaw to execute
arbitrary code with the privileges of the user running the Java Virtual
Machine. (CVE-2013-5830)

Multiple improper permission check issues were discovered in the 2D, CORBA,
JNDI, and Libraries components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2013-5829, CVE-2013-5814, CVE-2013-5817, CVE-2013-5842, CVE-2013-5850,
CVE-2013-5838)

Multiple input checking flaws were discovered in the JPEG image reading and
writing code in the 2D component. An untrusted Java application or applet
could use these flaws to corrupt the Java Virtual Machine memory and bypass
Java sandbox restrictions. (CVE-2013-5809)

The FEATURE_SECURE_PROCESSING setting was not properly honored by the
javax.xml.transform package transformers. A remote attacker could use this
flaw to supply a crafted XML that would be processed without the intended
security restrictions. (CVE-2013-5802)

Multiple errors were discovered in the way the JAXP and Security components
processes XML inputs. A remote attacker could create a crafted XML that
would cause a Java application to use an excessive amount of CPU and memory
when processed. (CVE-2013-5825, CVE-2013-4002, CVE-2013-5823)

Multiple improper permission check issues were discovered in the Libraries,
Swing, JAX-WS, JAXP, JGSS, AWT, Beans, and Scripting components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2013-3829, CVE-2013-5840,
CVE-2013-5774, CVE-2013-5783, CVE-2013-5820, CVE-2013-5851, CVE-2013-5800,
CVE-2013-5849, CVE-2013-5790, CVE-2013-5784)

It was discovered that the 2D component image library did not properly
check bounds when performing image conversions. An untrusted Java
application or applet could use this flaw to disclose portions of the Java
Virtual Machine memory. (CVE-2013-5778)

Multiple input sanitization flaws were discovered in javadoc. When javadoc
documentation was generated from an untrusted Java source code and hosted
on a domain not controlled by the code author, these issues could make it
easier to perform cross-site scripting attacks. (CVE-2013-5804,
CVE-2013-5797)

Various OpenJDK classes that represent cryptographic keys could leak
private key information by including sensitive data in strings returned by
toString() methods. These flaws could possibly lead to an unexpected
exposure of sensitive key data. (CVE-2013-5780)

The Java Heap Analysis Tool (jhat) failed to properly escape all data added
into the HTML pages it generated. Crafted content in the memory of a Java
program analyzed using jhat could possibly be used to conduct cross-site
scripting attacks. (CVE-2013-5772)

The Kerberos implementation in OpenJDK did not properly parse KDC
responses. A malformed packet could cause a Java application using JGSS to
exit. (CVE-2013-5803)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5817</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5838</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5850</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5851</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131451"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131452" severity="medium">
    <xccdf:title>RHSA-2013:1452: vino security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Vino is a Virtual Network Computing (VNC) server for GNOME. It allows
remote users to connect to a running GNOME session using VNC.

A denial of service flaw was found in the way Vino handled certain
authenticated requests from clients that were in the deferred state. A
remote attacker could use this flaw to make the vino-server process enter
an infinite loop when processing those incoming requests. (CVE-2013-5745)

All vino users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The GNOME session must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5745</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131452"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131457" severity="medium">
    <xccdf:title>RHSA-2013:1457: libgcrypt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libgcrypt library provides general-purpose implementations of various
cryptographic algorithms.

It was found that GnuPG was vulnerable to the Yarom/Falkner flush+reload
cache side-channel attack on the RSA secret exponent. An attacker able to
execute a process on the logical CPU that shared the L3 cache with the
GnuPG process (such as a different local user or a user of a KVM guest
running on the same host with the kernel same-page merging functionality
enabled) could possibly use this flaw to obtain portions of the RSA secret
key. (CVE-2013-4242)

All libgcrypt users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4242</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131457"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131458" severity="medium">
    <xccdf:title>RHSA-2013:1458: gnupg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and
creating digital signatures, compliant with the proposed OpenPGP Internet
standard and the S/MIME standard.

It was found that GnuPG was vulnerable to the Yarom/Falkner flush+reload
cache side-channel attack on the RSA secret exponent. An attacker able to
execute a process on the logical CPU that shared the L3 cache with the
GnuPG process (such as a different local user or a user of a KVM guest
running on the same host with the kernel same-page merging functionality
enabled) could possibly use this flaw to obtain portions of the RSA secret
key. (CVE-2013-4242)

A denial of service flaw was found in the way GnuPG parsed certain
compressed OpenPGP packets. An attacker could use this flaw to send
specially crafted input data to GnuPG, making GnuPG enter an infinite loop
when parsing data. (CVE-2013-4402)

It was found that importing a corrupted public key into a GnuPG keyring
database corrupted that keyring. An attacker could use this flaw to trick a
local user into importing a specially crafted public key into their keyring
database, causing the keyring to be corrupted and preventing its further
use. (CVE-2012-6085)

It was found that GnuPG did not properly interpret the key flags in a PGP
key packet. GPG could accept a key for uses not indicated by its holder.
(CVE-2013-4351)

Red Hat would like to thank Werner Koch for reporting the CVE-2013-4402
issue. Upstream acknowledges Taylor R Campbell as the original reporter.

All gnupg users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4402</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131458"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131459" severity="medium">
    <xccdf:title>RHSA-2013:1459: gnupg2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and
creating digital signatures, compliant with the proposed OpenPGP Internet
standard and the S/MIME standard.

A denial of service flaw was found in the way GnuPG parsed certain
compressed OpenPGP packets. An attacker could use this flaw to send
specially crafted input data to GnuPG, making GnuPG enter an infinite loop
when parsing data. (CVE-2013-4402)

It was found that importing a corrupted public key into a GnuPG keyring
database corrupted that keyring. An attacker could use this flaw to trick a
local user into importing a specially crafted public key into their keyring
database, causing the keyring to be corrupted and preventing its further
use. (CVE-2012-6085)

It was found that GnuPG did not properly interpret the key flags in a PGP
key packet. GPG could accept a key for uses not indicated by its holder.
(CVE-2013-4351)

Red Hat would like to thank Werner Koch for reporting the CVE-2013-4402
issue. Upstream acknowledges Taylor R Campbell as the original reporter.

All gnupg2 users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4351</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4402</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131473" severity="high">
    <xccdf:title>RHSA-2013:1473: spice-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)

This issue was discovered by Tomas Jamrisko of Red Hat.

All spice-server users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131473"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131474" severity="high">
    <xccdf:title>RHSA-2013:1474: qspice security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)

This issue was discovered by Tomas Jamrisko of Red Hat.

All qspice users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4282</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131475" severity="medium">
    <xccdf:title>RHSA-2013:1475: postgresql and postgresql84 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

An array index error, leading to a heap-based out-of-bounds buffer read
flaw, was found in the way PostgreSQL performed certain error processing
using enumeration types. An unprivileged database user could issue a
specially crafted SQL query that, when processed by the server component of
the PostgreSQL service, would lead to a denial of service (daemon crash) or
disclosure of certain portions of server memory. (CVE-2013-0255)

A flaw was found in the way the pgcrypto contrib module of PostgreSQL
(re)initialized its internal random number generator. This could lead to
random numbers with less bits of entropy being used by certain pgcrypto
functions, possibly allowing an attacker to conduct other attacks.
(CVE-2013-1900)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Sumit Soni via Secunia SVCRP as the original
reporter of CVE-2013-0255, and Marko Kreen as the original reporter of
CVE-2013-1900.

These updated packages upgrade PostgreSQL to version 8.4.18, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-18.html

After installing this update, it is advisable to rebuild, using the REINDEX
command, Generalized Search Tree (GiST) indexes that meet one or more of
the following conditions:

- GiST indexes on box, polygon, circle, or point columns

- GiST indexes for variable-width data types, that is text, bytea, bit, and
numeric

- GiST multi-column indexes

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1900</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131475"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131476" severity="high">
    <xccdf:title>RHSA-2013:1476: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to terminate
unexpectedly or, potentially, execute arbitrary code with the privileges of
the user running Firefox. (CVE-2013-5590, CVE-2013-5597, CVE-2013-5599,
CVE-2013-5600, CVE-2013-5601, CVE-2013-5602)

It was found that the Firefox JavaScript engine incorrectly allocated
memory for certain functions. An attacker could combine this flaw with
other vulnerabilities to execute arbitrary code with the privileges of the
user running Firefox. (CVE-2013-5595)

A flaw was found in the way Firefox handled certain Extensible Stylesheet
Language Transformations (XSLT) files. An attacker could combine this flaw
with other vulnerabilities to execute arbitrary code with the privileges of
the user running Firefox. (CVE-2013-5604)

Red Hat would like to thank the Mozilla project for reporting these
issues. Upstream acknowledges Jesse Ruderman, Christoph Diehl, Dan Gohman,
Byoungyoung Lee, Nils, and Abhishek Arya as the original reporters of these
issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 17.0.10 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 17.0.10 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5604</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131476"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131480" severity="high">
    <xccdf:title>RHSA-2013:1480: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-5590,
CVE-2013-5597, CVE-2013-5599, CVE-2013-5600, CVE-2013-5601, CVE-2013-5602)

It was found that the Thunderbird JavaScript engine incorrectly allocated
memory for certain functions. An attacker could combine this flaw with
other vulnerabilities to execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2013-5595)

A flaw was found in the way Thunderbird handled certain Extensible
Stylesheet Language Transformations (XSLT) files. An attacker could combine
this flaw with other vulnerabilities to execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2013-5604)

Red Hat would like to thank the Mozilla project for reporting these
issues. Upstream acknowledges Jesse Ruderman, Christoph Diehl, Dan Gohman,
Byoungyoung Lee, Nils, and Abhishek Arya as the original reporters of these
issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 17.0.10 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.10 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5604</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131480"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131500" severity="medium">
    <xccdf:title>RHSA-2013:1500: gc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gc is a Boehm-Demers-Weiser conservative garbage collector for C and C++.

It was discovered that gc's implementation of the malloc() and calloc()
routines did not properly perform parameter sanitization when allocating
memory. If an application using gc did not implement application-level
validity checks for the malloc() and calloc() routines, a remote attacker
could provide specially crafted application-specific input, which, when
processed by the application, could lead to an application crash or,
potentially, arbitrary code execution with the privileges of the user
running the application. (CVE-2012-2673)

Users of gc are advised to upgrade to these updated packages, which contain
backported patches to correct this issue. Applications using gc must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2673</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131500"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131505" severity="high">
    <xccdf:title>RHSA-2013:1505: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple input checking flaws were found in the 2D component native image
parsing code. A specially crafted image file could trigger a Java Virtual
Machine memory corruption and, possibly, lead to arbitrary code execution
with the privileges of the user running the Java Virtual Machine.
(CVE-2013-5782)

The class loader did not properly check the package access for non-public
proxy classes. A remote attacker could possibly use this flaw to execute
arbitrary code with the privileges of the user running the Java Virtual
Machine. (CVE-2013-5830)

Multiple improper permission check issues were discovered in the 2D, CORBA,
JNDI, and Libraries components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2013-5829, CVE-2013-5814, CVE-2013-5817, CVE-2013-5842, CVE-2013-5850)

Multiple input checking flaws were discovered in the JPEG image reading and
writing code in the 2D component. An untrusted Java application or applet
could use these flaws to corrupt the Java Virtual Machine memory and bypass
Java sandbox restrictions. (CVE-2013-5809)

The FEATURE_SECURE_PROCESSING setting was not properly honored by the
javax.xml.transform package transformers. A remote attacker could use this
flaw to supply a crafted XML that would be processed without the intended
security restrictions. (CVE-2013-5802)

Multiple errors were discovered in the way the JAXP and Security components
processes XML inputs. A remote attacker could create a crafted XML that
would cause a Java application to use an excessive amount of CPU and memory
when processed. (CVE-2013-5825, CVE-2013-4002, CVE-2013-5823)

Multiple improper permission check issues were discovered in the Libraries,
Swing, JAX-WS, JGSS, AWT, Beans, and Scripting components in OpenJDK. An
untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2013-3829, CVE-2013-5840,
CVE-2013-5774, CVE-2013-5783, CVE-2013-5820, CVE-2013-5849, CVE-2013-5790,
CVE-2013-5784)

It was discovered that the 2D component image library did not properly
check bounds when performing image conversions. An untrusted Java
application or applet could use this flaw to disclose portions of the Java
Virtual Machine memory. (CVE-2013-5778)

Multiple input sanitization flaws were discovered in javadoc. When javadoc
documentation was generated from an untrusted Java source code and hosted
on a domain not controlled by the code author, these issues could make it
easier to perform cross-site scripting attacks. (CVE-2013-5804,
CVE-2013-5797)

Various OpenJDK classes that represent cryptographic keys could leak
private key information by including sensitive data in strings returned by
toString() methods. These flaws could possibly lead to an unexpected
exposure of sensitive key data. (CVE-2013-5780)

The Java Heap Analysis Tool (jhat) failed to properly escape all data added
into the HTML pages it generated. Crafted content in the memory of a Java
program analyzed using jhat could possibly be used to conduct cross-site
scripting attacks. (CVE-2013-5772)

The Kerberos implementation in OpenJDK did not properly parse KDC
responses. A malformed packet could cause a Java application using JGSS to
exit. (CVE-2013-5803)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5817</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5850</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131505"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131536" severity="medium">
    <xccdf:title>RHSA-2013:1536: libguestfs security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Libguestfs is a library and set of tools for accessing and modifying guest
disk images.

It was found that guestfish, which enables shell scripting and command line
access to libguestfs, insecurely created the temporary directory used to
store the network socket when started in server mode. A local attacker
could use this flaw to intercept and modify other user's guestfish command,
allowing them to perform arbitrary guestfish actions with the privileges of
a different user, or use this flaw to obtain authentication credentials.
(CVE-2013-4419)

This issue was discovered by Michael Scherer of the Red Hat Regional IT
team.

These updated libguestfs packages include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All libguestfs users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4419</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131536"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131537" severity="low">
    <xccdf:title>RHSA-2013:1537: augeas security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Augeas is a utility for editing configuration. Augeas parses configuration
files in their native formats and transforms them into a tree.
Configuration changes are made by manipulating this tree and saving it back
into native configuration files. Augeas also uses "lenses" as basic
building blocks for establishing the mapping from files into the Augeas
tree and back.

Multiple flaws were found in the way Augeas handled configuration files
when updating them. An application using Augeas to update configuration
files in a directory that is writable to by a different user (for example,
an application running as root that is updating files in a directory owned
by a non-root service user) could have been tricked into overwriting
arbitrary files or leaking information via a symbolic link or mount point
attack. (CVE-2012-0786, CVE-2012-0787)

The augeas package has been upgraded to upstream version 1.0.0, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#817753)

This update also fixes the following bugs:

* Previously, when single quotes were used in an XML attribute, Augeas was
unable to parse the file with the XML lens. An upstream patch has been
provided ensuring that single quotes are handled as valid characters and
parsing no longer fails. (BZ#799885)

* Prior to this update, Augeas was unable to set up the "require_ssl_reuse"
option in the vsftpd.conf file. The updated patch fixes the vsftpd lens to
properly recognize this option, thus fixing this bug. (BZ#855022)

* Previously, the XML lens did not support non-Unix line endings.
Consequently, Augeas was unable to load any files containing such line
endings. The XML lens has been fixed to handle files with CRLF line
endings, thus fixing this bug. (BZ#799879)

* Previously, Augeas was unable to parse modprobe.conf files with spaces
around "=" characters in option directives. The modprobe lens has been
updated and parsing no longer fails. (BZ#826752)

All Augeas users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0787</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131537"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131540" severity="low">
    <xccdf:title>RHSA-2013:1540: evolution security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Evolution is the integrated collection of email, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution selected GnuPG public keys when
encrypting emails. This could result in emails being encrypted with public
keys other than the one belonging to the intended recipient.
(CVE-2013-4166)

The Evolution packages have been upgraded to upstream version 2.32.3, which
provides a number of bug fixes and enhancements over the previous version.
These changes include implementation of Gnome XDG Config Folders, and
support for Exchange Web Services (EWS) protocol to connect to Microsoft
Exchange servers. EWS support has been added as a part of the
evolution-exchange packages. (BZ#883010, BZ#883014, BZ#883015, BZ#883017,
BZ#524917, BZ#524921, BZ#883044)

The gtkhtml3 packages have been upgraded to upstream version 2.32.2, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#883019)

The libgdata packages have been upgraded to upstream version 0.6.4, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#883032)

This update also fixes the following bug:

* The Exchange Calendar could not fetch the "Free" and "Busy" information
for meeting attendees when using Microsoft Exchange 2010 servers, and this
information thus could not be displayed. This happened because Microsoft
Exchange 2010 servers use more strict rules for "Free" and "Busy"
information fetching. With this update, the respective code in the
openchange packages has been modified so the "Free" and "Busy" information
fetching now complies with the fetching rules on Microsoft Exchange 2010
servers. The "Free" and "Busy" information can now be displayed as expected
in the Exchange Calendar. (BZ#665967)

All Evolution users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. All running instances of Evolution must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1540</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4166</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131540"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131542" severity="medium">
    <xccdf:title>RHSA-2013:1542: samba security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim's
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the
Samba server.

Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.

These updated samba packages include numerous bug fixes and one
enhancement. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. After installing this update, the smb service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4124</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131542"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131543" severity="medium">
    <xccdf:title>RHSA-2013:1543: samba4 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the
Samba server.

This update fixes the following bugs:

* When Samba was installed in the build root directory, the RPM target
might not have existed. Consequently, the find-debuginfo.sh script did not
create symbolic links for the libwbclient.so.debug module associated with
the target. With this update, the paths to the symbolic links are relative
so that the symbolic links are now created correctly. (BZ#882338)

* Previously, the samba4 packages were missing a dependency for the
libreplace.so module which could lead to installation failures. With this
update, the missing dependency has been added to the dependency list of the
samba4 packages and installation now proceeds as expected. (BZ#911264)

All samba4 users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1543</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4124</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131543"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131553" severity="high">
    <xccdf:title>RHSA-2013:1553: qemu-kvm security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems that is built into the standard Red Hat
Enterprise Linux kernel. The qemu-kvm packages form the user-space
component for running virtual machines using KVM.

A buffer overflow flaw was found in the way QEMU processed the SCSI "REPORT
LUNS" command when more than 256 LUNs were specified for a single SCSI
target. A privileged guest user could use this flaw to corrupt QEMU process
memory on the host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4344)

This issue was discovered by Asias He of Red Hat.

These updated qemu-kvm packages include numerous bug fixes and various
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. After installing this update, shut down all running virtual
machines. Once all virtual machines have shut down, start them again for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4344</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131553"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131569" severity="medium">
    <xccdf:title>RHSA-2013:1569: wireshark security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark, previously known as Ethereal, is a network protocol analyzer.
It is used to capture and browse the traffic running on a computer network.

Two flaws were found in Wireshark. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2013-3559,
CVE-2013-4083)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2012-2392, CVE-2012-3825, CVE-2012-4285,
CVE-2012-4288, CVE-2012-4289, CVE-2012-4290, CVE-2012-4291, CVE-2012-4292,
CVE-2012-5595, CVE-2012-5597, CVE-2012-5598, CVE-2012-5599, CVE-2012-5600,
CVE-2012-6056, CVE-2012-6059, CVE-2012-6060, CVE-2012-6061, CVE-2012-6062,
CVE-2013-3557, CVE-2013-3561, CVE-2013-4081, CVE-2013-4927, CVE-2013-4931,
CVE-2013-4932, CVE-2013-4933, CVE-2013-4934, CVE-2013-4935, CVE-2013-4936,
CVE-2013-5721)

The wireshark packages have been upgraded to upstream version 1.8.10, which
provides a number of bug fixes and enhancements over the previous versions.
For more information on the bugs fixed, enhancements included, and
supported protocols introduced, refer to the Wireshark Release Notes,
linked to in the References. (BZ#711024)

This update also fixes the following bugs:

* Previously, Wireshark did not parse the RECLAIM-COMPLETE opcode when
inspecting traffic generated by NFSv4.1. A patch has been provided to
enable the parsing of the RECLAIM_COMPLETE opcode, and Wireshark is now
able to properly dissect and handle NFSv4.1 traffic. (BZ#750712)

* Prior to this update, frame arrival times in a text file were reported
one hour ahead from the timestamps in the packet capture file.
This resulted in various failures being reported by the dfilter-test.py
test suite. To fix this bug, frame arrival timestamps have been shifted by
one hour, thus fixing this bug. (BZ#832021)

* The "tshark -D" command returned output to STDERR instead of STDOUT,
which could break scripts that are parsing the "tshark -D" output. This bug
has been fixed, and the "tshark -D" command now writes output data to a
correct standard stream. (BZ#1004636)

* Due to an array overrun, Wireshark could experience undefined program
behavior or could unexpectedly terminate. With this update, proper array
handling ensures Wireshark no longer crashes in the described scenario.
(BZ#715560)

* Previously, the dftest and randpkt command line utilities lacked manual
pages. This update adds proper manual pages for both utilities. (BZ#659661)

In addition, this update adds the following enhancements:

* With this update, Wireshark is able to properly dissect and handle
InfiniBand and GlusterFS traffic. (BZ#699636, BZ#858976)

All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. All running instances of Wireshark must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1569</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4291</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6059</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3559</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4927</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4931</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4932</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4934</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4936</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5721</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131569"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131582" severity="medium">
    <xccdf:title>RHSA-2013:1582: python security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the way the Python SSL module handled X.509 certificate
fields that contain a NULL byte. An attacker could potentially exploit this
flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that
to exploit this issue, an attacker would need to obtain a carefully crafted
certificate signed by an authority that the client trusts. (CVE-2013-4238)

These updated python packages include numerous bug fixes and one
enhancement. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All users of python are advised to upgrade to these updated packages, which
fix these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4238</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131582"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131591" severity="low">
    <xccdf:title>RHSA-2013:1591: openssh security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's Secure Shell (SSH) protocol implementation.
These packages include the core files necessary for the OpenSSH client
and server.

The default OpenSSH configuration made it easy for remote attackers to
exhaust unauthorized connection slots and prevent other users from being
able to log in to a system. This flaw has been addressed by enabling random
early connection drops by setting MaxStartups to 10:30:100 by default.
For more information, refer to the sshd_config(5) man page. (CVE-2010-5107)

These updated openssh packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes,
linked to in the References, for information on the most significant of
these changes.

All openssh users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5107</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131591"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131603" severity="medium">
    <xccdf:title>RHSA-2013:1603: luci security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Luci is a web-based high availability administration application.

A flaw was found in the way the luci service was initialized. If a system
administrator started the luci service from a directory that was writable
to by a local user, that user could use this flaw to execute arbitrary code
as the root or luci user. (CVE-2013-4482)

A flaw was found in the way luci generated its configuration file. The file
was created as world readable for a short period of time, allowing a local
user to gain access to the authentication secrets stored in the
configuration file. (CVE-2013-4481)

These issues were discovered by Jan Pokorný of Red Hat.

These updated luci packages include numerous bug fixes and two
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All luci users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. After installing this update, the luci service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4482</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131603"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131605" severity="medium">
    <xccdf:title>RHSA-2013:1605: glibc security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in glibc's memory allocator functions (pvalloc, valloc, and
memalign). If an application used such a function, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2013-4332)

A flaw was found in the regular expression matching routines that process
multibyte character input. If an application utilized the glibc regular
expression matching mechanism, an attacker could provide specially-crafted
input that, when processed, would cause the application to crash.
(CVE-2013-0242)

It was found that getaddrinfo() did not limit the amount of stack memory
used during name resolution. An attacker able to make an application
resolve an attacker-controlled hostname or IP address could possibly cause
the application to exhaust all stack memory and crash. (CVE-2013-1914)

Among other changes, this update includes an important fix for the following bug:

* Due to a defect in the initial release of the getaddrinfo() system call in Red Hat enterprise Linux 6.0, AF_INET and AF_INET6 queries resolved from the /etc/hosts file returned queried names as canonical names. This incorrect behavior is, however, still considered to be the expected behavior. As a result of a recent change in getaddrinfo(), AF_INET6 queries started resolving the canonical names correctly. However, this behavior was unexpected by applications that relied on queries resolved from the /etc/hosts file, and these applications could thus fail to operate properly. This update applies a fix ensuring that AF_INET6 queries resolved from /etc/hosts always return the queried name as canonical. Note that DNS lookups are resolved properly and always return the correct canonical names. A proper fix to AF_INET6 queries resolution from /etc/hosts may be applied in future releases; for now, due to a lack of standard, Red Hat suggests the first entry in the /etc/hosts file, that applies for the IP address being resolved, to be considered the canonical entry. (BZ#1022022)

These updated glibc packages also include additional bug fixes and 
various enhancements. Space precludes documenting all of these changes 
in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 
Technical Notes, linked to in the References, for information on the 
most significant of these changes.

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1914</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4332</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131605"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131615" severity="medium">
    <xccdf:title>RHSA-2013:1615: php security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that PHP did not properly handle file names with a NULL
character. A remote attacker could possibly use this flaw to make a PHP
script access unexpected files and bypass intended file system access
restrictions. (CVE-2006-7243)

A flaw was found in PHP's SSL client's hostname identity check when
handling certificates that contain hostnames with NULL bytes. If an
attacker was able to get a carefully crafted certificate signed by a
trusted Certificate Authority, the attacker could use the certificate to
conduct man-in-the-middle attacks to spoof SSL servers. (CVE-2013-4248)

It was found that the PHP SOAP parser allowed the expansion of external XML
entities during SOAP message parsing. A remote attacker could possibly use
this flaw to read arbitrary files that are accessible to a PHP application
using a SOAP extension. (CVE-2013-1643)

This update fixes the following bugs:

* Previously, when the allow_call_time_pass_reference setting was disabled,
a virtual host on the Apache server could terminate with a segmentation
fault when attempting to process certain PHP content. This bug has been
fixed and virtual hosts no longer crash when allow_call_time_pass_reference
is off. (BZ#892158, BZ#910466)

* Prior to this update, if an error occurred during the operation of the
fclose(), file_put_contents(), or copy() function, the function did not
report it. This could have led to data loss. With this update, the
aforementioned functions have been modified to properly report any errors.
(BZ#947429)

* The internal buffer for the SQLSTATE error code can store maximum of 5
characters. Previously, when certain calls exceeded this limit, a buffer
overflow occurred. With this update, messages longer than 5 characters are
automatically replaced with the default "HY000" string, thus preventing the
overflow. (BZ#969110)

In addition, this update adds the following enhancement:

* This update adds the following rpm macros to the php package: %__php,
%php_inidir, %php_incldir. (BZ#953814)

Users of php are advised to upgrade to these updated packages, which fix
these bugs and add this enhancement. After installing the updated packages,
the httpd daemon must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131615"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131620" severity="low">
    <xccdf:title>RHSA-2013:1620: xorg-x11-server security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way the X.org X11 server registered new hot plugged
devices. If a local user switched to a different session and plugged in a
new device, input from that device could become available in the previous
session, possibly leading to information disclosure. (CVE-2013-1940)

This issue was found by David Airlie and Peter Hutterer of Red Hat.

This update also fixes the following bugs:

* A previous upstream patch modified the Xephyr X server to be resizeable,
however, it did not enable the resize functionality by default. As a
consequence, X sandboxes were not resizeable on Red Hat Enterprise Linux
6.4 and later. This update enables the resize functionality by default so
that X sandboxes can now be resized as expected. (BZ#915202)

* In Red Hat Enterprise Linux 6, the X Security extension (XC-SECURITY)
has been disabled and replaced by X Access Control Extension (XACE).
However, XACE does not yet include functionality that was previously
available in XC-SECURITY. With this update, XC-SECURITY is enabled in the
xorg-x11-server spec file on Red Hat Enterprise Linux 6. (BZ#957298)

* Upstream code changes to extension initialization accidentally disabled
the GLX extension in Xvfb (the X virtual frame buffer), rendering headless
3D applications not functional. An upstream patch to this problem has been
backported so the GLX extension is enabled again, and applications relying
on this extension work as expected. (BZ#969538)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1940</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131620"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131635" severity="low">
    <xccdf:title>RHSA-2013:1635: pacemaker security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pacemaker is a high-availability cluster resource manager with a powerful
policy engine.

A denial of service flaw was found in the way Pacemaker performed
authentication and processing of remote connections in certain
circumstances. When Pacemaker was configured to allow remote Cluster
Information Base (CIB) configuration or resource management, a remote
attacker could use this flaw to cause Pacemaker to block indefinitely
(preventing it from serving other requests). (CVE-2013-0281)

Note: The default Pacemaker configuration in Red Hat Enterprise Linux 6 has
the remote CIB management functionality disabled.

The pacemaker package has been upgraded to upstream version 1.1.10, which
provides a number of bug fixes and enhancements over the previous version:

* Pacemaker no longer assumes unknown cman nodes are safely stopped.

* The core dump file now converts all exit codes into positive 'errno'
values.

* Pacemaker ensures a return to a stable state after too many fencing
failures, and initiates a shutdown if a node claimed to be fenced is still
active.

* The crm_error tool adds the ability to list and print error symbols.

* The crm_resource command allows individual resources to be reprobed, and
implements the "--ban" option for moving resources away from nodes.
The "--clear" option has replaced the "--unmove" option. Also, crm_resource
now supports OCF tracing when using the "--force" option.

* The IPC mechanism restores the ability for members of the haclient group
to connect to the cluster.

* The Policy Engine daemon allows active nodes in the current membership to
be fenced without quorum.

* Policy Engine now suppresses meaningless IDs when displaying anonymous
clone status, supports maintenance mode for a single node, and correctly
handles the recovered resources before they are operated on.

* XML configuration files are now checked for non-printing characters and
replaced with their octal equivalent when exporting XML text. Also, a more
reliable buffer allocation strategy has been implemented to prevent
lockups.

(BZ#987355)

Additional bug fixes:

* The "crm_resource --move" command was designed for atomic resources and
could not handle resources on clones, masters, or slaves present on
multiple nodes. Consequently, crm_resource could not obtain enough
information to move a resource and did not perform any action. The "--ban"
and "--clear" options have been added to allow the administrator to
instruct the cluster unambiguously. Clone, master, and slave resources can
now be navigated within the cluster as expected. (BZ#902407)

* The hacluster user account did not have a user identification (UID) or
group identification (GID) number reserved on the system. Thus, UID and GID
values were picked randomly during the installation process. The UID and
GID number 189 was reserved for hacluster and is now used consistently for
all installations. (BZ#908450)

* Certain clusters used node host names that did not match the output of
the "uname -n" command. Thus, the default node name used by the crm_standby
and crm_failcount commands was incorrect and caused the cluster to ignore
the update by the administrator. The crm_node command is now used instead
of the uname utility in helper scripts. As a result, the cluster behaves as
expected. (BZ#913093)

* Due to incorrect return code handling, internal recovery logic of the
crm_mon utility was not executed when a configuration updated failed to
apply, leading to an assertion failure. Return codes are now checked
correctly, and the recovery of an expected error state is now handled
transparently. (BZ#951371)

* cman's automatic unfencing feature failed when combined with Pacemaker.
Support for automated unfencing in Pacemaker has been added, and the
unwanted behavior no longer occurs. (BZ#996850)

All pacemaker users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1635</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0281</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131635"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131645" severity="high">
    <xccdf:title>RHSA-2013:1645: Red Hat Enterprise Linux 6 kernel update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Linux kernel's IPv6 implementation
handled certain UDP packets when the UDP Fragmentation Offload (UFO)
feature was enabled. A remote attacker could use this flaw to crash the
system or, potentially, escalate their privileges on the system.
(CVE-2013-4387, Important)

* A flaw was found in the way the Linux kernel handled the creation of
temporary IPv6 addresses. If the IPv6 privacy extension was enabled
(/proc/sys/net/ipv6/conf/eth0/use_tempaddr set to '2'), an attacker on the
local network could disable IPv6 temporary address generation, leading to a
potential information disclosure. (CVE-2013-0343, Moderate)

* A flaw was found in the way the Linux kernel handled HID (Human Interface
Device) reports with an out-of-bounds Report ID. An attacker with physical
access to the system could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2013-2888,
Moderate)

* An off-by-one flaw was found in the way the ANSI CPRNG implementation in
the Linux kernel processed non-block size aligned requests. This could lead
to random numbers being generated with less bits of entropy than expected
when ANSI CPRNG was used. (CVE-2013-4345, Moderate)

* It was found that the fix for CVE-2012-2375 released via RHSA-2012:1580
accidentally removed a check for small-sized result buffers. A local,
unprivileged user with access to an NFSv4 mount with ACL support could use
this flaw to crash the system or, potentially, escalate their privileges on
the system . (CVE-2013-4591, Moderate)

* A flaw was found in the way IOMMU memory mappings were handled when
moving memory slots. A malicious user on a KVM host who has the ability to
assign a device to a guest could use this flaw to crash the host.
(CVE-2013-4592, Moderate)

* Heap-based buffer overflow flaws were found in the way the Zeroplus and
Pantherlord/GreenAsia game controllers handled HID reports. An attacker
with physical access to the system could use these flaws to crash the
system or, potentially, escalate their privileges on the system.
(CVE-2013-2889, CVE-2013-2892, Moderate)

* Two information leak flaws were found in the logical link control (LLC)
implementation in the Linux kernel. A local, unprivileged user could use
these flaws to leak kernel stack memory to user space. (CVE-2012-6542,
CVE-2013-3231, Low)

* A heap-based buffer overflow in the way the tg3 Ethernet driver parsed
the vital product data (VPD) of devices could allow an attacker with
physical access to a system to cause a denial of service or, potentially,
escalate their privileges. (CVE-2013-1929, Low)

* Information leak flaws in the Linux kernel could allow a privileged,
local user to leak kernel memory to user space. (CVE-2012-6545,
CVE-2013-1928, CVE-2013-2164, CVE-2013-2234, Low)

* A format string flaw was found in the Linux kernel's block layer.
A privileged, local user could potentially use this flaw to escalate their
privileges to kernel level (ring0). (CVE-2013-2851, Low)

Red Hat would like to thank Stephan Mueller for reporting CVE-2013-4345,
and Kees Cook for reporting CVE-2013-2851.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.5 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.5 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1645</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6545</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1928</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2234</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2851</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2888</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2892</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4387</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4592</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131645"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131652" severity="low">
    <xccdf:title>RHSA-2013:1652: coreutils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The coreutils package contains the core GNU utilities. It is a combination
of the old GNU fileutils, sh-utils, and textutils packages.

It was discovered that the sort, uniq, and join utilities did not properly
restrict the use of the alloca() function. An attacker could use this flaw
to crash those utilities by providing long input strings. (CVE-2013-0221,
CVE-2013-0222, CVE-2013-0223)

These updated coreutils packages include numerous bug fixes and two
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All coreutils users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0223</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131652"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131661" severity="medium">
    <xccdf:title>RHSA-2013:1661: RDMA stack security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Enterprise Linux includes a collection of Infiniband and iWARP
utilities, libraries and development packages for writing applications that
use Remote Direct Memory Access (RDMA) technology.

A flaw was found in the way ibutils handled temporary files. A local
attacker could use this flaw to cause arbitrary files to be overwritten as
the root user via a symbolic link attack. (CVE-2013-2561)

It was discovered that librdmacm used a static port to connect to the
ib_acm service. A local attacker able to run a specially crafted ib_acm
service on that port could use this flaw to provide incorrect address
resolution information to librmdacm applications. (CVE-2012-4516)

The CVE-2012-4516 issue was discovered by Florian Weimer of the Red Hat
Product Security Team.

This advisory updates the following packages to the latest upstream
releases, providing a number of bug fixes and enhancements over the
previous versions:

* libibverbs-1.1.7
* libmlx4-1.0.5
* librdmacm-1.0.17
* mstflint-3.0
* perftest-2.0
* qperf-0.4.9
* rdma-3.10

Several bugs have been fixed in the openmpi, mpitests, ibutils, and
infinipath-psm packages.

The most notable changes in these updated packages from the RDMA stack are
the following:

* Multiple bugs in the Message Passing Interface (MPI) test packages were
resolved, allowing more of the mpitest applications to pass on the
underlying MPI implementations.

* The libmlx4 package now includes dracut module files to ensure that any
necessary custom configuration of mlx4 port types is included in the
initramfs dracut builds.

* Multiple test programs in the perftest and qperf packages now work
properly over RoCE interfaces, or when specifying the use of rdmacm
queue pairs.

* The mstflint package has been updated to the latest upstream version,
which is now capable of burning firmware on newly released Mellanox
Connect-IB hardware.

* A compatibility problem between the openmpi and infinipath-psm packages
has been resolved with new builds of these packages.

All RDMA users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1661</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4516</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2561</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131661"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131674" severity="medium">
    <xccdf:title>RHSA-2013:1674: dracut security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The dracut packages include an event-driven initramfs generator
infrastructure based on the udev device manager. The virtual file system,
initramfs, is loaded together with the kernel at boot time and initializes
the system, so it can read and boot from the root partition.

It was discovered that dracut created initramfs images as world readable.
A local user could possibly use this flaw to obtain sensitive information
from these files, such as iSCSI authentication passwords, encrypted root
file system crypttab passwords, or other information. (CVE-2012-4453)

This issue was discovered by Peter Jones of the Red Hat Installer Team.

These updated dracut packages include numerous bug fixes and two
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All dracut users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-4453</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131674"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131701" severity="low">
    <xccdf:title>RHSA-2013:1701: sudo security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled time stamp files. An attacker able
to run code as a local user and with the ability to control the system
clock could possibly gain additional privileges by running commands that
the victim user was allowed to run via sudo, without knowing the victim's
password. (CVE-2013-1775)

It was found that sudo did not properly validate the controlling terminal
device when the tty_tickets option was enabled in the /etc/sudoers file.
An attacker able to run code as a local user could possibly gain additional
privileges by running commands that the victim user was allowed to run via
sudo, without knowing the victim's password. (CVE-2013-2776, CVE-2013-2777)

This update also fixes the following bugs:

* Previously, sudo did not support netgroup filtering for sources from the
System Security Services Daemon (SSSD). Consequently, SSSD rules were
applied to all users even when they did not belong to the specified
netgroup. With this update, netgroup filtering for SSSD sources has been
implemented. As a result, rules with a netgroup specification are applied
only to users that are part of the netgroup. (BZ#880150)

* When the sudo utility set up the environment in which it ran a command,
it reset the value of the RLIMIT_NPROC resource limit to the parent's value
of this limit if both the soft (current) and hard (maximum) values of
RLIMIT_NPROC were not limited. An upstream patch has been provided to
address this bug and RLIMIT_NPROC can now be set to "unlimited".
(BZ#947276)

* Due to the refactoring of the sudo code by upstream, the SUDO_USER
variable that stores the name of the user running the sudo command was not
logged to the /var/log/secure file as before. Consequently, user name
"root" was always recorded instead of the real user name. With this update,
the previous behavior of sudo has been restored. As a result, the expected
user name is now written to /var/log/secure. (BZ#973228)

* Due to an error in a loop condition in sudo's rule listing code, a buffer
overflow could have occurred in certain cases. This condition has been
fixed and the buffer overflow no longer occurs. (BZ#994626)

In addition, this update adds the following enhancements:

* With this update, sudo has been modified to send debug messages about
netgroup matching to the debug log. These messages should provide better
understanding of how sudo matches netgroup database records with values
from the running system and what the values are exactly. (BZ#848111)

* With this update, sudo has been modified to accept the ipa_hostname value
from the /etc/sssd/sssd.conf configuration file when matching netgroups.
(BZ#853542)

All sudo users are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add
these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1701</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1775</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2777</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131701"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131732" severity="low">
    <xccdf:title>RHSA-2013:1732: busybox security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>BusyBox provides a single binary that includes versions of a large number
of system commands, including a shell. This can be very useful for
recovering from certain types of system failures, particularly those
involving broken shared libraries.

It was found that the mdev BusyBox utility could create certain directories
within /dev with world-writable permissions. A local unprivileged user
could use this flaw to manipulate portions of the /dev directory tree.
(CVE-2013-1813)

This update also fixes the following bugs:

* Previously, due to a too eager string size optimization on the IBM System
z architecture, the "wc" BusyBox command failed after processing standard
input with the following error:

    wc: : No such file or directory

This bug was fixed by disabling the string size optimization and the "wc"
command works properly on IBM System z architectures. (BZ#820097)

* Prior to this update, the "mknod" command was unable to create device
nodes with a major or minor number larger than 255. Consequently, the kdump
utility failed to handle such a device. The underlying source code has been
modified, and it is now possible to use the "mknod" command to create
device nodes with a major or minor number larger than 255. (BZ#859817)

* If a network installation from an NFS server was selected, the "mount"
command used the UDP protocol by default. If only TCP mounts were supported
by the server, this led to a failure of the mount command. As a result,
Anaconda could not continue with the installation. This bug is now fixed
and NFS mount operations default to the TCP protocol. (BZ#855832)

All busybox users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1813</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131732"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131752" severity="high">
    <xccdf:title>RHSA-2013:1752: 389-ds-base security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not properly handle
certain Get Effective Rights (GER) search queries when the attribute list,
which is a part of the query, included several names using the '@'
character. An attacker able to submit search queries to the 389 Directory
Server could cause it to crash. (CVE-2013-4485)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4485</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131752"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131764" severity="high">
    <xccdf:title>RHSA-2013:1764: ruby security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language.
It has features to process text files and to perform system management
tasks.

A buffer overflow flaw was found in the way Ruby parsed floating point
numbers from their text representation. If an application using Ruby
accepted untrusted input strings and converted them to floating point
numbers, an attacker able to provide such input could cause the application
to crash or, possibly, execute arbitrary code with the privileges of the
application. (CVE-2013-4164)

All ruby users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4164</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131764"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131778" severity="medium">
    <xccdf:title>RHSA-2013:1778: gimp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

A stack-based buffer overflow flaw, a heap-based buffer overflow, and an
integer overflow flaw were found in the way GIMP loaded certain X Window
System (XWD) image dump files. A remote attacker could provide a specially
crafted XWD image file that, when processed, would cause the XWD plug-in to
crash or, potentially, execute arbitrary code with the privileges of the
user running the GIMP. (CVE-2012-5576, CVE-2013-1913, CVE-2013-1978)

The CVE-2013-1913 and CVE-2013-1978 issues were discovered by Murray
McAllister of the Red Hat Security Response Team.

Users of the GIMP are advised to upgrade to these updated packages, which
correct these issues. The GIMP must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1913</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1978</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131778"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131779" severity="medium">
    <xccdf:title>RHSA-2013:1779: mod_nss security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_nss module provides strong cryptography for the Apache HTTP Server
via the Secure Sockets Layer (SSL) and Transport Layer Security (TLS)
protocols, using the Network Security Services (NSS) security library.

A flaw was found in the way mod_nss handled the NSSVerifyClient setting for
the per-directory context. When configured to not require a client
certificate for the initial connection and only require it for a specific
directory, mod_nss failed to enforce this requirement and allowed a client
to access the directory when no valid client certificate was provided.
(CVE-2013-4566)

Red Hat would like to thank Albert Smith of OUSD(AT&amp;L) for reporting this
issue.

All mod_nss users should upgrade to this updated package, which contains a
backported patch to correct this issue. The httpd service must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1779</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4566</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131779"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131790" severity="medium">
    <xccdf:title>RHSA-2013:1790: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An information leak flaw was found in the way the Xen hypervisor handled
error conditions when reading guest memory during certain guest-originated
operations, such as port or memory mapped I/O writes. A privileged user in
a fully-virtualized guest could use this flaw to leak hypervisor stack
memory to a guest. (CVE-2013-4355, Moderate)

Red Hat would like to thank the Xen project for reporting this issue.

This update also fixes the following bugs:

* A previous fix to the kernel did not contain a memory barrier in the
percpu_up_write() function. Consequently, under certain circumstances, a
race condition could occur leading to memory corruption and a subsequent
kernel panic. This update introduces a new memory barrier pair, light_mb()
and heavy_mb(), for per-CPU basis read and write semaphores
(percpu-rw-semaphores) ensuring that the race condition can no longer
occur. In addition, the read path performance of "percpu-rw-semaphores" has
been improved. (BZ#1014715)

* Due to a bug in the tg3 driver, systems that had the Wake-on-LAN (WOL)
feature enabled on their NICs could not have been woken up from suspension
or hibernation using WOL. A missing pci_wake_from_d3() function call has
been added to the tg3 driver, which ensures that WOL functions properly by
setting the PME_ENABLE bit. (BZ#1014973)

* Due to an incorrect test condition in the mpt2sas driver, the driver was
unable to catch failures to map a SCSI scatter-gather list. The test
condition has been corrected so that the mpt2sas driver now handles SCSI
scatter-gather mapping failures as expected. (BZ#1018458)

* A previous patch to the kernel introduced the "VLAN tag re-insertion"
workaround to resolve a problem with incorrectly handled VLAN-tagged
packets with no assigned VLAN group while the be2net driver was in
promiscuous mode. However, this solution led to packet corruption and a
subsequent kernel oops if such a processed packed was a GRO packet.
Therefore, a patch has been applied to restrict VLAN tag re-insertion only
to non-GRO packets. The be2net driver now processes VLAN-tagged packets
with no assigned VLAN group correctly in this situation. (BZ#1023348)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4355</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131790"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131791" severity="high">
    <xccdf:title>RHSA-2013:1791: nss and nspr security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS handled invalid handshake packets. A remote
attacker could use this flaw to cause a TLS/SSL client using NSS to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-5605)

It was found that the fix for CVE-2013-1620 released via RHSA-2013:1135
introduced a regression causing NSS to read uninitialized data when a
decryption failure occurred. A remote attacker could use this flaw to cause
a TLS/SSL server using NSS to crash. (CVE-2013-1739)

An integer overflow flaw was discovered in both NSS and NSPR's
implementation of certification parsing on 64-bit systems. A remote
attacker could use these flaws to cause an application using NSS or NSPR to
crash. (CVE-2013-1741, CVE-2013-5607)

It was discovered that NSS did not reject certificates with incompatible
key usage constraints when validating them while the verifyLog feature was
enabled. An application using the NSS certificate validation API could
accept an invalid certificate. (CVE-2013-5606)

Red Hat would like to thank the Mozilla project for reporting
CVE-2013-1741, CVE-2013-5606, and CVE-2013-5607. Upstream acknowledges
Tavis Ormandy as the original reporter of CVE-2013-1741, Camilo Viecco as
the original reporter of CVE-2013-5606, and Pascal Cuoq, Kamil Dudka, and
Wan-Teh Chang as the original reporters of CVE-2013-5607.

In addition, the nss package has been upgraded to upstream version 3.15.3,
and the nspr package has been upgraded to upstream version 4.10.2.
These updates provide a number of bug fixes and enhancements over the
previous versions. (BZ#1033478, BZ#1020520)

This update also fixes the following bug:

* The RHBA-2013:1318 update introduced a regression that prevented the use
of certificates that have an MD5 signature. This update fixes this
regression and certificates that have an MD5 signature are once again
supported. To prevent the use of certificates that have an MD5 signature,
set the "NSS_HASH_ALG_SUPPORT" environment variable to "-MD5". (BZ#1033499)

Users of NSS and NSPR are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing this
update, applications using NSS or NSPR must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5607</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131791"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131801" severity="high">
    <xccdf:title>RHSA-2013:1801: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled sending of certain UDP packets over sockets that
used the UDP_CORK option when the UDP Fragmentation Offload (UFO) feature
was enabled on the output device. A local, unprivileged user could use this
flaw to cause a denial of service or, potentially, escalate their
privileges on the system. (CVE-2013-4470, Important)

* A divide-by-zero flaw was found in the apic_get_tmcct() function in KVM's
Local Advanced Programmable Interrupt Controller (LAPIC) implementation.
A privileged guest user could use this flaw to crash the host.
(CVE-2013-6367, Important)

* A memory corruption flaw was discovered in the way KVM handled virtual
APIC accesses that crossed a page boundary. A local, unprivileged user
could use this flaw to crash the system or, potentially, escalate their
privileges on the system. (CVE-2013-6368, Important)

* An information leak flaw in the Linux kernel could allow a local,
unprivileged user to leak kernel memory to user space. (CVE-2013-2141, Low)

Red Hat would like to thank Hannes Frederic Sowa for reporting
CVE-2013-4470, and Andrew Honig of Google for reporting CVE-2013-6367 and
CVE-2013-6368.

This update also fixes several bugs and adds two enhancements.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6367</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6368</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131801"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131803" severity="medium">
    <xccdf:title>RHSA-2013:1803: libjpeg-turbo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libjpeg-turbo package contains a library of functions for manipulating
JPEG images. It also contains simple client programs for accessing the
libjpeg functions.

An uninitialized memory read issue was found in the way libjpeg-turbo
decoded images with missing Start Of Scan (SOS) JPEG markers or Define
Huffman Table (DHT) JPEG markers. A remote attacker could create a
specially crafted JPEG image that, when decoded, could possibly lead to a
disclosure of potentially sensitive information. (CVE-2013-6629,
CVE-2013-6630)

All libjpeg-turbo users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6629</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6630</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131803"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131804" severity="medium">
    <xccdf:title>RHSA-2013:1804: libjpeg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libjpeg package contains a library of functions for manipulating JPEG
images. It also contains simple client programs for accessing the
libjpeg functions.

An uninitialized memory read issue was found in the way libjpeg decoded
images with missing Start Of Scan (SOS) JPEG markers. A remote attacker
could create a specially crafted JPEG image that, when decoded, could
possibly lead to a disclosure of potentially sensitive information.
(CVE-2013-6629)

All libjpeg users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6629</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131804"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131805" severity="high">
    <xccdf:title>RHSA-2013:1805: samba4 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A heap-based buffer overflow flaw was found in the DCE-RPC client code in
Samba. A specially crafted DCE-RPC packet could cause various Samba
programs to crash or, possibly, execute arbitrary code when parsed.
A malicious or compromised Active Directory Domain Controller could use
this flaw to compromise the winbindd daemon running with root privileges.
(CVE-2013-4408)

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Stefan Metzmacher and Michael Adam of SerNet as the
original reporters of this issue.

All users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4408</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131805"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131806" severity="high">
    <xccdf:title>RHSA-2013:1806: samba and samba3x security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A heap-based buffer overflow flaw was found in the DCE-RPC client code in
Samba. A specially crafted DCE-RPC packet could cause various Samba
programs to crash or, possibly, execute arbitrary code when parsed.
A malicious or compromised Active Directory Domain Controller could use
this flaw to compromise the winbindd daemon running with root privileges.
(CVE-2013-4408)

A flaw was found in the way Samba performed ACL checks on alternate file
and directory data streams. An attacker able to access a CIFS share with
alternate stream support enabled could access alternate data streams
regardless of the underlying file or directory ACL permissions.
(CVE-2013-4475)

Red Hat would like to thank the Samba project for reporting CVE-2013-4408.
Upstream acknowledges Stefan Metzmacher and Michael Adam of SerNet as the
original reporters of this issue.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4475</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131806"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131812" severity="high">
    <xccdf:title>RHSA-2013:1812: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to terminate
unexpectedly or, potentially, execute arbitrary code with the privileges of
the user running Firefox. (CVE-2013-5609, CVE-2013-5616, CVE-2013-5618,
CVE-2013-6671, CVE-2013-5613)

A flaw was found in the way Firefox rendered web content with missing
character encoding information. An attacker could use this flaw to possibly
bypass same-origin inheritance and perform cross-site scripting (XSS)
attacks. (CVE-2013-5612)

It was found that certain malicious web content could bypass restrictions
applied by sandboxed iframes. An attacker could combine this flaw with
other vulnerabilities to execute arbitrary code with the privileges of the
user running Firefox. (CVE-2013-5614)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Ben Turner, Bobby Holley, Jesse Ruderman, Christian
Holler, Masato Kinugawa, Daniel Veditz, Jesse Schwartzentruber, Nils, Tyson
Smith, and Atte Kettunen as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.2.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.2.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5614</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5618</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6671</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131812"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131813" severity="high">
    <xccdf:title>RHSA-2013:1813: php53 and php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A memory corruption flaw was found in the way the openssl_x509_parse()
function of the PHP openssl extension parsed X.509 certificates. A remote
attacker could use this flaw to provide a malicious self-signed certificate
or a certificate signed by a trusted authority to a PHP application using
the aforementioned function, causing the application to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
user running the PHP interpreter. (CVE-2013-6420)

Red Hat would like to thank the PHP project for reporting this issue.
Upstream acknowledges Stefan Esser as the original reporter of this issue.

All php53 and php users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6420</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131813"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131814" severity="high">
    <xccdf:title>RHSA-2013:1814: php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A memory corruption flaw was found in the way the openssl_x509_parse()
function of the PHP openssl extension parsed X.509 certificates. A remote
attacker could use this flaw to provide a malicious self-signed certificate
or a certificate signed by a trusted authority to a PHP application using
the aforementioned function, causing the application to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
user running the PHP interpreter. (CVE-2013-6420)

It was found that PHP did not check for carriage returns in HTTP headers,
allowing intended HTTP response splitting protections to be bypassed.
Depending on the web browser the victim is using, a remote attacker could
use this flaw to perform HTTP response splitting attacks. (CVE-2011-1398)

An integer signedness issue, leading to a heap-based buffer underflow, was
found in the PHP scandir() function. If a remote attacker could upload an
excessively large number of files to a directory the scandir() function
runs on, it could cause the PHP interpreter to crash or, possibly, execute
arbitrary code. (CVE-2012-2688)

It was found that the PHP SOAP parser allowed the expansion of external XML
entities during SOAP message parsing. A remote attacker could possibly use
this flaw to read arbitrary files that are accessible to a PHP application
using a SOAP extension. (CVE-2013-1643)

Red Hat would like to thank the PHP project for reporting CVE-2013-6420.
Upstream acknowledges Stefan Esser as the original reporter.

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-1398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6420</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131814"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131823" severity="high">
    <xccdf:title>RHSA-2013:1823: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content.
Malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2013-5609, CVE-2013-5616, CVE-2013-5618, CVE-2013-6671, CVE-2013-5613)

A flaw was found in the way Thunderbird rendered web content with missing
character encoding information. An attacker could use this flaw to possibly
bypass same-origin inheritance and perform cross site-scripting (XSS)
attacks. (CVE-2013-5612)

It was found that certain malicious web content could bypass restrictions
applied by sandboxed iframes. An attacker could combine this flaw with
other vulnerabilities to execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2013-5614)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Ben Turner, Bobby Holley, Jesse Ruderman, Christian
Holler, Masato Kinugawa, Daniel Veditz, Jesse Schwartzentruber, Nils, Tyson
Smith, and Atte Kettunen as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.2.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.2.0 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5609</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5612</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5614</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5618</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6674</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131823"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131829" severity="high">
    <xccdf:title>RHSA-2013:1829: nss, nspr, and nss-util security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS handled invalid handshake packets. A remote
attacker could use this flaw to cause a TLS/SSL client using NSS to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-5605)

It was found that the fix for CVE-2013-1620 released via RHSA-2013:1135
introduced a regression causing NSS to read uninitialized data when a
decryption failure occurred. A remote attacker could use this flaw to cause
a TLS/SSL server using NSS to crash. (CVE-2013-1739)

An integer overflow flaw was discovered in both NSS and NSPR's
implementation of certification parsing on 64-bit systems. A remote
attacker could use these flaws to cause an application using NSS or NSPR to
crash. (CVE-2013-1741, CVE-2013-5607)

It was discovered that NSS did not reject certificates with incompatible
key usage constraints when validating them while the verifyLog feature was
enabled. An application using the NSS certificate validation API could
accept an invalid certificate. (CVE-2013-5606)

Red Hat would like to thank the Mozilla project for reporting
CVE-2013-1741, CVE-2013-5606, and CVE-2013-5607. Upstream acknowledges
Tavis Ormandy as the original reporter of CVE-2013-1741, Camilo Viecco as
the original reporter of CVE-2013-5606, and Pascal Cuoq, Kamil Dudka, and
Wan-Teh Chang as the original reporters of CVE-2013-5607.

All NSS, NSPR, and nss-util users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.
After installing this update, applications using NSS, NSPR, or nss-util
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5607</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131829"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131850" severity="high">
    <xccdf:title>RHSA-2013:1850: openjpeg security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenJPEG is an open source library for reading and writing image files in
JPEG 2000 format.

Multiple heap-based buffer overflow flaws were found in OpenJPEG.
An attacker could create a specially crafted OpenJPEG image that, when
opened, could cause an application using openjpeg to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-6045, CVE-2013-6054)

Multiple denial of service flaws were found in OpenJPEG. An attacker could
create a specially crafted OpenJPEG image that, when opened, could cause an
application using openjpeg to crash (CVE-2013-1447, CVE-2013-6052)

Red Hat would like to thank Raphael Geissert for reporting these issues.

Users of OpenJPEG are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using OpenJPEG must be restarted for the update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1850</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6054</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131850"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131860" severity="medium">
    <xccdf:title>RHSA-2013:1860: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An information leak flaw was found in the way the Linux kernel's device
mapper subsystem, under certain conditions, interpreted data written to
snapshot block devices. An attacker could use this flaw to read data from
disk blocks in free space, which are normally inaccessible. (CVE-2013-4299,
Moderate)

Red Hat would like to thank Fujitsu for reporting this issue.

This update also fixes the following bugs:

* A previous fix to the kernel did not contain a memory barrier in the percpu_up_write() function. Consequently, under certain circumstances, a race condition could occur, leading to memory corruption and a subsequent kernel panic. This update introduces a new memory barrier pair, light_mb() and heavy_mb(), for per-CPU basis read and write semaphores (percpu-rw-semaphores) ensuring that the race condition can no longer occur. In addition, the read path performance of "percpu-rw-semaphores" has been improved. (BZ#884735)

* Due to several related bugs in the be2net driver, the driver did not handle firmware manipulation of the network cards using the Emulex XE201 I/O controller properly. As a consequence, these NICs could not recover from an error successfully. A series of patches has been applied that fix the initialization sequence, and firmware download and activation for the XE201 controller. Error recovery now works as expected for the be2net NICs using the Emulex XE201 I/O controller. (BZ#1019892)

* A bug in the be2net driver could cause packet corruption when handling VLAN-tagged packets with no assigned VLAN group. This happened because the be2net driver called a function responsible for VLAN tag reinsertion in a wrong order in the code. The code has been restructured and the be2net driver now calls the __vlan_put_tag() function correctly, thus avoiding the packet corruption. (BZ#1019893)

* A previous patch to the kernel introduced the "VLAN tag re-insertion" workaround to resolve a problem with incorrectly handled VLAN-tagged packets with no assigned VLAN group while the be2net driver was in promiscuous mode. However, this solution led to packet corruption and a subsequent kernel oops if such a processed packet was a GRO packet. Therefore, a patch has been applied to restrict VLAN tag re-insertion only to non-GRO packets. The be2net driver now processes VLAN-tagged packets with no assigned VLAN group correctly in this situation. (BZ#1023347)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4299</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131860"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131866" severity="medium">
    <xccdf:title>RHSA-2013:1866: ca-certificates security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).

It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)

All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1866</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131866"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131868" severity="high">
    <xccdf:title>RHSA-2013:1868: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

An integer overflow, which led to a heap-based buffer overflow, was found
in the way X.Org server handled trapezoids. A malicious, authorized client
could use this flaw to crash the X.Org server or, potentially, execute
arbitrary code with root privileges. (CVE-2013-6424)

All xorg-x11-server users are advised to upgrade to these updated 
packages, which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6424</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131868"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20131869" severity="high">
    <xccdf:title>RHSA-2013:1869: pixman security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pixman is a pixel manipulation library for the X Window System and Cairo.

An integer overflow, which led to a heap-based buffer overflow, was found
in the way pixman handled trapezoids. If a remote attacker could trick an 
application using pixman into rendering a trapezoid shape with specially 
crafted coordinates, it could cause the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-6425)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. All applications using pixman 
must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2013:1869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6425</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20131869"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140015" severity="high">
    <xccdf:title>RHSA-2014:0015: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A flaw was found in the way OpenSSL determined which hashing algorithm to
use when TLS protocol version 1.2 was enabled. This could possibly cause
OpenSSL to use an incorrect hashing algorithm, leading to a crash of an
application using the library. (CVE-2013-6449)

It was discovered that the Datagram Transport Layer Security (DTLS)
protocol implementation in OpenSSL did not properly maintain encryption and
digest contexts during renegotiation. A lost or discarded renegotiation
handshake packet could cause a DTLS client or server using OpenSSL to
crash. (CVE-2013-6450)

A NULL pointer dereference flaw was found in the way OpenSSL handled
TLS/SSL protocol handshake packets. A specially crafted handshake packet
could cause a TLS/SSL client using OpenSSL to crash. (CVE-2013-4353)

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6450</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140015"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140016" severity="medium">
    <xccdf:title>RHSA-2014:0016: gnupg security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and
creating digital signatures, compliant with the proposed OpenPGP Internet
standard and the S/MIME standard.

It was found that GnuPG was vulnerable to side-channel attacks via acoustic
cryptanalysis. An attacker in close range to a target system that is
decrypting ciphertexts could possibly use this flaw to recover the RSA
secret key from that system. (CVE-2013-4576)

Red Hat would like to thank Werner Koch of GnuPG upstream for reporting
this issue. Upstream acknowledges Genkin, Shamir, and Tromer as the
original reporters.

All gnupg users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4576</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140018" severity="high">
    <xccdf:title>RHSA-2014:0018: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A stack-based buffer overflow flaw was found in the way the libXfont
library parsed Glyph Bitmap Distribution Format (BDF) fonts. A malicious,
local user could exploit this issue to potentially execute arbitrary code
with the privileges of the X.Org server. (CVE-2013-6462)

Users of libXfont should upgrade to these updated packages, which contain
a backported patch to resolve this issue. All running X.Org server
instances must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0018</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6462</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140018"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140026" severity="high">
    <xccdf:title>RHSA-2014:0026: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

An input validation flaw was discovered in the font layout engine in the 2D
component. A specially crafted font file could trigger Java Virtual Machine
memory corruption when processed. An untrusted Java application or applet
could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2013-5907)

Multiple improper permission check issues were discovered in the CORBA,
JNDI, and Libraries components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2014-0428, CVE-2014-0422, CVE-2013-5893)

Multiple improper permission check issues were discovered in the
Serviceability, Security, CORBA, JAAS, JAXP, and Networking components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2014-0373, CVE-2013-5878,
CVE-2013-5910, CVE-2013-5896, CVE-2013-5884, CVE-2014-0416, CVE-2014-0376,
CVE-2014-0368)

It was discovered that the Beans component did not restrict processing of
XML external entities. This flaw could cause a Java application using Beans
to leak sensitive information, or affect application availability.
(CVE-2014-0423)

It was discovered that the JSSE component could leak timing information
during the TLS/SSL handshake. This could possibly lead to disclosure of
information about the used encryption keys. (CVE-2014-0411)

Note: The java-1.7.0-openjdk package shipped with Red Hat Enterprise Linux
6.5 via RHBA-2013:1611 replaced "java7" with "java" in the provides list.
This update re-adds "java7" to the provides list to maintain backwards
compatibility with releases prior to Red Hat Enterprise Linux 6.5.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0368</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0428</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140026"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140027" severity="high">
    <xccdf:title>RHSA-2014:0027: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 7 Java Runtime Environment and the
OpenJDK 7 Software Development Kit.

An input validation flaw was discovered in the font layout engine in the 2D
component. A specially crafted font file could trigger Java Virtual Machine
memory corruption when processed. An untrusted Java application or applet
could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2013-5907)

Multiple improper permission check issues were discovered in the CORBA,
JNDI, and Libraries components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2014-0428, CVE-2014-0422, CVE-2013-5893)

Multiple improper permission check issues were discovered in the
Serviceability, Security, CORBA, JAAS, JAXP, and Networking components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2014-0373, CVE-2013-5878,
CVE-2013-5910, CVE-2013-5896, CVE-2013-5884, CVE-2014-0416, CVE-2014-0376,
CVE-2014-0368)

It was discovered that the Beans component did not restrict processing of
XML external entities. This flaw could cause a Java application using Beans
to leak sensitive information, or affect application availability.
(CVE-2014-0423)

It was discovered that the JSSE component could leak timing information
during the TLS/SSL handshake. This could possibly lead to disclosure of
information about the used encryption keys. (CVE-2014-0411)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0368</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0428</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140027"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140043" severity="medium">
    <xccdf:title>RHSA-2014:0043: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND handled queries for
NSEC3-signed zones. A remote attacker could use this flaw against an
authoritative name server that served NCES3-signed zones by sending a
specially crafted query, which, when processed, would cause named to crash.
(CVE-2014-0591)

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0043</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0591</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140043"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140044" severity="medium">
    <xccdf:title>RHSA-2014:0044: augeas security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Augeas is a utility for editing configuration. Augeas parses configuration
files in their native formats and transforms them into a tree.
Configuration changes are made by manipulating this tree and saving it back
into native configuration files. Augeas also uses "lenses" as basic
building blocks for establishing the mapping from files into the Augeas
tree and back.

A flaw was found in the way Augeas handled certain umask settings when
creating new configuration files. This flaw could result in configuration
files being created as world writable, allowing unprivileged local users to
modify their content. (CVE-2013-6412)

This issue was discovered by the Red Hat Security Response Team.

All augeas users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using augeas must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0044</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140044"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140097" severity="high">
    <xccdf:title>RHSA-2014:0097: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the font layout engine in the 2D
component. A specially crafted font file could trigger a Java Virtual
Machine memory corruption when processed. An untrusted Java application or
applet could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2013-5907)

Multiple improper permission check issues were discovered in the CORBA and
JNDI components in OpenJDK. An untrusted Java application or applet could
use these flaws to bypass Java sandbox restrictions. (CVE-2014-0428,
CVE-2014-0422)

Multiple improper permission check issues were discovered in the
Serviceability, Security, CORBA, JAAS, JAXP, and Networking components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2014-0373, CVE-2013-5878,
CVE-2013-5910, CVE-2013-5896, CVE-2013-5884, CVE-2014-0416, CVE-2014-0376,
CVE-2014-0368)

It was discovered that the Beans component did not restrict processing of
XML external entities. This flaw could cause a Java application using Beans
to leak sensitive information, or affect application availability.
(CVE-2014-0423)

It was discovered that the JSSE component could leak timing information
during the TLS/SSL handshake. This could possibly lead to a disclosure of
information about the used encryption keys. (CVE-2014-0411)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0368</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0428</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140097"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140103" severity="medium">
    <xccdf:title>RHSA-2014:0103: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

A use-after-free flaw was found in the way several libvirt block APIs
handled domain jobs. A remote attacker able to establish a read-only
connection to libvirtd could use this flaw to crash libvirtd or,
potentially, execute arbitrary code with the privileges of the libvirtd
process (usually root). (CVE-2013-6458)

A race condition was found in the way libvirtd handled keepalive
initialization requests when the connection was closed prior to
establishing connection credentials. An attacker able to establish a
read-only connection to libvirtd could use this flaw to crash libvirtd,
resulting in a denial of service. (CVE-2014-1447)

This update also fixes the following bug:

* A race condition was possible between a thread starting a virtual machine
with a guest agent configured (regular start-up or while migrating) and a
thread that was killing the VM process (or the process crashing). The race
could cause the monitor object to be freed by the thread that killed the VM
process, which was later accessed by the thread that was attempting to
start the VM, resulting in a crash. This issue was fixed by checking the
state of the VM after the attempted connection to the guest agent; if the
VM in the meantime exited, no other operations are attempted. (BZ#1055578)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0103</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1447</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140103"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140108" severity="medium">
    <xccdf:title>RHSA-2014:0108: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Xen hypervisor did not always lock
'page_alloc_lock' and 'grant_table.lock' in the same order. This could
potentially lead to a deadlock. A malicious guest administrator could use
this flaw to cause a denial of service on the host. (CVE-2013-4494,
Moderate)

Red Hat would like to thank the Xen project for reporting this issue.

This update also fixes the following bugs:

* A recent patch to the CIFS code that introduced the NTLMSSP 
(NT LAN Manager Security Support Provider) authentication mechanism caused
a regression in CIFS behavior. As a result of the regression, an encryption
key that is returned during the SMB negotiation protocol response was only
used for the first session that was created on the SMB client. Any
subsequent mounts to the same server did not use the encryption key
returned by the initial negotiation with the server. As a consequence, it
was impossible to mount multiple SMB shares with different credentials to
the same server. A patch has been applied to correct this problem so that
an encryption key or a server challenge is now provided for every SMB
session during the SMB negotiation protocol response. (BZ#1029865)

* The igb driver previously used a 16-bit mask when writing values of the
flow control high-water mark to hardware registers on a network device.
Consequently, the values were truncated on some network devices, disrupting
the flow control. A patch has been applied to the igb driver so that it now
uses a 32-bit mask as expected. (BZ#1041694)

* The IPMI driver did not properly handle kernel panic messages.
Consequently, when a kernel panic occurred on a system that was utilizing
IPMI without Kdump being set up, a second kernel panic could be triggered.
A patch has been applied to the IPMI driver to fix this problem, and a
message handler now properly waits for a response to panic event messages.
(BZ#1049731)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140108"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140126" severity="medium">
    <xccdf:title>RHSA-2014:0126: openldap security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols used
to access and maintain distributed directory information services over an
IP network. The openldap package contains configuration files, libraries,
and documentation for OpenLDAP.

A denial of service flaw was found in the way the OpenLDAP server daemon
(slapd) performed reference counting when using the rwm (rewrite/remap)
overlay. A remote attacker able to query the OpenLDAP server could use this
flaw to crash the server by immediately unbinding from the server after
sending a search request. (CVE-2013-4449)

Red Hat would like to thank Michael Vishchers from Seven Principles AG for
reporting this issue.

This update also fixes the following bug:

* Previously, OpenLDAP did not properly handle a number of simultaneous
updates. As a consequence, sending a number of parallel update requests to
the server could cause a deadlock. With this update, a superfluous locking
mechanism causing the deadlock has been removed, thus fixing the bug.
(BZ#1056124)

All openldap users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4449</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140126"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140127" severity="medium">
    <xccdf:title>RHSA-2014:0127: librsvg2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The librsvg2 packages provide an SVG (Scalable Vector Graphics) library
based on libart.

An XML External Entity expansion flaw was found in the way librsvg2
processed SVG files. If a user were to open a malicious SVG file, a remote
attacker could possibly obtain a copy of the local resources that the user
had access to. (CVE-2013-1881)

All librsvg2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
that use librsvg2 must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0127</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1881</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140127"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140132" severity="high">
    <xccdf:title>RHSA-2014:0132: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1477, CVE-2014-1482, CVE-2014-1486)

A flaw was found in the way Firefox handled error messages related to web
workers. An attacker could use this flaw to bypass the same-origin policy,
which could lead to cross-site scripting (XSS) attacks, or could
potentially be used to gather authentication tokens and other data from
third-party websites. (CVE-2014-1487)

A flaw was found in the implementation of System Only Wrappers (SOW).
An attacker could use this flaw to crash Firefox. When combined with other
vulnerabilities, this flaw could have additional security implications.
(CVE-2014-1479)

It was found that the Firefox JavaScript engine incorrectly handled window
objects. A remote attacker could use this flaw to bypass certain security
checks and possibly execute arbitrary code. (CVE-2014-1481)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Terrence Cole, Jesse Ruderman, Gary
Kwong, Eric Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Sotaro
Ikeda, Cody Crews, Fredrik "Flonka" Lönnqvist, Arthur Gerkis, Masato
Kinugawa, and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.3.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.3.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0132</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1487</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140132"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140133" severity="high">
    <xccdf:title>RHSA-2014:0133: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content.
Malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1477, CVE-2014-1482, CVE-2014-1486)

A flaw was found in the way Thunderbird handled error messages related to
web workers. An attacker could use this flaw to bypass the same-origin
policy, which could lead to cross-site scripting (XSS) attacks, or could
potentially be used to gather authentication tokens and other data from
third-party websites. (CVE-2014-1487)

A flaw was found in the implementation of System Only Wrappers (SOW).
An attacker could use this flaw to crash Thunderbird. When combined with
other vulnerabilities, this flaw could have additional security
implications. (CVE-2014-1479)

It was found that the Thunderbird JavaScript engine incorrectly handled
window objects. A remote attacker could use this flaw to bypass certain
security checks and possibly execute arbitrary code. (CVE-2014-1481)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Terrence Cole, Jesse Ruderman, Gary
Kwong, Eric Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Sotaro
Ikeda, Cody Crews, Fredrik "Flonka" Lönnqvist, Arthur Gerkis, Masato
Kinugawa, and Boris Zbarsky as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.3.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.3.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0133</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1487</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140133"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140139" severity="medium">
    <xccdf:title>RHSA-2014:0139: pidgin security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A heap-based buffer overflow flaw was found in the way Pidgin processed
certain HTTP responses. A malicious server could send a specially crafted
HTTP response, causing Pidgin to crash or potentially execute arbitrary
code with the permissions of the user running Pidgin. (CVE-2013-6485)

Multiple heap-based buffer overflow flaws were found in several protocol
plug-ins in Pidgin (Gadu-Gadu, MXit, SIMPLE). A malicious server could send
a specially crafted message, causing Pidgin to crash or potentially execute
arbitrary code with the permissions of the user running Pidgin.
(CVE-2013-6487, CVE-2013-6489, CVE-2013-6490)

Multiple denial of service flaws were found in several protocol plug-ins in
Pidgin (Yahoo!, XMPP, MSN, stun, IRC). A remote attacker could use these
flaws to crash Pidgin by sending a specially crafted message.
(CVE-2012-6152, CVE-2013-6477, CVE-2013-6481, CVE-2013-6482, CVE-2013-6484,
CVE-2014-0020)

It was found that the Pidgin XMPP protocol plug-in did not verify the
origin of "iq" replies. A remote attacker could use this flaw to spoof an
"iq" reply, which could lead to injection of fake data or cause Pidgin to
crash via a NULL pointer dereference. (CVE-2013-6483)

A flaw was found in the way Pidgin parsed certain HTTP response headers.
A remote attacker could use this flaw to crash Pidgin via a specially
crafted HTTP response header. (CVE-2013-6479)

It was found that Pidgin crashed when a mouse pointer was hovered over a
long URL. A remote attacker could use this flaw to crash Pidgin by sending
a message containing a long URL string. (CVE-2013-6478)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Thijs Alkemade, Robert Vehse, Jaime Breva Ribes,
Jacob Appelbaum of the Tor Project, Daniel Atallah, Fabian Yamaguchi and
Christian Wressnegger of the University of Goettingen, Matt Jones of
Volvent, and Yves Younan, Ryan Pentney, and Pawel Janic of Sourcefire VRT
as the original reporters of these issues.

All pidgin users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Pidgin must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6481</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6487</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6489</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0020</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140139"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140151" severity="low">
    <xccdf:title>RHSA-2014:0151: wget security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wget package provides the GNU Wget file retrieval utility for HTTP,
HTTPS, and FTP protocols. Wget provides various useful features, such as
the ability to work in the background while the user is logged out,
recursive retrieval of directories, file name wildcard matching or updating
files in dependency on file timestamp comparison.

It was discovered that wget used a file name provided by the server when
saving a downloaded file. This could cause wget to create a file with a
different name than expected, possibly allowing the server to execute
arbitrary code on the client. (CVE-2010-2252)

Note: With this update, wget always uses the last component of the original
URL as the name for the downloaded file. Previous behavior of using the
server provided name or the last component of the redirected URL when
creating files can be re-enabled by using the '--trust-server-names'
command line option, or by setting 'trust_server_names=on' in the wget
start-up file.

This update also fixes the following bugs:

* Prior to this update, the wget package did not recognize HTTPS SSL
certificates with alternative names (subjectAltName) specified in the
certificate as valid. As a consequence, running the wget command failed
with a certificate error. This update fixes wget to recognize such
certificates as valid. (BZ#1060113)

All users of wget are advised to upgrade to this updated package, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2252</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140151"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140159" severity="high">
    <xccdf:title>RHSA-2014:0159: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A buffer overflow flaw was found in the way the qeth_snmp_command()
function in the Linux kernel's QETH network device driver implementation
handled SNMP IOCTL requests with an out-of-bounds length. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2013-6381, Important)

* A flaw was found in the way the get_dumpable() function return value was
interpreted in the ptrace subsystem of the Linux kernel. When
'fs.suid_dumpable' was set to 2, a local, unprivileged local user could
use this flaw to bypass intended ptrace restrictions and obtain
potentially sensitive information. (CVE-2013-2929, Low)

* It was found that certain protocol handlers in the Linux kernel's
networking implementation could set the addr_len value without initializing
the associated data structure. A local, unprivileged user could use this
flaw to leak kernel stack memory to user space using the recvmsg, recvfrom,
and recvmmsg system calls (CVE-2013-7263, CVE-2013-7265, Low).

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6381</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7265</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140159"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140163" severity="high">
    <xccdf:title>RHSA-2014:0163: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A divide-by-zero flaw was found in the apic_get_tmcct() function in KVM's
Local Advanced Programmable Interrupt Controller (LAPIC) implementation.
A privileged guest user could use this flaw to crash the host.
(CVE-2013-6367)

A memory corruption flaw was discovered in the way KVM handled virtual APIC
accesses that crossed a page boundary. A local, unprivileged user could use
this flaw to crash the system or, potentially, escalate their privileges on
the system. (CVE-2013-6368)

Red Hat would like to thank Andrew Honig of Google for reporting these
issues.

All kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Note: the procedure in
the Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0163</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6367</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6368</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140163"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140164" severity="medium">
    <xccdf:title>RHSA-2014:0164: mysql security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-0386,
CVE-2014-0393, CVE-2014-0401, CVE-2014-0402, CVE-2014-0412, CVE-2014-0437,
CVE-2013-5908)

A buffer overflow flaw was found in the way the MySQL command line client
tool (mysql) processed excessively long version strings. If a user
connected to a malicious MySQL server via the mysql client, the server
could use this flaw to crash the mysql client or, potentially, execute
arbitrary code as the user running the mysql client. (CVE-2014-0001)

The CVE-2014-0001 issue was discovered by Garth Mollett of the Red Hat
Security Response Team.

This update also fixes the following bug:

* Prior to this update, MySQL did not check whether a MySQL socket was
actually being used by any process before starting the mysqld service. If a
particular mysqld service did not exit cleanly while a socket was being
used by a process, this socket was considered to be still in use during the
next start-up of this service, which resulted in a failure to start the
service up. With this update, if a socket exists but is not used by any
process, it is ignored during the mysqld service start-up. (BZ#1058719)

These updated packages upgrade MySQL to version 5.1.73. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140174" severity="high">
    <xccdf:title>RHSA-2014:0174: piranha security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Piranha provides high-availability and load-balancing services for Red Hat
Enterprise Linux. The piranha packages contain various tools to administer
and configure the Linux Virtual Server (LVS), as well as the heartbeat and
failover components. LVS is a dynamically-adjusted kernel routing mechanism
that provides load balancing, primarily for Web and FTP servers.

It was discovered that the Piranha Configuration Tool did not properly
restrict access to its web pages. A remote attacker able to connect to the
Piranha Configuration Tool web server port could use this flaw to read or
modify the LVS configuration without providing valid administrative
credentials. (CVE-2013-6492)

All piranha users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140174"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140175" severity="high">
    <xccdf:title>RHSA-2014:0175: piranha security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Piranha provides high-availability and load-balancing services for Red Hat
Enterprise Linux. The piranha packages contain various tools to administer
and configure the Linux Virtual Server (LVS), as well as the heartbeat and
failover components. LVS is a dynamically-adjusted kernel routing mechanism
that provides load balancing, primarily for Web and FTP servers.

It was discovered that the Piranha Configuration Tool did not properly
restrict access to its web pages. A remote attacker able to connect to the
Piranha Configuration Tool web server port could use this flaw to read or
modify the LVS configuration without providing valid administrative
credentials. (CVE-2013-6492)

This update also fixes the following bug:

* When the lvsd service attempted to start, the sem_timedwait() function
received the interrupted function call (EINTR) error and exited, causing
the lvsd service to fail to start. With this update, EINTR errors are
correctly ignored during the start-up of the lvsd service. (BZ#1055709)

All piranha users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140175"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140185" severity="medium">
    <xccdf:title>RHSA-2014:0185: openswan security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Openswan is a free implementation of Internet Protocol Security (IPsec) and
Internet Key Exchange (IKE). IPsec uses strong cryptography to provide both
authentication and encryption services. These services allow you to build
secure tunnels through untrusted networks.

A NULL pointer dereference flaw was discovered in the way Openswan's IKE
daemon processed IKEv2 payloads. A remote attacker could send specially
crafted IKEv2 payloads that, when processed, would lead to a denial of
service (daemon crash), possibly causing existing VPN connections to be
dropped. (CVE-2013-6466)

All openswan users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6466</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140185"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140186" severity="medium">
    <xccdf:title>RHSA-2014:0186: mysql55-mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2013-5807,
CVE-2013-5891, CVE-2014-0386, CVE-2014-0393, CVE-2014-0401, CVE-2014-0402,
CVE-2014-0412, CVE-2014-0420, CVE-2014-0437, CVE-2013-3839, CVE-2013-5908)

A buffer overflow flaw was found in the way the MySQL command line client
tool (mysql) processed excessively long version strings. If a user
connected to a malicious MySQL server via the mysql client, the server
could use this flaw to crash the mysql client or, potentially, execute
arbitrary code as the user running the mysql client. (CVE-2014-0001)

The CVE-2014-0001 issue was discovered by Garth Mollett of the Red Hat
Security Response Team.

These updated packages upgrade MySQL to version 5.5.36. Refer to the MySQL
Release Notes listed in the References section for a complete list
of changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3839</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5891</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0386</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140186"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140206" severity="medium">
    <xccdf:title>RHSA-2014:0206: openldap security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols used
to access and maintain distributed directory information services over an
IP network. The openldap package contains configuration files, libraries,
and documentation for OpenLDAP.

A denial of service flaw was found in the way the OpenLDAP server daemon
(slapd) performed reference counting when using the rwm (rewrite/remap)
overlay. A remote attacker able to query the OpenLDAP server could use this
flaw to crash the server by immediately unbinding from the server after
sending a search request. (CVE-2013-4449)

Red Hat would like to thank Michael Vishchers from Seven Principles AG for
reporting this issue.

All openldap users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4449</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140206"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140211" severity="high">
    <xccdf:title>RHSA-2014:0211: postgresql84 and postgresql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)

Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)

It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)

A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)

A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)

It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.

These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0211</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0066</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140211"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140222" severity="medium">
    <xccdf:title>RHSA-2014:0222: libtiff security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow and a use-after-free flaw were found in the
tiff2pdf tool. An attacker could use these flaws to create a specially
crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute
arbitrary code. (CVE-2013-1960, CVE-2013-4232)

Multiple buffer overflow flaws were found in the gif2tiff tool. An attacker
could use these flaws to create a specially crafted GIF file that could
cause gif2tiff to crash or, possibly, execute arbitrary code.
(CVE-2013-4231, CVE-2013-4243, CVE-2013-4244)

A flaw was found in the way libtiff handled OJPEG-encoded TIFF images. An
attacker could use this flaw to create a specially crafted TIFF file that
would cause an application using libtiff to crash. (CVE-2010-2596)

Multiple buffer overflow flaws were found in the tiff2pdf tool. An attacker
could use these flaws to create a specially crafted TIFF file that would
cause tiff2pdf to crash. (CVE-2013-1961)

Red Hat would like to thank Emmanuel Bouillon of NCI Agency for reporting
CVE-2013-1960 and CVE-2013-1961. The CVE-2013-4243 issue was discovered by
Murray McAllister of the Red Hat Security Response Team, and the
CVE-2013-4244 issue was discovered by Huzaifa Sidhpurwala of the Red Hat
Security Response Team.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against libtiff must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-2596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140222"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140223" severity="medium">
    <xccdf:title>RHSA-2014:0223: libtiff security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow and a use-after-free flaw were found in the
tiff2pdf tool. An attacker could use these flaws to create a specially
crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute
arbitrary code. (CVE-2013-1960, CVE-2013-4232)

Multiple buffer overflow flaws were found in the gif2tiff tool. An attacker
could use these flaws to create a specially crafted GIF file that could
cause gif2tiff to crash or, possibly, execute arbitrary code.
(CVE-2013-4231, CVE-2013-4243, CVE-2013-4244)

Multiple buffer overflow flaws were found in the tiff2pdf tool. An attacker
could use these flaws to create a specially crafted TIFF file that would
cause tiff2pdf to crash. (CVE-2013-1961)

Red Hat would like to thank Emmanuel Bouillon of NCI Agency for reporting
CVE-2013-1960 and CVE-2013-1961. The CVE-2013-4243 issue was discovered by
Murray McAllister of the Red Hat Security Response Team, and the
CVE-2013-4244 issue was discovered by Huzaifa Sidhpurwala of the Red Hat
Security Response Team.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against libtiff must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1960</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1961</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140223"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140246" severity="high">
    <xccdf:title>RHSA-2014:0246: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)

The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the
Red Hat Security Technologies Team.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0246</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0092</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140246"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140247" severity="high">
    <xccdf:title>RHSA-2014:0247: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)

A flaw was found in the way GnuTLS handled version 1 X.509 certificates.
An attacker able to obtain a version 1 certificate from a trusted
certificate authority could use this flaw to issue certificates for other
sites that would be accepted by GnuTLS as valid. (CVE-2009-5138)

The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the
Red Hat Security Technologies Team.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-5138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0092</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140247"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140249" severity="high">
    <xccdf:title>RHSA-2014:0249: postgresql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)

Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)

It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)

A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)

A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)

It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0066</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140249"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140255" severity="medium">
    <xccdf:title>RHSA-2014:0255: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A flaw was found in the way the mod_dav_svn module handled OPTIONS
requests. A remote attacker with read access to an SVN repository served
via HTTP could use this flaw to cause the httpd process that handled such a
request to crash. (CVE-2014-0032)

A flaw was found in the way Subversion handled file names with newline
characters when the FSFS repository format was used. An attacker with
commit access to an SVN repository could corrupt a revision by committing a
specially crafted file. (CVE-2013-1968)

A flaw was found in the way the svnserve tool of Subversion handled remote
client network connections. An attacker with read access to an SVN
repository served via svnserve could use this flaw to cause the svnserve
daemon to exit, leading to a denial of service. (CVE-2013-2112)

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1968</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0032</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140255"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140266" severity="medium">
    <xccdf:title>RHSA-2014:0266: sudo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the way sudo handled its blacklist of environment
variables. When the "env_reset" option was disabled, a user permitted to
run certain commands via sudo could use this flaw to run such a command
with one of the blacklisted environment variables set, allowing them to run
an arbitrary command with the target user's privileges. (CVE-2014-0106)

Note: This issue does not affect the default configuration of the sudo
package as shipped with Red Hat Enterprise Linux 5.

Red Hat would like to thank Todd C. Miller for reporting this issue.
Upstream acknowledges Sebastien Macke as the original reporter.

All sudo users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0106</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140266"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140285" severity="high">
    <xccdf:title>RHSA-2014:0285: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A buffer overflow flaw was found in the way the qeth_snmp_command()
function in the Linux kernel's QETH network device driver implementation
handled SNMP IOCTL requests with an out-of-bounds length. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2013-6381, Important)

* A flaw was found in the way the ipc_rcu_putref() function in the Linux
kernel's IPC implementation handled reference counter decrementing.
A local, unprivileged user could use this flaw to trigger an Out of Memory
(OOM) condition and, potentially, crash the system. (CVE-2013-4483,
Moderate)

* It was found that the Xen hypervisor implementation did not correctly
check privileges of hypercall attempts made by HVM guests, allowing
hypercalls to be invoked from protection rings 1 and 2 in addition to ring
0. A local attacker in an HVM guest able to execute code on privilege
levels 1 and 2 could potentially use this flaw to further escalate their
privileges in that guest. Note: Xen HVM guests running unmodified versions
of Red Hat Enterprise Linux and Microsoft Windows are not affected by this
issue because they are known to only use protection rings 0 (kernel) and 3
(userspace). (CVE-2013-4554, Moderate)

* A flaw was found in the way the Linux kernel's Adaptec RAID controller
(aacraid) checked permissions of compat IOCTLs. A local attacker could use
this flaw to bypass intended security restrictions. (CVE-2013-6383,
Moderate)

* It was found that, under specific circumstances, a combination of write
operations to write-combined memory and locked CPU instructions may cause a
core hang on certain AMD CPUs (for more information, refer to AMD CPU
erratum 793 linked in the References section). A privileged user in a guest
running under the Xen hypervisor could use this flaw to cause a denial of
service on the host system. This update adds a workaround to the Xen
hypervisor implementation, which mitigates the AMD CPU issue. Note: this
issue only affects AMD Family 16h Models 00h-0Fh Processors. Non-AMD CPUs
are not vulnerable. (CVE-2013-6885, Moderate)

* It was found that certain protocol handlers in the Linux kernel's
networking implementation could set the addr_len value without initializing
the associated data structure. A local, unprivileged user could use this
flaw to leak kernel stack memory to user space using the recvmsg, recvfrom,
and recvmmsg system calls. (CVE-2013-7263, Low)

* A flaw was found in the way the get_dumpable() function return value was
interpreted in the ptrace subsystem of the Linux kernel. When
'fs.suid_dumpable' was set to 2, a local, unprivileged local user could
use this flaw to bypass intended ptrace restrictions and obtain
potentially sensitive information. (CVE-2013-2929, Low)

Red Hat would like to thank Vladimir Davydov of Parallels for reporting
CVE-2013-4483 and the Xen project for reporting CVE-2013-4554 and
CVE-2013-6885. Upstream acknowledges Jan Beulich as the original reporter
of CVE-2013-4554 and CVE-2013-6885.

This update also fixes several bugs and adds one enhancement.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0285</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4554</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6381</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7263</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140285"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140292" severity="high">
    <xccdf:title>RHSA-2014:0292: 389-ds-base security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not properly handle
certain SASL-based authentication mechanisms. A user able to authenticate
to the directory using these SASL mechanisms could connect as any other
directory user, including the administrative Directory Manager account.
This could allow them to modify configuration values, as well as read and
write any data the directory holds. (CVE-2014-0132)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0132</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140292"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140293" severity="high">
    <xccdf:title>RHSA-2014:0293: udisks security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The udisks package provides a daemon, a D-Bus API, and command line
utilities for managing disks and storage devices.

A stack-based buffer overflow flaw was found in the way udisks handled
files with long path names. A malicious, local user could use this flaw to
create a specially crafted directory structure that, when processed by the
udisks daemon, could lead to arbitrary code execution with the privileges
of the udisks daemon (root). (CVE-2014-0004)

This issue was discovered by Florian Weimer of the Red Hat Product
Security Team.

All udisks users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0004</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140293"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140304" severity="high">
    <xccdf:title>RHSA-2014:0304: mutt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mutt is a text-mode mail user agent.

A heap-based buffer overflow flaw was found in the way mutt processed
certain email headers. A remote attacker could use this flaw to send an
email with specially crafted headers that, when processed, could cause mutt
to crash or, potentially, execute arbitrary code with the permissions of
the user running mutt. (CVE-2014-0467)

All mutt users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running instances of
mutt must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0304</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0467</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140304"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140305" severity="medium">
    <xccdf:title>RHSA-2014:0305: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim's
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the Samba
server.

Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0305</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4124</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140305"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140310" severity="high">
    <xccdf:title>RHSA-2014:0310: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Firefox
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Firefox to crash. (CVE-2014-1497,
CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Firefox rendered certain PDF
files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Firefox or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0310</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1514</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140310"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140311" severity="high">
    <xccdf:title>RHSA-2014:0311: php security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the way PHP parsed floating point
numbers from their text representation. If a PHP application converted
untrusted input strings to numbers, an attacker able to provide such input
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the application. (CVE-2009-0689)

It was found that PHP did not properly handle file names with a NULL
character. A remote attacker could possibly use this flaw to make a PHP
script access unexpected files and bypass intended file system access
restrictions. (CVE-2006-7243)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0311</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2006-7243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2009-0689</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140311"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140316" severity="high">
    <xccdf:title>RHSA-2014:0316: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0316</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1514</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140316"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140321" severity="medium">
    <xccdf:title>RHSA-2014:0321: net-snmp security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

A buffer overflow flaw was found in the way the decode_icmp_msg() function
in the ICMP-MIB implementation processed Internet Control Message Protocol
(ICMP) message statistics reported in the /proc/net/snmp file. A remote
attacker could send a message for each ICMP message type, which could
potentially cause the snmpd service to crash when processing the
/proc/net/snmp file. (CVE-2014-2284)

This update also fixes the following bug:

* The snmpd service parses the /proc/diskstats file to track disk usage
statistics for UCD-DISKIO-MIB::diskIOTable. On systems with a large number
of block devices, /proc/diskstats may be large in size and parsing it can
take a non-trivial amount of CPU time. With this update, Net-SNMP
introduces a new option, 'diskio', in the /etc/snmp/snmpd.conf file, which
can be used to explicitly specify devices that should be monitored.
Only these whitelisted devices are then reported in
UCD-DISKIO-MIB::diskIOTable, thus speeding up snmpd on systems with
numerous block devices. (BZ#990674)

All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the snmpd service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2284</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140321"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140322" severity="medium">
    <xccdf:title>RHSA-2014:0322: net-snmp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

A denial of service flaw was found in the way snmpd, the Net-SNMP daemon,
handled subagent timeouts. A remote attacker able to trigger a subagent
timeout could use this flaw to cause snmpd to loop infinitely or crash.
(CVE-2012-6151)

A denial of service flaw was found in the way the snmptrapd service, which
receives and logs SNMP trap messages, handled SNMP trap requests with an
empty community string when the Perl handler (provided by the net-snmp-perl
package) was enabled. A remote attacker could use this flaw to crash
snmptrapd by sending a trap request with an empty community string.
(CVE-2014-2285)

All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the snmpd and snmptrapd services will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2285</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140322"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140328" severity="high">
    <xccdf:title>RHSA-2014:0328: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the get_rx_bufs() function in the vhost_net
implementation in the Linux kernel handled error conditions reported by the
vhost_get_vq_desc() function. A privileged guest user could use this flaw
to crash the host. (CVE-2014-0055, Important)

* A flaw was found in the way the Linux kernel processed an authenticated
COOKIE_ECHO chunk during the initialization of an SCTP connection. A remote
attacker could use this flaw to crash the system by initiating a specially
crafted SCTP handshake in order to trigger a NULL pointer dereference on
the system. (CVE-2014-0101, Important)

* A flaw was found in the way the Linux kernel's CIFS implementation
handled uncached write operations with specially crafted iovec structures.
An unprivileged local user with access to a CIFS share could use this flaw
to crash the system, leak kernel memory, or, potentially, escalate their
privileges on the system. Note: the default cache settings for CIFS mounts
on Red Hat Enterprise Linux 6 prohibit a successful exploitation of this
issue. (CVE-2014-0069, Moderate)

* A heap-based buffer overflow flaw was found in the Linux kernel's cdc-wdm
driver, used for USB CDC WCM device management. An attacker with physical
access to a system could use this flaw to cause a denial of service or,
potentially, escalate their privileges. (CVE-2013-1860, Low)

Red Hat would like to thank Nokia Siemens Networks for reporting
CVE-2014-0101, and Al Viro for reporting CVE-2014-0069.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0328</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2038</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140328"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140330" severity="medium">
    <xccdf:title>RHSA-2014:0330: samba and samba3x security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)

A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)

Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and Sam Richardson for reporting CVE-2012-6150. Upstream acknowledges
Andrew Bartlett as the original reporter of CVE-2013-4496.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4496</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140330"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140341" severity="medium">
    <xccdf:title>RHSA-2014:0341: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2013-3559, CVE-2013-4083, CVE-2014-2281, CVE-2014-2299)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2012-5595, CVE-2012-5598, CVE-2012-5599,
CVE-2012-5600, CVE-2012-6056, CVE-2012-6060, CVE-2012-6061, CVE-2012-6062,
CVE-2013-3557, CVE-2013-4081, CVE-2013-4927, CVE-2013-4931, CVE-2013-4932,
CVE-2013-4933, CVE-2013-4934, CVE-2013-4935, CVE-2013-5721, CVE-2013-7112)

All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6060</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6061</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3557</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3559</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4927</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4931</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4932</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4933</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4934</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4935</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2299</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140341"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140342" severity="medium">
    <xccdf:title>RHSA-2014:0342: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Two flaws were found in Wireshark. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2014-2281,
CVE-2014-2299)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2013-6336, CVE-2013-6337, CVE-2013-6338,
CVE-2013-6339, CVE-2013-6340, CVE-2014-2283, CVE-2013-7112, CVE-2013-7114)

All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6336</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6338</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6340</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7112</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7114</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2299</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140342"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140348" severity="high">
    <xccdf:title>RHSA-2014:0348: xalan-j2 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)

All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0107</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140348"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140369" severity="medium">
    <xccdf:title>RHSA-2014:0369: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
"apache" user. (CVE-2013-6438)

A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0369</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0098</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140369"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140370" severity="medium">
    <xccdf:title>RHSA-2014:0370: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
"apache" user. (CVE-2013-6438)

A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0098</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140370"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140376" severity="high">
    <xccdf:title>RHSA-2014:0376: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Neel Mehta of Google Security as the original
reporter.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0160</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140376"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140383" severity="medium">
    <xccdf:title>RHSA-2014:0383: samba4 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)

A flaw was found in Samba's "smbcacls" command, which is used to set or get
ACLs on SMB file shares. Certain command line options of this command would
incorrectly remove an ACL previously applied on a file or a directory,
leaving the file or directory without the intended ACL. (CVE-2013-6442)

A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)

Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and CVE-2013-6442, and Sam Richardson for reporting CVE-2012-6150.
Upstream acknowledges Andrew Bartlett as the original reporter of
CVE-2013-4496, and Noel Power as the original reporter of CVE-2013-6442.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6442</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140383"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140406" severity="high">
    <xccdf:title>RHSA-2014:0406: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140406"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140407" severity="high">
    <xccdf:title>RHSA-2014:0407: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140407"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140408" severity="high">
    <xccdf:title>RHSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

This update also fixes the following bug:

* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140408"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140413" severity="high">
    <xccdf:title>RHSA-2014:0413: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6629</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6954</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2428</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140413"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140414" severity="high">
    <xccdf:title>RHSA-2014:0414: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2437</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2444</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2445</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2450</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3743</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-3829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5772</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5774</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5776</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5780</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5782</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5784</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5804</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5814</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5817</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5818</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5819</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5820</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5823</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5824</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5829</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5832</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5849</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5850</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5852</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5878</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5887</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5888</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5896</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5898</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5899</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5905</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5910</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6629</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6954</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0368</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0373</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0375</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0376</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0387</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2428</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140414"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140420" severity="medium">
    <xccdf:title>RHSA-2014:0420: qemu-kvm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Multiple integer overflow, input validation, logic error, and buffer
overflow flaws were discovered in various QEMU block drivers. An attacker
able to modify a disk image file loaded by a guest could use these flaws to
crash the guest, or corrupt QEMU process memory on the host, potentially
resulting in arbitrary code execution on the host with the privileges of
the QEMU process. (CVE-2014-0143, CVE-2014-0144, CVE-2014-0145,
CVE-2014-0147)

A buffer overflow flaw was found in the way the virtio_net_handle_mac()
function of QEMU processed guest requests to update the table of MAC
addresses. A privileged guest user could use this flaw to corrupt QEMU
process memory on the host, potentially resulting in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0150)

A divide-by-zero flaw was found in the seek_to_sector() function of the
parallels block driver in QEMU. An attacker able to modify a disk image
file loaded by a guest could use this flaw to crash the guest.
(CVE-2014-0142)

A NULL pointer dereference flaw was found in the QCOW2 block driver in
QEMU. An attacker able to modify a disk image file loaded by a guest could
use this flaw to crash the guest. (CVE-2014-0146)

It was found that the block driver for Hyper-V VHDX images did not
correctly calculate BAT (Block Allocation Table) entries due to a missing
bounds check. An attacker able to modify a disk image file loaded by a
guest could use this flaw to crash the guest. (CVE-2014-0148)

The CVE-2014-0143 issues were discovered by Kevin Wolf and Stefan Hajnoczi
of Red Hat, the CVE-2014-0144 issues were discovered by Fam Zheng, Jeff
Cody, Kevin Wolf, and Stefan Hajnoczi of Red Hat, the CVE-2014-0145 issues
were discovered by Stefan Hajnoczi of Red Hat, the CVE-2014-0150 issue was
discovered by Michael S. Tsirkin of Red Hat, the CVE-2014-0142,
CVE-2014-0146, and CVE-2014-0147 issues were discovered by Kevin Wolf of
Red Hat, and the CVE-2014-0148 issue was discovered by Jeff Cody of
Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0150</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140420"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140429" severity="medium">
    <xccdf:title>RHSA-2014:0429: tomcat6 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that when Tomcat processed a series of HTTP requests in which
at least one request contained either multiple content-length headers, or
one content-length header with a chunked transfer-encoding header, Tomcat
would incorrectly handle the request. A remote attacker could use this flaw
to poison a web cache, perform cross-site scripting (XSS) attacks, or
obtain sensitive information from other requests. (CVE-2013-4286)

It was discovered that the fix for CVE-2012-3544 did not properly resolve a
denial of service flaw in the way Tomcat processed chunk extensions and
trailing headers in chunked requests. A remote attacker could use this flaw
to send an excessively long request that, when processed by Tomcat, could
consume network bandwidth, CPU, and memory on the Tomcat server. Note that
chunked transfer encoding is enabled by default. (CVE-2013-4322)

A denial of service flaw was found in the way Apache Commons FileUpload
handled small-sized buffers used by MultipartStream. A remote attacker
could use this flaw to create a malformed Content-Type header for a
multipart request, causing JBoss Web to enter an infinite loop when
processing such an incoming request. (CVE-2014-0050)

All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0050</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140429"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140433" severity="medium">
    <xccdf:title>RHSA-2014:0433: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled TCP packets with both the SYN and FIN flags set.
A remote attacker could use this flaw to consume an excessive amount of
resources on the target system, potentially resulting in a denial of
service. (CVE-2012-6638, Moderate)

* A flaw was found in the way the Linux kernel handled HID (Human Interface
Device) reports with an out-of-bounds Report ID. An attacker with physical
access to the system could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2013-2888,
Moderate)

This update also fixes the following bugs:

* A previous change to the sunrpc code introduced a race condition between
the rpc_wake_up_task() and rpc_wake_up_status() functions. A race between
threads operating on these functions could result in a deadlock situation,
subsequently triggering a "soft lockup" event and rendering the system
unresponsive. This problem has been fixed by re-ordering tasks in the RPC
wait queue. (BZ#1073731)

* Running a process in the background on a GFS2 file system could
sometimes trigger a glock recursion error that resulted in a kernel panic.
This happened when a readpage operation attempted to take a glock that had
already been held by another function. To prevent this error, GFS2 now
verifies whether the glock is already held when performing the readpage
operation. (BZ#1073953)

* A previous patch backport to the IUCV (Inter User Communication Vehicle)
code was incomplete. Consequently, when establishing an IUCV connection,
the kernel could, under certain circumstances, dereference a NULL pointer,
resulting in a kernel panic. A patch has been applied to correct this
problem by calling the proper function when removing IUCV paths.
(BZ#1077045)

In addition, this update adds the following enhancement:

* The lpfc driver had a fixed timeout of 60 seconds for SCSI task
management commands. With this update, the lpfc driver enables the user to
set this timeout within the range from 5 to 180 seconds. The timeout can
be changed by modifying the "lpfc_task_mgmt_tmo" parameter for the lpfc
driver. (BZ#1073123)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2888</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140433"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140448" severity="high">
    <xccdf:title>RHSA-2014:0448: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)

A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1523</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1524</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1532</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140448"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140449" severity="high">
    <xccdf:title>RHSA-2014:0449: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)

A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0449</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1518</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1523</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1524</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1532</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140449"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140474" severity="high">
    <xccdf:title>RHSA-2014:0474: struts security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Struts is a framework for building web applications with Java.

It was found that the Struts 1 ActionForm object allowed access to the
'class' parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)

All struts users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using struts must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0474</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0114</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140474"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140475" severity="high">
    <xccdf:title>RHSA-2014:0475: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's netfilter connection
tracking implementation for Datagram Congestion Control Protocol (DCCP)
packets used the skb_header_pointer() function. A remote attacker could use
this flaw to send a specially crafted DCCP packet to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-2523,
Important)

* A flaw was found in the way the Linux kernel's Adaptec RAID controller
(aacraid) checked permissions of compat IOCTLs. A local attacker could use
this flaw to bypass intended security restrictions. (CVE-2013-6383,
Moderate)

* A flaw was found in the way the handle_rx() function handled large
network packets when mergeable buffers were disabled. A privileged guest
user could use this flaw to crash the host or corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-0077, Moderate)

The CVE-2014-0077 issue was discovered by Michael S. Tsirkin of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0077</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2523</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140475"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140513" severity="medium">
    <xccdf:title>RHSA-2014:0513: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

It was discovered that libxml2 loaded external parameter entities even when
entity substitution was disabled. A remote attacker able to provide a
specially crafted XML file to an application linked against libxml2 could
use this flaw to conduct XML External Entity (XXE) attacks, possibly
resulting in a denial of service or an information leak on the system.
(CVE-2014-0191)

An out-of-bounds read flaw was found in the way libxml2 detected the end of
an XML file. A remote attacker could provide a specially crafted XML file
that, when processed by an application linked against libxml2, could cause
the application to crash. (CVE-2013-2877)

The CVE-2014-0191 issue was discovered by Daniel P. Berrange of Red Hat.

All libxml2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2877</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0191</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140513"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140536" severity="medium">
    <xccdf:title>RHSA-2014:0536: mysql55-mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2436,
CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431,
CVE-2014-2432, CVE-2014-2438)

These updated packages upgrade MySQL to version 5.5.37. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2438</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140536"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140560" severity="medium">
    <xccdf:title>RHSA-2014:0560: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In 
addition, libvirt provides tools for remote management of virtualized
systems. 

It was found that libvirt passes the XML_PARSE_NOENT flag when parsing XML
documents using the libxml2 library, in which case all XML entities in the
parsed documents are expanded. A user able to force libvirtd to parse an
XML document with an entity pointing to a special file that blocks on read
access could use this flaw to cause libvirtd to hang indefinitely,
resulting in a denial of service on the system. (CVE-2014-0179)

Red Hat would like to thank the upstream Libvirt project for reporting this
issue. Upstream acknowledges Daniel P. Berrange and Richard Jones as the
original reporters.

This update also fixes the following bugs:

* When hot unplugging a virtual CPU (vCPU), libvirt kept a pointer to
already freed memory if the vCPU was pinned to a host CPU. Consequently,
when reading the CPU pinning information, libvirt terminated unexpectedly
due to an attempt to access this memory. This update ensures that libvirt
releases the pointer to the previously allocated memory when a vCPU is
being hot unplugged, and it no longer crashes in this situation.
(BZ#1091206)

* Previously, libvirt passed an incorrect argument to the "tc" command when
setting quality of service (QoS) on a network interface controller (NIC).
As a consequence, QoS was applied only to IP traffic. With this update,
libvirt constructs the "tc" command correctly so that QoS is applied to all
traffic as expected. (BZ#1096806)

* When using the sanlock daemon for managing access to shared storage,
libvirt expected all QEMU domains to be registered with sanlock. However,
if a QEMU domain was started prior to enabling sanlock, the domain was not
registered with sanlock. Consequently, migration of a virtual machine (VM)
from such a QEMU domain failed with a libvirt error. With this update,
libvirt verifies whether a QEMU domain process is registered with sanlock
before it starts working with the domain, ensuring that migration of
virtual machines works as expected. (BZ#1097227)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0560</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0179</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140560"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140561" severity="medium">
    <xccdf:title>RHSA-2014:0561: curl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

It was found that libcurl could incorrectly reuse existing connections for
requests that should have used different or no authentication credentials,
when using one of the following protocols: HTTP(S) with NTLM
authentication, LDAP(S), SCP, or SFTP. If an application using the libcurl
library connected to a remote server with certain authentication
credentials, this flaw could cause other requests to use those same
credentials. (CVE-2014-0015, CVE-2014-0138)

Red Hat would like to thank the cURL project for reporting these issues.
Upstream acknowledges Paras Sethia as the original reporter of
CVE-2014-0015 and Yehezkel Horowitz for discovering the security impact of
this issue, and Steve Holme as the original reporter of CVE-2014-0138.

This update also fixes the following bugs:

* Previously, the libcurl library was closing a network socket without
first terminating the SSL connection using the socket. This resulted in a
write after close and consequent leakage of memory dynamically allocated by
the SSL library. An upstream patch has been applied on libcurl to fix this
bug. As a result, the write after close no longer happens, and the SSL
library no longer leaks memory. (BZ#1092479)

* Previously, the libcurl library did not implement a non-blocking SSL
handshake, which negatively affected performance of applications based on
libcurl's multi API. To fix this bug, the non-blocking SSL handshake has
been implemented by libcurl. With this update, libcurl's multi API
immediately returns the control back to the application whenever it cannot
read/write data from/to the underlying network socket. (BZ#1092480)

* Previously, the curl package could not be rebuilt from sources due to an
expired cookie in the upstream test-suite, which runs during the build. An
upstream patch has been applied to postpone the expiration date of the
cookie, which makes it possible to rebuild the package from sources again.
(BZ#1092486)

* Previously, the libcurl library attempted to authenticate using Kerberos
whenever such an authentication method was offered by the server. This
caused problems when the server offered multiple authentication methods and
Kerberos was not the selected one. An upstream patch has been applied on
libcurl to fix this bug. Now libcurl no longer uses Kerberos authentication
if another authentication method is selected. (BZ#1096797)

All curl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications that use libcurl have to be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0015</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0138</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140561"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140594" severity="high">
    <xccdf:title>RHSA-2014:0594: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). The gnutls packages also
include the libtasn1 library, which provides Abstract Syntax Notation One
(ASN.1) parsing and structures management, and Distinguished Encoding Rules
(DER) encoding and decoding functions.

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

Red Hat would like to thank GnuTLS upstream for reporting these issues.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter of CVE-2014-3466.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS or libtasn1 library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0594</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3469</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140594"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140595" severity="high">
    <xccdf:title>RHSA-2014:0595: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3466</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140595"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140596" severity="medium">
    <xccdf:title>RHSA-2014:0596: libtasn1 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtasn1 library provides Abstract Syntax Notation One (ASN.1) parsing
and structures management, and Distinguished Encoding Rules (DER) encoding
and decoding functions.

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

Red Hat would like to thank GnuTLS upstream for reporting these issues.

All libtasn1 users are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the libtasn1 library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3469</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140596"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140597" severity="medium">
    <xccdf:title>RHSA-2014:0597: squid security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A denial of service flaw was found in the way Squid processed certain HTTPS
requests when the SSL Bump feature was enabled. A remote attacker could
send specially crafted requests that could cause Squid to crash.
(CVE-2014-0128)

Red Hat would like to thank the Squid project for reporting this issue.
Upstream acknowledges Mathias Fischer and Fabian Hugelshofer from Open
Systems AG as the original reporters.

All squid users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the squid service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0128</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140597"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140624" severity="high">
    <xccdf:title>RHSA-2014:0624: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0624</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140624"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140625" severity="high">
    <xccdf:title>RHSA-2014:0625: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

A buffer overflow flaw was found in the way OpenSSL handled invalid DTLS
packet fragments. A remote attacker could possibly use this flaw to execute
arbitrary code on a DTLS client or server. (CVE-2014-0195)

Multiple flaws were found in the way OpenSSL handled read and write buffers
when the SSL_MODE_RELEASE_BUFFERS mode was enabled. A TLS/SSL client or
server using OpenSSL could crash or unexpectedly drop connections when
processing certain SSL traffic. (CVE-2010-5298, CVE-2014-0198)

A denial of service flaw was found in the way OpenSSL handled certain DTLS
ServerHello requests. A specially crafted DTLS handshake packet could cause
a DTLS client using OpenSSL to crash. (CVE-2014-0221)

A NULL pointer dereference flaw was found in the way OpenSSL performed
anonymous Elliptic Curve Diffie Hellman (ECDH) key exchange. A specially
crafted handshake packet could cause a TLS/SSL client that has the
anonymous ECDH cipher suite enabled to crash. (CVE-2014-3470)

Red Hat would like to thank the OpenSSL project for reporting these issues.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of CVE-2014-0224, Jüri Aedla as the original reporter of CVE-2014-0195,
Imre Rad of Search-Lab as the original reporter of CVE-2014-0221, and Felix
Gröbert and Ivan Fratrić of Google as the original reporters of
CVE-2014-3470.

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3470</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140625"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140626" severity="high">
    <xccdf:title>RHSA-2014:0626: openssl097a and openssl098e security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0626</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140626"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140675" severity="high">
    <xccdf:title>RHSA-2014:0675: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0454</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140675"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140678" severity="high">
    <xccdf:title>RHSA-2014:0678: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A race condition flaw, leading to heap-based buffer overflows, was found
in the way the Linux kernel's N_TTY line discipline (LDISC) implementation
handled concurrent processing of echo output and TTY write operations
originating from user space when the underlying TTY driver was PTY.
An unprivileged, local user could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-0196,
Important)

All kernel users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0196</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140678"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140679" severity="high">
    <xccdf:title>RHSA-2014:0679: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

A buffer overflow flaw was found in the way OpenSSL handled invalid DTLS
packet fragments. A remote attacker could possibly use this flaw to execute
arbitrary code on a DTLS client or server. (CVE-2014-0195)

Multiple flaws were found in the way OpenSSL handled read and write buffers
when the SSL_MODE_RELEASE_BUFFERS mode was enabled. A TLS/SSL client or
server using OpenSSL could crash or unexpectedly drop connections when
processing certain SSL traffic. (CVE-2010-5298, CVE-2014-0198)

A denial of service flaw was found in the way OpenSSL handled certain DTLS
ServerHello requests. A specially crafted DTLS handshake packet could cause
a DTLS client using OpenSSL to crash. (CVE-2014-0221)

A NULL pointer dereference flaw was found in the way OpenSSL performed
anonymous Elliptic Curve Diffie Hellman (ECDH) key exchange. A specially
crafted handshake packet could cause a TLS/SSL client that has the
anonymous ECDH cipher suite enabled to crash. (CVE-2014-3470)

Red Hat would like to thank the OpenSSL project for reporting these issues.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of CVE-2014-0224, Jüri Aedla as the original reporter of CVE-2014-0195,
Imre Rad of Search-Lab as the original reporter of CVE-2014-0221, and Felix
Gröbert and Ivan Fratrić of Google as the original reporters of
CVE-2014-3470.

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0224</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3470</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140679"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140680" severity="high">
    <xccdf:title>RHSA-2014:0680: openssl098e security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0680</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0224</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140680"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140684" severity="high">
    <xccdf:title>RHSA-2014:0684: gnutls security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

A NULL pointer dereference flaw was found in the way GnuTLS parsed X.509
certificates. A specially crafted certificate could cause a server or
client application using GnuTLS to crash. (CVE-2014-3465)

Red Hat would like to thank GnuTLS upstream for reporting these issues.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter of CVE-2014-3466.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0684</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3465</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3466</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140684"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140685" severity="high">
    <xccdf:title>RHSA-2014:0685: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0685</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0446</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0451</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0452</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0453</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0461</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1876</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2398</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2427</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140685"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140686" severity="high">
    <xccdf:title>RHSA-2014:0686: tomcat security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that a fix for a previous security flaw introduced a
regression that could cause a denial of service in Tomcat 7. A remote
attacker could use this flaw to consume an excessive amount of CPU on the
Tomcat server by sending a specially crafted request to that server.
(CVE-2014-0186)

It was found that when Tomcat 7 processed a series of HTTP requests in
which at least one request contained either multiple content-length
headers, or one content-length header with a chunked transfer-encoding
header, Tomcat would incorrectly handle the request. A remote attacker
could use this flaw to poison a web cache, perform cross-site scripting
(XSS) attacks, or obtain sensitive information from other requests.
(CVE-2013-4286)

It was discovered that the fix for CVE-2012-3544 did not properly resolve a
denial of service flaw in the way Tomcat 7 processed chunk extensions and
trailing headers in chunked requests. A remote attacker could use this flaw
to send an excessively long request that, when processed by Tomcat, could
consume network bandwidth, CPU, and memory on the Tomcat server. Note that
chunked transfer encoding is enabled by default. (CVE-2013-4322)

All Tomcat 7 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0686</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4322</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0186</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140686"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140687" severity="medium">
    <xccdf:title>RHSA-2014:0687: libtasn1 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libtasn1 library provides Abstract Syntax Notation One (ASN.1) parsing
and structures management, and Distinguished Encoding Rules (DER) encoding
and decoding functions.

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

Red Hat would like to thank GnuTLS upstream for reporting these issues.

All libtasn1 users are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the libtasn1 library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3467</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3469</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140687"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140702" severity="medium">
    <xccdf:title>RHSA-2014:0702: mariadb security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MariaDB is a multi-user, multi-threaded SQL database server that is binary
compatible with MySQL.

This update fixes several vulnerabilities in the MariaDB database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2436,
CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431,
CVE-2014-2432, CVE-2014-2438)

These updated packages upgrade MariaDB to version 5.5.37. Refer to the
MariaDB Release Notes listed in the References section for a complete list
of changes.

All MariaDB users should upgrade to these updated packages, which correct
these issues. After installing this update, the MariaDB server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0702</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2438</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2019-2481</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140702"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140703" severity="medium">
    <xccdf:title>RHSA-2014:0703: json-c security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>JSON-C implements a reference counting object model that allows you to
easily construct JSON objects in C, output them as JSON-formatted strings,
and parse JSON-formatted strings back into the C representation of
JSON objects.

Multiple buffer overflow flaws were found in the way the json-c library
handled long strings in JSON documents. An attacker able to make an
application using json-c parse excessively large JSON input could cause the
application to crash. (CVE-2013-6370)

A denial of service flaw was found in the implementation of hash arrays in
json-c. An attacker could use this flaw to make an application using json-c
consume an excessive amount of CPU time by providing a specially crafted
JSON document that triggers multiple hash function collisions. To mitigate
this issue, json-c now uses a different hash function and randomization to
reduce the chance of an attacker successfully causing intentional
collisions. (CVE-2013-6371)

These issues were discovered by Florian Weimer of the Red Hat Product
Security Team.

All json-c users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6370</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6371</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140703"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140704" severity="medium">
    <xccdf:title>RHSA-2014:0704: qemu-kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm packages provide a
user-space component to run virtual machines using KVM.

An out-of-bounds memory access flaw was found in the way QEMU's IDE device
driver handled the execution of SMART EXECUTE OFFLINE commands.
A privileged guest user could use this flaw to corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-2894)

This update also fixes the following bugs:

* Prior to this update, a bug in the migration code caused the following
error on specific machine types: after a Red Hat Enterprise Linux 6.5 guest
was migrated from a Red Hat Enterprise Linux 6.5 host to a Red Hat
Enterprise Linux 7.0 host and then restarted, the boot failed and the guest
automatically restarted. Thus, the guest entered an endless loop. With this
update, the migration code has been fixed and the Red Hat Enterprise Linux
6.5 guests migrated in the aforementioned scenario now boot properly.
(BZ#1091322)

* Due to a regression bug in the iSCSI driver, the qemu-kvm process
terminated unexpectedly with a segmentation fault when the "write same"
command was executed in guest mode under the iSCSI protocol. This update
fixes the regression and the "write same" command now functions in guest
mode under iSCSI as intended. (BZ#1090978)

* Due to a mismatch in interrupt request (IRQ) routing, migration of a Red
Hat Enterprise Linux 6.5 guest from a Red Hat Enterprise Linux 6.5 host to
a Red Hat Enterprise Linux 7.0 host could produce a call trace.
This happened if memory ballooning and a Universal Host Control Interface
(UHCI) device were used at the same time on certain machine types.
With this patch, the IRQ routing mismatch has been amended and the
described migration now proceeds as expected. (BZ#1090981)

* Previously, an internal error prevented KVM from executing a CPU hot plug
on a Red Hat Enterprise Linux 7 guest running on a Red Hat Enterprise Linux
7 host. This update addresses the internal error and CPU hot plugging in
the described scenario now functions correctly. (BZ#1094820)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0704</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2894</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140704"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140740" severity="high">
    <xccdf:title>RHSA-2014:0740: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's floppy driver handled user
space provided data in certain error code paths while processing FDRAWCMD
IOCTL commands. A local user with write access to /dev/fdX could use this
flaw to free (using the kfree() function) arbitrary kernel memory.
(CVE-2014-1737, Important)

* It was found that the Linux kernel's floppy driver leaked internal kernel
memory addresses to user space during the processing of the FDRAWCMD IOCTL
command. A local user with write access to /dev/fdX could use this flaw to
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)

Note: A local user with write access to /dev/fdX could use these two flaws
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their
privileges on the system.

* A NULL pointer dereference flaw was found in the rds_ib_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2013-7339, Moderate)

Red Hat would like to thank Matthew Daley for reporting CVE-2014-1737 and
CVE-2014-1738.

This update also fixes the following bugs:

* A bug in the futex system call could result in an overflow when passing
a very large positive timeout. As a consequence, the FUTEX_WAIT operation
did not work as intended and the system call was timing out immediately.
A backported patch fixes this bug by limiting very large positive timeouts
to the maximal supported value. (BZ#1091832)

* A new Linux Security Module (LSM) functionality related to the setrlimit
hooks should produce a warning message when used by a third party module
that could not cope with it. However, due to a programming error, the
kernel could print this warning message when a process was setting rlimits
for a different process, or if rlimits were modified by another than the
main thread even though there was no incompatible third party module. This
update fixes the relevant code and ensures that the kernel handles this
warning message correctly. (BZ#1092869)

* Previously, the kernel was unable to detect KVM on system boot if the
Hyper-V emulation was enabled. A patch has been applied to ensure that
both KVM and Hyper-V hypervisors are now correctly detected during system
boot. (BZ#1094152)

* A function in the RPC code responsible for verifying whether cached
credentials match the current process did not perform the check correctly.
The code checked only whether the groups in the current process
credentials appear in the same order as in the cached credentials but did
not ensure that no other groups are present in the cached credentials. As
a consequence, when accessing files in NFS mounts, a process with the same
UID and GID as the original process but with a non-matching group list
could have been granted an unauthorized access to a file, or under certain
circumstances, the process could have been wrongly prevented from
accessing the file. The incorrect test condition has been fixed and the
problem can no longer occur. (BZ#1095062)

* When being under heavy load, some Fibre Channel storage devices, such as
Hitachi and HP Open-V series, can send a logout (LOGO) message to the
host system. However, due to a bug in the lpfc driver, this could result
in a loss of active paths to the storage and the paths could not be
recovered without manual intervention. This update corrects the lpfc
driver to ensure automatic recovery of the lost paths to the storage in
this scenario. (BZ#1096061)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1738</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140740"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140741" severity="high">
    <xccdf:title>RHSA-2014:0741: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1541</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140741"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140742" severity="high">
    <xccdf:title>RHSA-2014:0742: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1533</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1541</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140742"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140743" severity="medium">
    <xccdf:title>RHSA-2014:0743: qemu-kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Multiple buffer overflow, input validation, and out-of-bounds write flaws
were found in the way the virtio, virtio-net, virtio-scsi, and usb drivers
of QEMU handled state loading after migration. A user able to alter the
savevm data (either on the disk or over the wire during migration) could
use either of these flaws to corrupt QEMU process memory on the
(destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536, CVE-2013-4541,
CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, CVE-2014-3461)

An out-of-bounds memory access flaw was found in the way QEMU's IDE device
driver handled the execution of SMART EXECUTE OFFLINE commands.
A privileged guest user could use this flaw to corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-2894)

The CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536,
CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, and
CVE-2014-3461 issues were discovered by Michael S. Tsirkin of Red Hat,
Anthony Liguori, and Michael Roth.

This update also fixes the following bugs:

* Previously, under certain circumstances, libvirt failed to start guests
which used a non-zero PCI domain and SR-IOV Virtual Functions (VFs), and
returned the following error message:

Can't assign device inside non-zero PCI segment as this KVM module doesn't
support it.

This update fixes this issue and guests using the aforementioned
configuration no longer fail to start. (BZ#1099941)

* Due to an incorrect initialization of the cpus_sts bitmap, which holds
the enablement status of a vCPU, libvirt could fail to start a guest with
an unusual vCPU topology (for example, a guest with three cores and two
sockets). With this update, the initialization of cpus_sts has been
corrected, and libvirt no longer fails to start the aforementioned guests.
(BZ#1100575)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0743</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6399</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2894</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3461</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140743"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140747" severity="medium">
    <xccdf:title>RHSA-2014:0747: python-jinja2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Jinja2 is a template engine written in pure Python. It provides a
Django-inspired, non-XML syntax but supports inline expressions and an
optional sandboxed environment.

It was discovered that Jinja2 did not properly handle bytecode cache files
stored in the system's temporary directory. A local attacker could use this
flaw to alter the output of an application using Jinja2 and
FileSystemBytecodeCache, and potentially execute arbitrary code with the
privileges of that application. (CVE-2014-1402)

All python-jinja2 users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. For the update to
take effect, all applications using python-jinja2 must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0747</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1402</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140747"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140771" severity="high">
    <xccdf:title>RHSA-2014:0771: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's futex subsystem handled
the requeuing of certain Priority Inheritance (PI) futexes. A local,
unprivileged user could use this flaw to escalate their privileges on the
system. (CVE-2014-3153, Important)

* A flaw was found in the way the Linux kernel's floppy driver handled user
space provided data in certain error code paths while processing FDRAWCMD
IOCTL commands. A local user with write access to /dev/fdX could use this
flaw to free (using the kfree() function) arbitrary kernel memory.
(CVE-2014-1737, Important)

* It was found that the Linux kernel's floppy driver leaked internal kernel
memory addresses to user space during the processing of the FDRAWCMD IOCTL
command. A local user with write access to /dev/fdX could use this flaw to
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)

Note: A local user with write access to /dev/fdX could use these two flaws
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their
privileges on the system.

* It was discovered that the proc_ns_follow_link() function did not
properly return the LAST_BIND value in the last pathname component as is
expected for procfs symbolic links, which could lead to excessive freeing
of memory and consequent slab corruption. A local, unprivileged user could
use this flaw to crash the system. (CVE-2014-0203, Moderate)

* A flaw was found in the way the Linux kernel handled exceptions when
user-space applications attempted to use the linkage stack. On IBM S/390
systems, a local, unprivileged user could use this flaw to crash the
system. (CVE-2014-2039, Moderate)

* An invalid pointer dereference flaw was found in the Marvell 8xxx
Libertas WLAN (libertas) driver in the Linux kernel. A local user able to
write to a file that is provided by the libertas driver and located on the
debug file system (debugfs) could use this flaw to crash the system. Note:
The debugfs file system must be mounted locally to exploit this issue.
It is not mounted by default. (CVE-2013-6378, Low)

* A denial of service flaw was discovered in the way the Linux kernel's
SELinux implementation handled files with an empty SELinux security
context. A local user who has the CAP_MAC_ADMIN capability could use this
flaw to crash the system. (CVE-2014-1874, Low)

Red Hat would like to thank Kees Cook of Google for reporting
CVE-2014-3153, Matthew Daley for reporting CVE-2014-1737 and CVE-2014-1738,
and Vladimir Davydov of Parallels for reporting CVE-2014-0203. Google
acknowledges Pinkie Pie as the original reporter of CVE-2014-3153.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0203</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1874</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2039</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3153</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140771"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140786" severity="high">
    <xccdf:title>RHSA-2014:0786: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's futex subsystem handled
the requeuing of certain Priority Inheritance (PI) futexes. A local,
unprivileged user could use this flaw to escalate their privileges on the
system. (CVE-2014-3153, Important)

* A use-after-free flaw was found in the way the ping_init_sock() function
of the Linux kernel handled the group_info reference counter. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2014-2851, Important)

* Use-after-free and information leak flaws were found in the way the
Linux kernel's floppy driver processed the FDRAWCMD IOCTL command. A local
user with write access to /dev/fdX could use these flaws to escalate their
privileges on the system. (CVE-2014-1737, CVE-2014-1738, Important)

* It was found that the aio_read_events_ring() function of the Linux
kernel's Asynchronous I/O (AIO) subsystem did not properly sanitize the AIO
ring head received from user space. A local, unprivileged user could use
this flaw to disclose random parts of the (physical) memory belonging to
the kernel and/or other processes. (CVE-2014-0206, Moderate)

* An out-of-bounds memory access flaw was found in the Netlink Attribute
extension of the Berkeley Packet Filter (BPF) interpreter functionality in
the Linux kernel's networking implementation. A local, unprivileged user
could use this flaw to crash the system or leak kernel memory to user space
via a specially crafted socket filter. (CVE-2014-3144, CVE-2014-3145,
Moderate)

* An information leak flaw was found in the way the skb_zerocopy() function
copied socket buffers (skb) that are backed by user-space buffers (for
example vhost-net and Xen netback), potentially allowing an attacker to
read data from those buffers. (CVE-2014-2568, Low)

Red Hat would like to thank Kees Cook of Google for reporting
CVE-2014-3153 and Matthew Daley for reporting CVE-2014-1737 and CVE-2014-1738. Google acknowledges Pinkie Pie as the original reporter of
CVE-2014-3153. The CVE-2014-0206 issue was discovered by Mateusz Guzik of
Red Hat.

This update also fixes the following bugs:

* Due to incorrect calculation of Tx statistics in the qlcninc driver,
running the "ethtool -S ethX" command could trigger memory corruption.
As a consequence, running the sosreport tool, that uses this command,
resulted in a kernel panic. The problem has been fixed by correcting the
said statistics calculation. (BZ#1104972)

* When an attempt to create a file on the GFS2 file system failed due to a
file system quota violation, the relevant VFS inode was not completely
uninitialized. This could result in a list corruption error. This update
resolves this problem by correctly uninitializing the VFS inode in this
situation. (BZ#1097407)

* Due to a race condition in the kernel, the getcwd() system call could
return "/" instead of the correct full path name when querying a path name
of a file or directory. Paths returned in the "/proc" file system could
also be incorrect. This problem was causing instability of various
applications. The aforementioned race condition has been fixed and getcwd()
now always returns the correct paths. (BZ#1099048)

In addition, this update adds the following enhancements:

* The kernel mutex code has been improved. The changes include improved
queuing of the MCS spin locks, the MCS code optimization, introduction of
the cancellable MCS spin locks, and improved handling of mutexes without
wait locks. (BZ#1103631, BZ#1103629)

* The handling of the Virtual Memory Area (VMA) cache and huge page faults
has been improved. (BZ#1103630)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0786</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0206</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2851</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3153</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140786"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140788" severity="high">
    <xccdf:title>RHSA-2014:0788: mod_wsgi security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_wsgi adapter is an Apache module that provides a WSGI-compliant
interface for hosting Python-based web applications within Apache.

It was found that mod_wsgi did not properly drop privileges if the call to
setuid() failed. If mod_wsgi was set up to allow unprivileged users to run
WSGI applications, a local user able to run a WSGI application could
possibly use this flaw to escalate their privileges on the system.
(CVE-2014-0240)

Note: mod_wsgi is not intended to provide privilege separation for WSGI
applications. Systems relying on mod_wsgi to limit or sandbox the
privileges of mod_wsgi applications should migrate to a different solution
with proper privilege separation.

It was discovered that mod_wsgi could leak memory of a hosted web
application via the "Content-Type" header. A remote attacker could possibly
use this flaw to disclose limited portions of the web application's memory.
(CVE-2014-0242)

Red Hat would like to thank Graham Dumpleton for reporting these issues.
Upstream acknowledges Róbert Kisteleki as the original reporter of
CVE-2014-0240, and Buck Golemon as the original reporter of CVE-2014-0242.

All mod_wsgi users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0240</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0242</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140788"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140790" severity="medium">
    <xccdf:title>RHSA-2014:0790: dovecot security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Dovecot is an IMAP server, written with security primarily in mind, for
Linux and other UNIX-like systems. It also contains a small POP3 server.
It supports mail in both the maildir or mbox format. The SQL drivers and
authentication plug-ins are provided as subpackages.

It was discovered that Dovecot did not properly discard connections trapped
in the SSL/TLS handshake phase. A remote attacker could use this flaw to
cause a denial of service on an IMAP/POP3 server by exhausting the pool of
available connections and preventing further, legitimate connections to the
IMAP/POP3 server to be made. (CVE-2014-3430)

All dovecot users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the dovecot service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3430</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140790"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140827" severity="medium">
    <xccdf:title>RHSA-2014:0827: tomcat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that Apache Tomcat did not limit the length of chunk
sizes when using chunked transfer encoding. A remote attacker could use
this flaw to perform a denial of service attack against Tomcat by streaming
an unlimited quantity of data, leading to excessive consumption of server
resources. (CVE-2014-0075)

It was found that Apache Tomcat did not check for overflowing values when
parsing request content length headers. A remote attacker could use this
flaw to perform an HTTP request smuggling attack on a Tomcat server located
behind a reverse proxy that processed the content length header correctly.
(CVE-2014-0099)

It was found that the org.apache.catalina.servlets.DefaultServlet
implementation in Apache Tomcat allowed the definition of XML External
Entities (XXEs) in provided XSLTs. A malicious application could use this
to circumvent intended security restrictions to disclose sensitive
information. (CVE-2014-0096)

The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product
Security.

All Tomcat 7 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0099</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140827"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140861" severity="medium">
    <xccdf:title>RHSA-2014:0861: lzo security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LZO is a portable lossless data compression library written in ANSI C.

An integer overflow flaw was found in the way the lzo library decompressed
certain archives compressed with the LZO algorithm. An attacker could
create a specially crafted LZO-compressed input that, when decompressed by
an application using the lzo library, would cause that application to crash
or, potentially, execute arbitrary code. (CVE-2014-4607)

Red Hat would like to thank Don A. Bailey from Lab Mouse Security for
reporting this issue.

All lzo users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the lzo library must be restarted or the
system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4607</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140861"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140865" severity="medium">
    <xccdf:title>RHSA-2014:0865: tomcat6 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that Apache Tomcat did not limit the length of chunk
sizes when using chunked transfer encoding. A remote attacker could use
this flaw to perform a denial of service attack against Tomcat by streaming
an unlimited quantity of data, leading to excessive consumption of server
resources. (CVE-2014-0075)

It was found that Apache Tomcat did not check for overflowing values when
parsing request content length headers. A remote attacker could use this
flaw to perform an HTTP request smuggling attack on a Tomcat server located
behind a reverse proxy that processed the content length header correctly.
(CVE-2014-0099)

It was found that the org.apache.catalina.servlets.DefaultServlet
implementation in Apache Tomcat allowed the definition of XML External
Entities (XXEs) in provided XSLTs. A malicious application could use this
to circumvent intended security restrictions to disclose sensitive
information. (CVE-2014-0096)

The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product
Security.

This update also fixes the following bugs:

* The patch that resolved the CVE-2014-0050 issue contained redundant code.
This update removes the redundant code. (BZ#1094528)

* The patch that resolved the CVE-2013-4322 issue contained an invalid
check that triggered a java.io.EOFException while reading trailer headers
for chunked requests. This update fixes the check and the aforementioned
exception is no longer triggered in the described scenario. (BZ#1095602)

All Tomcat 6 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0865</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0099</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140865"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140866" severity="medium">
    <xccdf:title>RHSA-2014:0866: samba and samba3x security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493.
The Samba project acknowledges Simon Arlott as the original reporter of
CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0866</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140866"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140867" severity="medium">
    <xccdf:title>RHSA-2014:0867: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

A flaw was found in the way Samba created responses for certain
authenticated client requests when a shadow-copy VFS module was enabled.
An attacker able to send an authenticated request could use this flaw to
disclose limited portions of memory per each request. (CVE-2014-0178)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-0178
and CVE-2014-3493. The Samba project acknowledges Christof Schmitt as the
original reporter of CVE-2014-0178, and Simon Arlott as the original
reporter of CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140867"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140889" severity="high">
    <xccdf:title>RHSA-2014:0889: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140889"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140890" severity="high">
    <xccdf:title>RHSA-2014:0890: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140890"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140902" severity="high">
    <xccdf:title>RHSA-2014:0902: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4219, CVE-2014-2490, CVE-2014-4216, CVE-2014-4223, CVE-2014-4262,
CVE-2014-2483, CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266,
CVE-2014-4221, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227, CVE-2014-4265,
CVE-2014-4220, CVE-2014-4208, CVE-2014-4264)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 65 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4208</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4220</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4227</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4264</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4265</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140902"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140907" severity="high">
    <xccdf:title>RHSA-2014:0907: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

An improper permission check issue was discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
this flaw to bypass Java sandbox restrictions. (CVE-2014-4262)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

This update also fixes the following bug:

* Prior to this update, an application accessing an unsynchronized HashMap
could potentially enter an infinite loop and consume an excessive amount of
CPU resources. This update resolves this issue. (BZ#1115580)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0907</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4266</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140907"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140908" severity="high">
    <xccdf:title>RHSA-2014:0908: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch page, listed in the References section. (CVE-2014-4219,
CVE-2014-4216, CVE-2014-4262, CVE-2014-4209, CVE-2014-4218,
CVE-2014-4252, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227,
CVE-2014-4265)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 81 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4216</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4219</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4227</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4262</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4263</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4265</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140908"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140914" severity="medium">
    <xccdf:title>RHSA-2014:0914: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

It was found that libvirt passes the XML_PARSE_NOENT flag when parsing XML
documents using the libxml2 library, in which case all XML entities in the
parsed documents are expanded. A user able to force libvirtd to parse an
XML document with an entity pointing to a file could use this flaw to read
the contents of that file; parsing an XML document with an entity pointing
to a special file that blocks on read access could cause libvirtd to hang
indefinitely, resulting in a denial of service on the system.
(CVE-2014-0179)

Red Hat would like to thank the upstream Libvirt project for reporting this
issue. Upstream acknowledges Daniel P. Berrange and Richard Jones as the
original reporters.

This update also fixes the following bugs:

* A previous update of the libvirt package introduced an error; a
SIG_SETMASK argument was incorrectly replaced by a SIG_BLOCK argument after
the poll() system call. Consequently, the SIGCHLD signal could be
permanently blocked, which caused signal masks to not return to their
original values and defunct processes to be generated. With this update,
the original signal masks are restored and defunct processes are no longer
generated. (BZ#1112689)

* An attempt to start a domain that did not exist caused network filters to
be locked for read-only access. As a consequence, when trying to gain
read-write access, a deadlock occurred. This update applies a patch to fix
this bug and an attempt to start a non-existent domain no longer causes a
deadlock in the described scenario. (BZ#1112690)

* Previously, the libvirtd daemon was binding only to addresses that were
configured on certain network interfaces. When libvirtd started before the
IPv4 addresses had been configured, libvirtd listened only on the IPv6
addresses. The daemon has been modified to not require an address to be
configured when binding to a wildcard address, such as "0.0.0.0" or "::".
As a result, libvirtd binds to both IPv4 and IPv6 addresses as expected.
(BZ#1112692)

Users of libvirt are advised to upgrade to these updated packages, which
fix these bugs. After installing the updated packages, libvirtd will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0914</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0179</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5177</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140914"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140916" severity="high">
    <xccdf:title>RHSA-2014:0916: nss and nspr security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A race condition was found in the way NSS verified certain certificates.
A remote attacker could use this flaw to crash an application using NSS or,
possibly, execute arbitrary code with the privileges of the user running
that application. (CVE-2014-1544)

Red Hat would like to thank the Mozilla project for reporting
CVE-2014-1544. Upstream acknowledges Tyson Smith and Jesse Schwartzentruber
as the original reporters.

Users of NSS and NSPR are advised to upgrade to these updated packages,
which correct this issue. After installing this update, applications using
NSS or NSPR must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0916</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1544</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140916"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140917" severity="high">
    <xccdf:title>RHSA-2014:0917: nss and nspr security, bug fix, and enhancement update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A race condition was found in the way NSS verified certain certificates.
A remote attacker could use this flaw to crash an application using NSS or,
possibly, execute arbitrary code with the privileges of the user running
that application. (CVE-2014-1544)

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1544, CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues.
Upstream acknowledges Tyson Smith and Jesse Schwartzentruber as the
original reporters of CVE-2014-1544, Brian Smith as the original reporter
of CVE-2014-1490, Antoine Delignat-Lavaud and Karthikeyan Bhargavan as the
original reporters of CVE-2014-1491, and Abhishek Arya as the original
reporter of CVE-2014-1545.

In addition, the nss package has been upgraded to upstream version 3.16.1,
and the nspr package has been upgraded to upstream version 4.10.6. These
updated packages provide a number of bug fixes and enhancements over the
previous versions. (BZ#1112136, BZ#1112135)

Users of NSS and NSPR are advised to upgrade to these updated packages,
which correct these issues and add these enhancements. After installing
this update, applications using NSS or NSPR must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0917</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1544</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1545</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140917"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140918" severity="high">
    <xccdf:title>RHSA-2014:0918: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.7.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.7.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0918</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1557</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140918"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140919" severity="high">
    <xccdf:title>RHSA-2014:0919: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.7.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.7.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1547</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1556</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1557</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140919"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140920" severity="high">
    <xccdf:title>RHSA-2014:0920: httpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

A race condition flaw, leading to heap-based buffer overflows, was found in
the mod_status httpd module. A remote attacker able to access a status page
served by mod_status on a server using a threaded Multi-Processing Module
(MPM) could send a specially crafted request that would cause the httpd
child process to crash or, possibly, allow the attacker to execute
arbitrary code with the privileges of the "apache" user. (CVE-2014-0226)

A denial of service flaw was found in the way httpd's mod_deflate module
handled request body decompression (configured via the "DEFLATE" input
filter). A remote attacker able to send a request whose body would be
decompressed could use this flaw to consume an excessive amount of system
memory and CPU on the target system. (CVE-2014-0118)

A denial of service flaw was found in the way httpd's mod_cgid module
executed CGI scripts that did not read data from the standard input.
A remote attacker could submit a specially crafted request that would cause
the httpd child process to hang indefinitely. (CVE-2014-0231)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0920</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0118</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0226</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0231</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140920"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140921" severity="high">
    <xccdf:title>RHSA-2014:0921: httpd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

A race condition flaw, leading to heap-based buffer overflows, was found in
the mod_status httpd module. A remote attacker able to access a status page
served by mod_status on a server using a threaded Multi-Processing Module
(MPM) could send a specially crafted request that would cause the httpd
child process to crash or, possibly, allow the attacker to execute
arbitrary code with the privileges of the "apache" user. (CVE-2014-0226)

A NULL pointer dereference flaw was found in the mod_cache httpd module.
A malicious HTTP server could cause the httpd child process to crash when
the Apache HTTP Server was used as a forward proxy with caching.
(CVE-2013-4352)

A denial of service flaw was found in the mod_proxy httpd module. A remote
attacker could send a specially crafted request to a server configured as a
reverse proxy using a threaded Multi-Processing Modules (MPM) that would
cause the httpd child process to crash. (CVE-2014-0117)

A denial of service flaw was found in the way httpd's mod_deflate module
handled request body decompression (configured via the "DEFLATE" input
filter). A remote attacker able to send a request whose body would be
decompressed could use this flaw to consume an excessive amount of system
memory and CPU on the target system. (CVE-2014-0118)

A denial of service flaw was found in the way httpd's mod_cgid module
executed CGI scripts that did not read data from the standard input.
A remote attacker could submit a specially crafted request that would cause
the httpd child process to hang indefinitely. (CVE-2014-0231)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0921</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0117</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0118</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0226</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0231</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140921"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140923" severity="high">
    <xccdf:title>RHSA-2014:0923: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's ptrace subsystem allowed a traced
process' instruction pointer to be set to a non-canonical memory address
without forcing the non-sysret code path when returning to user space.
A local, unprivileged user could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-4699,
Important)

Note: The CVE-2014-4699 issue only affected systems using an Intel CPU.

* A flaw was found in the way the pppol2tp_setsockopt() and
pppol2tp_getsockopt() functions in the Linux kernel's PPP over L2TP
implementation handled requests with a non-SOL_PPPOL2TP socket option
level. A local, unprivileged user could use this flaw to escalate their
privileges on the system. (CVE-2014-4943, Important)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-4699,
and Sasha Levin for reporting CVE-2014-4943.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0923</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4943</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140923"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140924" severity="high">
    <xccdf:title>RHSA-2014:0924: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's ptrace subsystem allowed a traced
process' instruction pointer to be set to a non-canonical memory address
without forcing the non-sysret code path when returning to user space.
A local, unprivileged user could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-4699,
Important)

Note: The CVE-2014-4699 issue only affected systems using an Intel CPU.

* A flaw was found in the way the pppol2tp_setsockopt() and
pppol2tp_getsockopt() functions in the Linux kernel's PPP over L2TP
implementation handled requests with a non-SOL_PPPOL2TP socket option
level. A local, unprivileged user could use this flaw to escalate their
privileges on the system. (CVE-2014-4943, Important)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-4699,
and Sasha Levin for reporting CVE-2014-4943.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0924</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4943</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140924"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140926" severity="medium">
    <xccdf:title>RHSA-2014:0926: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A NULL pointer dereference flaw was found in the rds_iw_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2014-2678, Moderate)

* It was found that the Xen hypervisor implementation did not properly
clean memory pages previously allocated by the hypervisor. A privileged
guest user could potentially use this flaw to read data relating to other
guests or the hypervisor itself. (CVE-2014-4021, Moderate)

Red Hat would like to thank the Xen project for reporting CVE-2014-4021.
Upstream acknowledges Jan Beulich as the original reporter.

This update also fixes the following bugs:

* A bug in the journaling block device (jbd and jbd2) code could, under
certain circumstances, trigger a BUG_ON() assertion and result in a kernel
oops. This happened when an application performed an extensive number of
commits to the journal of the ext3 file system and there was no currently
active transaction while synchronizing the file's in-core state. This
problem has been resolved by correcting respective test conditions in the
jbd and jbd2 code. (BZ#1097528)

* After a statically defined gateway became unreachable and its
corresponding neighbor entry entered a FAILED state, the gateway stayed in
the FAILED state even after it became reachable again. As a consequence,
traffic was not routed through that gateway. This update allows probing
such a gateway automatically so that the traffic can be routed through
this gateway again once it becomes reachable. (BZ#1106354)

* Due to an incorrect condition check in the IPv6 code, the ipv6 driver
was unable to correctly assemble incoming packet fragments, which resulted
in a high IPv6 packet loss rate. This update fixes the said check for a
fragment overlap and ensures that incoming IPv6 packet fragments are now
processed as expected. (BZ#1107932)

* Recent changes in the d_splice_alias() function introduced a bug that
allowed d_splice_alias() to return a dentry from a different directory
than the directory being looked up. As a consequence in cluster
environment, a kernel panic could be triggered when a directory was being
removed while a concurrent cross-directory operation was performed on this
directory on another cluster node. This update avoids the kernel panic in
this situation by correcting the search logic in the d_splice_alias()
function so that the function can no longer return a dentry from an
incorrect directory. (BZ#1109720)

* The NFSv4 server did not handle multiple OPEN operations to the same file
separately, which could cause the NFSv4 client to repeatedly send CLOSE
requests with the same state ID, even though the NFS server rejected the
request with an NFS4ERR_OLD_STATEID (10024) error code. This update
ensures that the NFSv4 client no longer re-sends the same CLOSE request
after receiving NFS4ERR_OLD_STATEID. (BZ#1113468)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4021</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140926"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140927" severity="medium">
    <xccdf:title>RHSA-2014:0927: qemu-kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Two integer overflow flaws were found in the QEMU block driver for QCOW
version 1 disk images. A user able to alter the QEMU disk image files
loaded by a guest could use either of these flaws to corrupt QEMU process
memory on the host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0222, CVE-2014-0223)

Multiple buffer overflow, input validation, and out-of-bounds write flaws
were found in the way virtio, virtio-net, virtio-scsi, usb, and hpet
drivers of QEMU handled state loading after migration. A user able to alter
the savevm data (either on the disk or over the wire during migration)
could use either of these flaws to corrupt QEMU process memory on the
(destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4148, CVE-2013-4149, CVE-2013-4150, CVE-2013-4151, CVE-2013-4527,
CVE-2013-4529, CVE-2013-4535, CVE-2013-4536, CVE-2013-4541, CVE-2013-4542,
CVE-2013-6399, CVE-2014-0182, CVE-2014-3461)

These issues were discovered by Michael S. Tsirkin, Anthony Liguori and
Michael Roth of Red Hat: CVE-2013-4148, CVE-2013-4149, CVE-2013-4150,
CVE-2013-4151, CVE-2013-4527, CVE-2013-4529, CVE-2013-4535, CVE-2013-4536,
CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, and
CVE-2014-3461.

This update also fixes the following bugs:

* Previously, QEMU did not free pre-allocated zero clusters correctly and
the clusters under some circumstances leaked. With this update,
pre-allocated zero clusters are freed appropriately and the cluster leaks
no longer occur. (BZ#1110188)

* Prior to this update, the QEMU command interface did not properly handle
resizing of cache memory during guest migration, causing QEMU to terminate
unexpectedly with a segmentation fault and QEMU to fail. This update fixes
the related code and QEMU no longer crashes in the described situation.
(BZ#1110191)

* Previously, when a guest device was hot unplugged, QEMU correctly removed
the corresponding file descriptor watch but did not re-create it after the
device was re-connected. As a consequence, the guest became unable to
receive any data from the host over this device. With this update, the file
descriptor's watch is re-created and the guest in the above scenario can
communicate with the host as expected. (BZ#1110219)

* Previously, the QEMU migration code did not account for the gaps caused
by hot unplugged devices and thus expected more memory to be transferred
during migrations. As a consequence, guest migration failed to complete
after multiple devices were hot unplugged. In addition, the migration info
text displayed erroneous values for the "remaining ram" item. With this
update, QEMU calculates memory after a device has been unplugged correctly,
and any subsequent guest migrations proceed as expected. (BZ#1110189)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0927</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4149</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4536</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4541</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4542</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6399</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3461</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140927"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20140981" severity="high">
    <xccdf:title>RHSA-2014:0981: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A use-after-free flaw was found in the way the ping_init_sock() function
of the Linux kernel handled the group_info reference counter. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2014-2851, Important)

* A NULL pointer dereference flaw was found in the way the
futex_wait_requeue_pi() function of the Linux kernel's futex subsystem
handled the requeuing of certain Priority Inheritance (PI) futexes.
A local, unprivileged user could use this flaw to crash the system.
(CVE-2012-6647, Moderate)

* A NULL pointer dereference flaw was found in the rds_ib_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2013-7339, Moderate)

* It was found that a remote attacker could use a race condition flaw in
the ath_tx_aggr_sleep() function to crash the system by creating large
network traffic on the system's Atheros 9k wireless network adapter.
(CVE-2014-2672, Moderate)

* A NULL pointer dereference flaw was found in the rds_iw_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2014-2678, Moderate)

* A race condition flaw was found in the way the Linux kernel's mac80211
subsystem implementation handled synchronization between TX and STA wake-up
code paths. A remote attacker could use this flaw to crash the system.
(CVE-2014-2706, Moderate)

* An out-of-bounds memory access flaw was found in the Netlink Attribute
extension of the Berkeley Packet Filter (BPF) interpreter functionality in
the Linux kernel's networking implementation. A local, unprivileged user
could use this flaw to crash the system or leak kernel memory to user space
via a specially crafted socket filter. (CVE-2014-3144, CVE-2014-3145,
Moderate)

This update also fixes several bugs and adds one enhancement.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2672</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2678</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2706</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2851</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3145</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20140981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141004" severity="high">
    <xccdf:title>RHSA-2014:1004: yum-updatesd security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The yum-updatesd package provides a daemon which checks for available
updates and can notify you when they are available via email, syslog,
or dbus.

It was discovered that yum-updatesd did not properly perform RPM package
signature checks. When yum-updatesd was configured to automatically install
updates, a remote attacker could use this flaw to install a malicious
update on the target system using an unsigned RPM or an RPM signed with an
untrusted key. (CVE-2014-0022)

All yum-updatesd users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue. After installing
this update, the yum-updatesd service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0022</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141004"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141008" severity="high">
    <xccdf:title>RHSA-2014:1008: samba security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A heap-based buffer overflow flaw was found in Samba's NetBIOS message
block daemon (nmbd). An attacker on the local network could use this flaw
to send specially crafted packets that, when processed by nmbd, could
possibly lead to arbitrary code execution with root privileges.
(CVE-2014-3560)

This update also fixes the following bug:

* Prior to this update, Samba incorrectly used the O_TRUNC flag when using
the open(2) system call to access the contents of a file that was already
opened by a different process, causing the file's previous contents to be
removed. With this update, the O_TRUNC flag is no longer used in the above
scenario, and file corruption no longer occurs. (BZ#1115490)

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3560</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141009" severity="high">
    <xccdf:title>RHSA-2014:1009: samba4 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A heap-based buffer overflow flaw was found in Samba's NetBIOS message
block daemon (nmbd). An attacker on the local network could use this flaw
to send specially crafted packets that, when processed by nmbd, could
possibly lead to arbitrary code execution with root privileges.
(CVE-2014-3560)

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0178</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3560</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141009"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141011" severity="medium">
    <xccdf:title>RHSA-2014:1011: resteasy-base security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>RESTEasy contains a JBoss project that provides frameworks to help build
RESTful Web Services and RESTful Java applications. It is a fully certified
and portable implementation of the JAX-RS specification.

It was found that the fix for CVE-2012-0818 was incomplete: external
parameter entities were not disabled when the
resteasy.document.expand.entity.references parameter was set to false.
A remote attacker able to send XML requests to a RESTEasy endpoint could
use this flaw to read files accessible to the user running the application
server, and potentially perform other more advanced XXE attacks.
(CVE-2014-3490)

This issue was discovered by David Jorm of Red Hat Product Security.

All resteasy-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3490</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141011"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141012" severity="medium">
    <xccdf:title>RHSA-2014:1012: php53 and php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

Multiple denial of service flaws were found in the way the File Information
(fileinfo) extension parsed certain Composite Document Format (CDF) files.
A remote attacker could use either of these flaws to crash a PHP
application using fileinfo via a specially crafted CDF file.
(CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2012-1571)

Two denial of service flaws were found in the way the File Information
(fileinfo) extension handled indirect and search rules. A remote attacker
could use either of these flaws to cause a PHP application using fileinfo
to crash or consume an excessive amount of CPU. (CVE-2014-1943,
CVE-2014-2270)

A heap-based buffer overflow flaw was found in the way PHP parsed DNS TXT
records. A malicious DNS server or a man-in-the-middle attacker could
possibly use this flaw to execute arbitrary code as the PHP interpreter if
a PHP application used the dns_get_record() function to perform a DNS
query. (CVE-2014-4049)

A type confusion issue was found in PHP's phpinfo() function. A malicious
script author could possibly use this flaw to disclose certain portions of
server memory. (CVE-2014-4721)

A buffer over-read flaw was found in the way the DateInterval class parsed
interval specifications. An attacker able to make a PHP application parse a
specially crafted specification using DateInterval could possibly cause the
PHP interpreter to crash. (CVE-2013-6712)

A type confusion issue was found in the SPL ArrayObject and
SPLObjectStorage classes' unserialize() method. A remote attacker able to
submit specially crafted input to a PHP application, which would then
unserialize this input using one of the aforementioned methods, could use
this flaw to execute arbitrary code with the privileges of the user running
that PHP application. (CVE-2014-3515)

The CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, and CVE-2014-3480 issues
were discovered by Francisco Alonso of Red Hat Product Security.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4721</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141012"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141013" severity="medium">
    <xccdf:title>RHSA-2014:1013: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

A denial of service flaw was found in the File Information (fileinfo)
extension rules for detecting AWK files. A remote attacker could use this
flaw to cause a PHP application using fileinfo to consume an excessive
amount of CPU. (CVE-2013-7345)

Multiple denial of service flaws were found in the way the File Information
(fileinfo) extension parsed certain Composite Document Format (CDF) files.
A remote attacker could use either of these flaws to crash a PHP
application using fileinfo via a specially crafted CDF file.
(CVE-2014-0207, CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480,
CVE-2014-3487)

A heap-based buffer overflow flaw was found in the way PHP parsed DNS TXT
records. A malicious DNS server or a man-in-the-middle attacker could
possibly use this flaw to execute arbitrary code as the PHP interpreter if
a PHP application used the dns_get_record() function to perform a DNS
query. (CVE-2014-4049)

A type confusion issue was found in PHP's phpinfo() function. A malicious
script author could possibly use this flaw to disclose certain portions of
server memory. (CVE-2014-4721)

A type confusion issue was found in the SPL ArrayObject and
SPLObjectStorage classes' unserialize() method. A remote attacker able to
submit specially crafted input to a PHP application, which would then
unserialize this input using one of the aforementioned methods, could use
this flaw to execute arbitrary code with the privileges of the user running
that PHP application. (CVE-2014-3515)

The CVE-2014-0207, CVE-2014-0237, CVE-2014-0238, CVE-2014-3479,
CVE-2014-3480, and CVE-2014-3487 issues were discovered by Francisco Alonso
of Red Hat Product Security.

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1013</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3487</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4721</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141013"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141023" severity="high">
    <xccdf:title>RHSA-2014:1023: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that Linux kernel's ptrace subsystem did not properly
sanitize the address-space-control bits when the program-status word (PSW)
was being set. On IBM S/390 systems, a local, unprivileged user could use
this flaw to set address-space-control bits to the kernel space, and thus
gain read and write access to kernel memory. (CVE-2014-3534, Important)

* It was found that the permission checks performed by the Linux kernel
when a netlink message was received were not sufficient. A local,
unprivileged user could potentially bypass these restrictions by passing a
netlink socket as stdout or stderr to a more privileged process and
altering the output of this process. (CVE-2014-0181, Moderate)

* It was found that a remote attacker could use a race condition flaw in
the ath_tx_aggr_sleep() function to crash the system by creating large
network traffic on the system's Atheros 9k wireless network adapter.
(CVE-2014-2672, Moderate)

* A flaw was found in the way the Linux kernel performed forking inside of
a transaction. A local, unprivileged user on a PowerPC system that supports
transactional memory could use this flaw to crash the system.
(CVE-2014-2673, Moderate)

* A race condition flaw was found in the way the Linux kernel's mac80211
subsystem implementation handled synchronization between TX and STA wake-up
code paths. A remote attacker could use this flaw to crash the system.
(CVE-2014-2706, Moderate)

* An integer underflow flaw was found in the way the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation processed certain
COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote
attacker could use this flaw to prevent legitimate connections to a
particular SCTP server socket to be made. (CVE-2014-4667, Moderate)

Red Hat would like to thank Martin Schwidefsky of IBM for reporting
CVE-2014-3534, Andy Lutomirski for reporting CVE-2014-0181, and Gopal Reddy
Kodudula of Nokia Siemens Networks for reporting CVE-2014-4667.

This update also fixes the following bugs:

* Due to a NULL pointer dereference bug in the IPIP and SIT tunneling code,
a kernel panic could be triggered when using IPIP or SIT tunnels with
IPsec. This update restructures the related code to avoid a NULL pointer
dereference and the kernel no longer panics when using IPIP or SIT tunnels
with IPsec. (BZ#1114957)

* Previously, an IBM POWER8 system could terminate unexpectedly when the
kernel received an IRQ while handling a transactional memory re-checkpoint
critical section. This update ensures that IRQs are disabled in this
situation and the problem no longer occurs. (BZ#1113150)

* A missing read memory barrier, rmb(), in the bnx2x driver caused the
kernel to crash under various circumstances. This problem has been fixed
by adding an rmb() call to the relevant place in the bnx2x code.
(BZ#1107721)

* The hpwdt driver previously emitted a panic message that was misleading
on certain HP systems. This update ensures that upon a kernel panic, hpwdt
displays information valid on all HP systems. (BZ#1096961)

* The qla2xxx driver has been upgraded to version 8.06.00.08.07.0-k3,
which provides a number of bug fixes over the previous version in order to
correct various timeout problems with the mailbox commands. (BZ#1112389)

* The SCSI mid-layer could retry an I/O operation indefinitely if a storage
array repeatedly returned a CHECK CONDITION status to that I/O operation
but the sense data was invalid. This update fixes the problem by limiting
a time for which is such an I/O operation retried. (BZ#1114468)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2672</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2706</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141023"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141031" severity="high">
    <xccdf:title>RHSA-2014:1031: 389-ds-base security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was found that when replication was enabled for each attribute in 389
Directory Server, which is the default configuration, the server returned
replicated metadata when the directory was searched while debugging was
enabled. A remote attacker could use this flaw to disclose potentially
sensitive information. (CVE-2014-3562)

This issue was discovered by Ludwig Krispenz of Red Hat.

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1031</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3562</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141031"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141034" severity="low">
    <xccdf:title>RHSA-2014:1034: tomcat security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that, in certain circumstances, it was possible for a
malicious web application to replace the XML parsers used by Apache Tomcat
to process XSLTs for the default servlet, JSP documents, tag library
descriptors (TLDs), and tag plug-in configuration files. The injected XML
parser(s) could then bypass the limits imposed on XML external entities
and/or gain access to the XML files processed for other web applications
deployed on the same Apache Tomcat instance. (CVE-2014-0119)

All Tomcat users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Tomcat must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1034</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0119</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141034"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141038" severity="low">
    <xccdf:title>RHSA-2014:1038: tomcat6 security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that several application-provided XML files, such as web.xml,
content.xml, *.tld, *.tagx, and *.jspx, resolved external entities,
permitting XML External Entity (XXE) attacks. An attacker able to deploy
malicious applications to Tomcat could use this flaw to circumvent security
restrictions set by the JSM, and gain access to sensitive information on
the system. Note that this flaw only affected deployments in which Tomcat
is running applications from untrusted sources, such as in a shared hosting
environment. (CVE-2013-4590)

It was found that, in certain circumstances, it was possible for a
malicious web application to replace the XML parsers used by Apache Tomcat
to process XSLTs for the default servlet, JSP documents, tag library
descriptors (TLDs), and tag plug-in configuration files. The injected XML
parser(s) could then bypass the limits imposed on XML external entities
and/or gain access to the XML files processed for other web applications
deployed on the same Apache Tomcat instance. (CVE-2014-0119)

All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0119</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141038"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141052" severity="medium">
    <xccdf:title>RHSA-2014:1052: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

A race condition was found in the way OpenSSL handled ServerHello messages
with an included Supported EC Point Format extension. A malicious server
could possibly use this flaw to cause a multi-threaded TLS/SSL client using
OpenSSL to write into freed memory, causing the client to crash or execute
arbitrary code. (CVE-2014-3509)

It was discovered that the OBJ_obj2txt() function could fail to properly
NUL-terminate its output. This could possibly cause an application using
OpenSSL functions to format fields of X.509 certificates to disclose
portions of its memory. (CVE-2014-3508)

A flaw was found in the way OpenSSL handled fragmented handshake packets.
A man-in-the-middle attacker could use this flaw to force a TLS/SSL server
using OpenSSL to use TLS 1.0, even if both the client and the server
supported newer protocol versions. (CVE-2014-3511)

Multiple flaws were discovered in the way OpenSSL handled DTLS packets.
A remote attacker could use these flaws to cause a DTLS server or client
using OpenSSL to crash or use excessive amounts of memory. (CVE-2014-3505,
CVE-2014-3506, CVE-2014-3507)

A NULL pointer dereference flaw was found in the way OpenSSL performed a
handshake when using the anonymous Diffie-Hellman (DH) key exchange. A
malicious server could cause a DTLS client using OpenSSL to crash if that
client had anonymous DH cipher suites enabled. (CVE-2014-3510)

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3511</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141052"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141053" severity="medium">
    <xccdf:title>RHSA-2014:1053: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

It was discovered that the OBJ_obj2txt() function could fail to properly
NUL-terminate its output. This could possibly cause an application using
OpenSSL functions to format fields of X.509 certificates to disclose
portions of its memory. (CVE-2014-3508)

Multiple flaws were discovered in the way OpenSSL handled DTLS packets.
A remote attacker could use these flaws to cause a DTLS server or client
using OpenSSL to crash or use excessive amounts of memory. (CVE-2014-0221,
CVE-2014-3505, CVE-2014-3506)

A NULL pointer dereference flaw was found in the way OpenSSL performed a
handshake when using the anonymous Diffie-Hellman (DH) key exchange. A
malicious server could cause a DTLS client using OpenSSL to crash if that
client had anonymous DH cipher suites enabled. (CVE-2014-3510)

Red Hat would like to thank the OpenSSL project for reporting
CVE-2014-0221. Upstream acknowledges Imre Rad of Search-Lab as the original
reporter of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3508</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3510</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141053"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141073" severity="low">
    <xccdf:title>RHSA-2014:1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv3, TLS, and other
security standards.

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

In addition, the nss, nss-util, and nss-softokn packages have been upgraded
to upstream version 3.16.2, which provides a number of bug fixes and
enhancements over the previous versions. (BZ#1124659)

Users of NSS are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. After installing this
update, applications using NSS must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141073"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141075" severity="medium">
    <xccdf:title>RHSA-2014:1075: qemu-kvm security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Two integer overflow flaws were found in the QEMU block driver for QCOW
version 1 disk images. A user able to alter the QEMU disk image files
loaded by a guest could use either of these flaws to corrupt QEMU process
memory on the host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0222, CVE-2014-0223)

Red Hat would like to thank NSA for reporting these issues.

This update also fixes the following bugs:

* In certain scenarios, when performing live incremental migration, the
disk size could be expanded considerably due to the transfer of unallocated
sectors past the end of the base image. With this update, the
bdrv_is_allocated() function has been fixed to no longer return "True" for
unallocated sectors, and the disk size no longer changes after performing
live incremental migration. (BZ#1109715)

* This update enables ioeventfd in virtio-scsi-pci. This allows QEMU to
process I/O requests outside of the vCPU thread, reducing the latency of
submitting requests and improving single task throughput. (BZ#1123271)

* Prior to this update, vendor-specific SCSI commands issued from a KVM
guest did not reach the target device due to QEMU considering such commands
as invalid. This update fixes this bug by properly propagating
vendor-specific SCSI commands to the target device. (BZ#1125131)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1075</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0222</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0223</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141075"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141091" severity="high">
    <xccdf:title>RHSA-2014:1091: mod_wsgi security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mod_wsgi adapter is an Apache module that provides a WSGI-compliant
interface for hosting Python-based web applications within Apache.

It was found that mod_wsgi did not properly drop privileges if the call to
setuid() failed. If mod_wsgi was set up to allow unprivileged users to run
WSGI applications, a local user able to run a WSGI application could
possibly use this flaw to escalate their privileges on the system.
(CVE-2014-0240)

Note: mod_wsgi is not intended to provide privilege separation for WSGI
applications. Systems relying on mod_wsgi to limit or sandbox the
privileges of mod_wsgi applications should migrate to a different solution
with proper privilege separation.

Red Hat would like to thank Graham Dumpleton for reporting this issue.
Upstream acknowledges Róbert Kisteleki as the original reporter.

All mod_wsgi users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141091"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141110" severity="high">
    <xccdf:title>RHSA-2014:1110: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

An off-by-one heap-based buffer overflow flaw was found in glibc's internal
__gconv_translit_find() function. An attacker able to make an application
call the iconv_open() function with a specially crafted argument could
possibly use this flaw to execute arbitrary code with the privileges of
that application. (CVE-2014-5119)

A directory traveral flaw was found in the way glibc loaded locale files.
An attacker able to make an application use a specially crafted locale name
value (for example, specified in an LC_* environment variable) could
possibly use this flaw to execute arbitrary code with the privileges of
that application. (CVE-2014-0475)

Red Hat would like to thank Stephane Chazelas for reporting CVE-2014-0475.

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1110</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5119</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141110"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141143" severity="medium">
    <xccdf:title>RHSA-2014:1143: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An out-of-bounds memory access flaw was found in the Linux kernel's
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

This update also fixes the following bugs:

* A bug in the journaling code (jbd and jbd2) could, under very heavy
workload of fsync() operations, trigger a BUG_ON and result in a kernel
oops. Also, fdatasync() could fail to immediately write out changes in the
file size only. These problems have been resolved by backporting a series
of patches that fixed these problems in the respective code on Red Hat
Enterprise Linux 6. This update also improves performance of ext3 and ext4
file systems. (BZ#1116027)

* Due to a bug in the ext4 code, the fdatasync() system call did not force
the inode size change to be written to the disk if it was the only metadata
change in the file. This could result in the wrong inode size and possible
data loss if the system terminated unexpectedly. The code handling inode
updates has been fixed and fdatasync() now writes data to the disk as
expected in this situation. (BZ#1117665)

* A workaround to a DMA read problem in the tg3 driver was incorrectly
applied to the whole Broadcom 5719 and 5720 chipset family. This workaround
is valid only to the A0 revision of the 5719 chips and for other revisions
and chips causes occasional Tx timeouts. This update correctly applies the
aforementioned workaround only to the A0 revision of the 5719 chips.
(BZ#1121017)

* Due to a bug in the page writeback code, the system could become
unresponsive when being under memory pressure and heavy NFS load. This
update fixes the code responsible for handling of dirty pages, and dirty
page write outs no longer flood the work queue. (BZ#1125246)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3917</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141143"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141144" severity="high">
    <xccdf:title>RHSA-2014:1144: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1562, CVE-2014-1567)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jan de Mooij as the original reporter of
CVE-2014-1562, and regenrecht as the original reporter of CVE-2014-1567.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.8.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.8.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1144</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1567</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141144"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141145" severity="high">
    <xccdf:title>RHSA-2014:1145: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1562, CVE-2014-1567)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jan de Mooij as the original reporter of
CVE-2014-1562, and regenrecht as the original reporter of CVE-2014-1567.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.8.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.8.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1567</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141145"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141146" severity="high">
    <xccdf:title>RHSA-2014:1146: httpcomponents-client security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HttpClient is an HTTP/1.1 compliant HTTP agent implementation based on
httpcomponents HttpCore.

It was discovered that the HttpClient incorrectly extracted host name from
an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All httpcomponents-client users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1146</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3577</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141146"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141147" severity="high">
    <xccdf:title>RHSA-2014:1147: squid security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A flaw was found in the way Squid handled malformed HTTP Range headers.
A remote attacker able to send HTTP requests to the Squid proxy could use
this flaw to crash Squid. (CVE-2014-3609)

Red Hat would like to thank the Squid project for reporting this issue.
Upstream acknowledges Matthew Daley as the original reporter.

All Squid users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the squid service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141147"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141148" severity="high">
    <xccdf:title>RHSA-2014:1148: squid security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A flaw was found in the way Squid handled malformed HTTP Range headers.
A remote attacker able to send HTTP requests to the Squid proxy could use
this flaw to crash Squid. (CVE-2014-3609)

A buffer overflow flaw was found in Squid's DNS lookup module. A remote
attacker able to send HTTP requests to the Squid proxy could use this flaw
to crash Squid. (CVE-2013-4115)

Red Hat would like to thank the Squid project for reporting the
CVE-2014-3609 issue. Upstream acknowledges Matthew Daley as the original
reporter.

All Squid users are advised to upgrade to this updated package, which
contains backported patches to correct these issues. After installing this
update, the squid service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3609</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141148"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141166" severity="high">
    <xccdf:title>RHSA-2014:1166: jakarta-commons-httpclient security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Jakarta Commons HTTPClient implements the client side of HTTP standards.

It was discovered that the HTTPClient incorrectly extracted host name from
an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All jakarta-commons-httpclient users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3577</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141167" severity="high">
    <xccdf:title>RHSA-2014:1167: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's futex subsystem handled
reference counting when requeuing futexes during futex_wait(). A local,
unprivileged user could use this flaw to zero out the reference counter of
an inode or an mm struct that backs up the memory area of the futex, which
could lead to a use-after-free flaw, resulting in a system crash or,
potentially, privilege escalation. (CVE-2014-0205, Important)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
networking implementation handled logging while processing certain invalid
packets coming in via a VxLAN interface. A remote attacker could use this
flaw to crash the system by sending a specially crafted packet to such an
interface. (CVE-2014-3535, Important)

* An out-of-bounds memory access flaw was found in the Linux kernel's
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

* An integer underflow flaw was found in the way the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation processed certain
COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote
attacker could use this flaw to prevent legitimate connections to a
particular SCTP server socket to be made. (CVE-2014-4667, Moderate)

Red Hat would like to thank Gopal Reddy Kodudula of Nokia Siemens Networks
for reporting CVE-2014-4667. The security impact of the CVE-2014-0205 issue
was discovered by Mateusz Guzik of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1167</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3917</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4667</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141167"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141172" severity="high">
    <xccdf:title>RHSA-2014:1172: procmail security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The procmail program is used for local mail delivery. In addition to just
delivering mail, procmail can be used for automatic filtering, presorting,
and other mail handling jobs.

A heap-based buffer overflow flaw was found in procmail's formail utility.
A remote attacker could send an email with specially crafted headers that,
when processed by formail, could cause procmail to crash or, possibly,
execute arbitrary code as the user running formail. (CVE-2014-3618)

All procmail users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3618</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141172"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141193" severity="high">
    <xccdf:title>RHSA-2014:1193: axis security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

It was discovered that Axis incorrectly extracted the host name from an
X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3596)

For additional information on this flaw, refer to the Knowledgebase article
in the References section.

This issue was discovered by David Jorm and Arun Neelicattu of Red Hat
Product Security.

All axis users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using Apache
Axis must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3596</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141193"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141194" severity="medium">
    <xccdf:title>RHSA-2014:1194: conga security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Conga project is a management system for remote workstations.
It consists of luci, which is a secure web-based front end, and ricci,
which is a secure daemon that dispatches incoming messages to underlying
management modules.

It was discovered that Plone, included as a part of luci, did not properly
protect the administrator interface (control panel). A remote attacker
could use this flaw to inject a specially crafted Python statement or
script into Plone's restricted Python sandbox that, when the administrator
interface was accessed, would be executed with the privileges of that
administrator user. (CVE-2012-5485)

It was discovered that Plone, included as a part of luci, did not properly
sanitize HTTP headers provided within certain URL requests. A remote
attacker could use a specially crafted URL that, when processed, would
cause the injected HTTP headers to be returned as a part of the Plone HTTP
response, potentially allowing the attacker to perform other more advanced
attacks. (CVE-2012-5486)

Multiple information leak flaws were found in the way conga processed luci
site extension-related URL requests. A remote, unauthenticated attacker
could issue a specially crafted HTTP request that, when processed, would
result in unauthorized information disclosure. (CVE-2013-6496)

It was discovered that various components in the luci site
extension-related URLs were not properly restricted to administrative
users. A remote, authenticated attacker could escalate their privileges to
perform certain actions that should be restricted to administrative users,
such as adding users and systems, and viewing log data. (CVE-2014-3521)

It was discovered that Plone, included as a part of luci, did not properly
protect the privilege of running RestrictedPython scripts. A remote
attacker could use a specially crafted URL that, when processed, would
allow the attacker to submit and perform expensive computations or, in
conjunction with other attacks, be able to access or alter privileged
information. (CVE-2012-5488)

It was discovered that Plone, included as a part of luci, did not properly
enforce permissions checks on the membership database. A remote attacker
could use a specially crafted URL that, when processed, could allow the
attacker to enumerate user account names. (CVE-2012-5497)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of requests for certain collections. A remote
attacker could use a specially crafted URL that, when processed, would lead
to excessive I/O and/or cache resource consumption. (CVE-2012-5498)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of very large values passed to an internal utility
function. A remote attacker could use a specially crafted URL that, when
processed, would lead to excessive memory consumption. (CVE-2012-5499)

It was discovered that Plone, included as a part of luci, allowed a remote
anonymous user to change titles of content items due to improper
permissions checks. (CVE-2012-5500)

The CVE-2014-3521 issue was discovered by Radek Steiger of Red Hat, and the
CVE-2013-6496 issue was discovered by Jan Pokorny of Red Hat.

In addition, these updated conga packages include several bug fixes.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux 5.11 Technical Notes,
linked to in the References section, for information on the most
significant of these changes

All conga users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the luci and ricci services will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6496</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3521</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141194"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141243" severity="low">
    <xccdf:title>RHSA-2014:1243: automake security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Automake is a tool for automatically generating Makefile.in files compliant
with the GNU Coding Standards.

It was found that the distcheck rule in Automake-generated Makefiles made a
directory world-writable when preparing source archives. If a malicious,
local user could access this directory, they could execute arbitrary code
with the privileges of the user running "make distcheck". (CVE-2012-3386)

Red Hat would like to thank Jim Meyering for reporting this issue. Upstream
acknowledges Stefano Lattarini as the original reporter.

All automake users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-3386</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141243"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141244" severity="medium">
    <xccdf:title>RHSA-2014:1244: bind97 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. It contains a DNS server (named), a resolver
library with routines for applications to use when interfacing with DNS,
and tools for verifying that the DNS server is operating correctly.
These packages contain version 9.7 of the BIND suite.

A denial of service flaw was found in the way BIND handled queries for
NSEC3-signed zones. A remote attacker could use this flaw against an
authoritative name server that served NCES3-signed zones by sending a
specially crafted query, which, when processed, would cause named to crash.
(CVE-2014-0591)

Note: The CVE-2014-0591 issue does not directly affect the version of
bind97 shipped in Red Hat Enterprise Linux 5. This issue is being addressed
however to assure it is not introduced in future builds of bind97 (possibly
built with a different compiler or C library optimization).

This update also fixes the following bug:

* Previously, the bind97 initscript did not check for the existence of the
ROOTDIR variable when shutting down the named daemon. As a consequence,
some parts of the file system that are mounted when using bind97 in a
chroot environment were unmounted on daemon shut down, even if bind97 was
not running in a chroot environment. With this update, the initscript has
been fixed to check for the existence of the ROOTDIR variable when
unmounting some parts of the file system on named daemon shut down. Now,
when shutting down bind97 that is not running in a chroot environment, no
parts of the file system are unmounted. (BZ#1059118)

All bind97 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0591</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141244"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141245" severity="medium">
    <xccdf:title>RHSA-2014:1245: krb5 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer over-read flaw was found in the way MIT Kerberos handled certain
requests. A man-in-the-middle attacker with a valid Kerberos ticket who is
able to inject packets into a client or server application's GSSAPI session
could use this flaw to crash the application. (CVE-2014-4341)

This update also fixes the following bugs:

* Prior to this update, the libkrb5 library occasionally attempted to free
already freed memory when encrypting credentials. As a consequence, the
calling process terminated unexpectedly with a segmentation fault.
With this update, libkrb5 frees memory correctly, which allows the
credentials to be encrypted appropriately and thus prevents the mentioned
crash. (BZ#1004632)

* Previously, when the krb5 client library was waiting for a response from
a server, the timeout variable in certain cases became a negative number.
Consequently, the client could enter a loop while checking for responses.
With this update, the client logic has been modified and the described
error no longer occurs. (BZ#1089732)

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the krb5kdc daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4344</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141245"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141246" severity="medium">
    <xccdf:title>RHSA-2014:1246: nss and nspr security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues. Upstream
acknowledges Brian Smith as the original reporter of CVE-2014-1490, Antoine
Delignat-Lavaud and Karthikeyan Bhargavan as the original reporters of
CVE-2014-1491, and Abhishek Arya as the original reporter of CVE-2014-1545.

The nss and nspr packages have been upgraded to upstream version 3.16.1 and
4.10.6 respectively, which provide a number of bug fixes and enhancements
over the previous versions. (BZ#1110857, BZ#1110860)

This update also fixes the following bugs:

* Previously, when the output.log file was not present on the system, the
shell in the Network Security Services (NSS) specification handled test
failures incorrectly as false positive test results. Consequently, certain
utilities, such as "grep", could not handle failures properly. This update
improves error detection in the specification file, and "grep" and other
utilities now handle missing files or crashes as intended. (BZ#1035281)

* Prior to this update, a subordinate Certificate Authority (CA) of the
ANSSI agency incorrectly issued an intermediate certificate installed on a
network monitoring device. As a consequence, the monitoring device was
enabled to act as an MITM (Man in the Middle) proxy performing traffic
management of domain names or IP addresses that the certificate holder did
not own or control. The trust in the intermediate certificate to issue the
certificate for an MITM device has been revoked, and such a device can no
longer be used for MITM attacks. (BZ#1042684)

* Due to a regression, MD5 certificates were rejected by default because
Network Security Services (NSS) did not trust MD5 certificates. With this
update, MD5 certificates are supported in Red Hat Enterprise Linux 5.
(BZ#11015864)

Users of nss and nspr are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1246</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1490</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1545</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141246"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141255" severity="medium">
    <xccdf:title>RHSA-2014:1255: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

All krb5 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the krb5kdc and kadmind daemons will be restarted
automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1255</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4345</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141255"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141281" severity="medium">
    <xccdf:title>RHSA-2014:1281: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An out-of-bounds memory access flaw was found in the Linux kernel's
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

This update also fixes the following bugs: 

* A bug in the mtip32xx driver could prevent the Micron P420m PCIe SSD
devices with unaligned I/O access from completing the submitted I/O
requests. This resulted in a livelock situation and rendered the Micron
P420m PCIe SSD devices unusable. To fix this problem, mtip32xx now checks
whether an I/O access is unaligned and if so, it uses the correct
semaphore. (BZ#1125776)

* A series of patches has been backported to improve the functionality of
a touch pad on the latest Lenovo laptops in Red Hat Enterprise Linux 7.
(BZ#1122559)

* Due to a bug in the bnx2x driver, a network adapter could be unable to
recover from EEH error injection. The network adapter had to be taken
offline and rebooted in order to function properly again. With this update,
the bnx2x driver has been corrected and network adapters now recover from
EEH errors as expected. (BZ#1107722)

* Previously, if an hrtimer interrupt was delayed, all future pending
hrtimer events that were queued on the same processor were also delayed
until the initial hrtimer event was handled. This could cause all hrtimer
processing to stop for a significant period of time. To prevent this
problem, the kernel has been modified to handle all expired hrtimer events
when handling the initially delayed hrtimer event. (BZ#1113175)

* A previous change to the nouveau driver introduced a bit shift error,
which resulted in a wrong display resolution being set with some models
of NVIDIA controllers. With this update, the erroneous code has been
corrected, and the affected NVIDIA controllers can now set the correct
display resolution. (BZ#1114869)

* Due to a NULL pointer dereference bug in the be2net driver, the system
could experience a kernel oops and reboot when disabling a network adapter
after a permanent failure. This problem has been fixed by introducing a
flag to keep track of the setup state. The failing adapter can now be
disabled successfully without a kernel crash. (BZ#1122558)

* Previously, the Huge Translation Lookaside Buffer (HugeTLB) allowed
access to huge pages access by default. However, huge pages may be
unsupported in some environments, such as a KVM guest on a PowerPC
architecture, and an attempt to access a huge page in memory would result
in a kernel oops. This update ensures that HugeTLB denies access to huge
pages if the huge pages are not supported on the system. (BZ#1122115)

* If an NVMe device becomes ready but fails to create I/O queues, the nvme
driver creates a character device handle to manage such a device.
Previously, a character device could be created before a device reference
counter was initialized, which resulted in a kernel oops. This problem has
been fixed by calling the relevant initialization function earlier in the
code. (BZ#1119720)

* On some firmware versions of the BladeEngine 3 (BE3) controller,
interrupts remain disabled after a hardware reset. This was a problem for
all Emulex-based network adapters using such a BE3 controller because
these adapters would fail to recover from an EEH error if it occurred. To
resolve this problem, the be2net driver has been modified to enable the
interrupts in the eeh_resume handler explicitly. (BZ#1121712)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1281</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3917</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141281"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141292" severity="medium">
    <xccdf:title>RHSA-2014:1292: haproxy security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HAProxy provides high availability, load balancing, and proxying for TCP
and HTTP-based applications.

A buffer overflow flaw was discovered in the way HAProxy handled, under
very specific conditions, data uploaded from a client. A remote attacker
could possibly use this flaw to crash HAProxy. (CVE-2014-6269)

All haproxy users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6269</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141292"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141293" severity="high">
    <xccdf:title>RHSA-2014:1293: bash security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

A flaw was found in the way Bash evaluated certain specially crafted
environment variables. An attacker could use this flaw to override or
bypass environment restrictions to execute shell commands. Certain
services and applications allow remote unauthenticated attackers to
provide environment variables, allowing them to exploit this issue.
(CVE-2014-6271)

For additional information on the CVE-2014-6271 flaw, refer to the
Knowledgebase article at https://access.redhat.com/articles/1200223

Red Hat would like to thank Stephane Chazelas for reporting this issue.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6271</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141293"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141306" severity="high">
    <xccdf:title>RHSA-2014:1306: bash security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

It was found that the fix for CVE-2014-6271 was incomplete, and Bash still
allowed certain characters to be injected into other environments via
specially crafted environment variables. An attacker could potentially use
this flaw to override or bypass environment restrictions to execute shell
commands. Certain services and applications allow remote unauthenticated
attackers to provide environment variables, allowing them to exploit this
issue. (CVE-2014-7169)

Applications which directly create bash functions as environment variables
need to be made aware of changes to the way names are handled by this
update. Note that certain services, screen sessions, and tmux sessions may
need to be restarted, and affected interactive users may need to re-login.
Installing these updated packages without restarting services will address
the vulnerability, but functionality may be impacted until affected
services are restarted. For more information see the Knowledgebase article
at https://access.redhat.com/articles/1200223

Note: Docker users are advised to use "yum update" within their containers,
and to commit the resulting changes.

For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the
aforementioned Knowledgebase article.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1306</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7169</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7187</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141306"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141307" severity="high">
    <xccdf:title>RHSA-2014:1307: nss security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One)
input from certain RSA signatures. A remote attacker could use this flaw to
forge RSA certificates by providing a specially crafted signature to an
application using NSS. (CVE-2014-1568)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Antoine Delignat-Lavaud and Intel Product Security
Incident Response Team as the original reporters.

All NSS users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, applications using NSS must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1568</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141307"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141319" severity="medium">
    <xccdf:title>RHSA-2014:1319: xerces-j2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Xerces for Java (Xerces-J) is a high performance, standards
compliant, validating XML parser written in Java. The xerces-j2 packages
provide Xerces-J version 2.

A resource consumption issue was found in the way Xerces-J handled XML
declarations. A remote attacker could use an XML document with a specially
crafted declaration using a long pseudo-attribute name that, when parsed by
an application using Xerces-J, would cause that application to use an
excessive amount of CPU. (CVE-2013-4002)

All xerces-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using the
Xerces-J must be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1319</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4002</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141319"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141326" severity="medium">
    <xccdf:title>RHSA-2014:1326: php53 and php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

It was found that the fix for CVE-2012-1571 was incomplete; the File
Information (fileinfo) extension did not correctly parse certain Composite
Document Format (CDF) files. A remote attacker could use this flaw to crash
a PHP application using fileinfo via a specially crafted CDF file.
(CVE-2014-3587)

A NULL pointer dereference flaw was found in the gdImageCreateFromXpm()
function of PHP's gd extension. A remote attacker could use this flaw to
crash a PHP application using gd via a specially crafted X PixMap (XPM)
file. (CVE-2014-2497)

Multiple buffer over-read flaws were found in the php_parserr() function of
PHP. A malicious DNS server or a man-in-the-middle attacker could possibly
use this flaw to execute arbitrary code as the PHP interpreter if a PHP
application used the dns_get_record() function to perform a DNS query.
(CVE-2014-3597)

Two use-after-free flaws were found in the way PHP handled certain Standard
PHP Library (SPL) Iterators and ArrayIterators. A malicious script author
could possibly use either of these flaws to disclose certain portions of
server memory. (CVE-2014-4670, CVE-2014-4698)

The CVE-2014-3597 issue was discovered by David Kutálek of the Red Hat
BaseOS QE.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1326</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141326"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141327" severity="medium">
    <xccdf:title>RHSA-2014:1327: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

A buffer overflow flaw was found in the way the File Information (fileinfo)
extension processed certain Pascal strings. A remote attacker able to make
a PHP application using fileinfo convert a specially crafted Pascal string
provided by an image file could cause that application to crash.
(CVE-2014-3478)

Multiple flaws were found in the File Information (fileinfo) extension
regular expression rules for detecting various files. A remote attacker
could use either of these flaws to cause a PHP application using fileinfo
to consume an excessive amount of CPU. (CVE-2014-3538)

It was found that the fix for CVE-2012-1571 was incomplete; the File
Information (fileinfo) extension did not correctly parse certain Composite
Document Format (CDF) files. A remote attacker could use this flaw to crash
a PHP application using fileinfo via a specially crafted CDF file.
(CVE-2014-3587)

It was found that PHP's gd extension did not properly handle file names
with a null character. A remote attacker could possibly use this flaw to
make a PHP application access unexpected files and bypass intended file
system access restrictions. (CVE-2014-5120)

A NULL pointer dereference flaw was found in the gdImageCreateFromXpm()
function of PHP's gd extension. A remote attacker could use this flaw to
crash a PHP application using gd via a specially crafted X PixMap (XPM)
file. (CVE-2014-2497)

Multiple buffer over-read flaws were found in the php_parserr() function of
PHP. A malicious DNS server or a man-in-the-middle attacker could possibly
use this flaw to execute arbitrary code as the PHP interpreter if a PHP
application used the dns_get_record() function to perform a DNS query.
(CVE-2014-3597)

Two use-after-free flaws were found in the way PHP handled certain Standard
PHP Library (SPL) Iterators and ArrayIterators. A malicious script author
could possibly use either of these flaws to disclose certain portions of
server memory. (CVE-2014-4670, CVE-2014-4698)

The CVE-2014-3478 issue was discovered by Francisco Alonso of Red Hat
Product Security, the CVE-2014-3538 issue was discovered by Jan Kaluža of
the Red Hat Web Stack Team, and the CVE-2014-3597 issue was discovered by
David Kutálek of the Red Hat BaseOS QE.

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3597</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4698</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5120</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141352" severity="medium">
    <xccdf:title>RHSA-2014:1352: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

An out-of-bounds read flaw was found in the way libvirt's
qemuDomainGetBlockIoTune() function looked up the disk index in a
non-persistent (live) disk configuration while a persistent disk
configuration was being indexed. A remote attacker able to establish a
read-only connection to libvirtd could use this flaw to crash libvirtd or,
potentially, leak memory from the libvirtd process. (CVE-2014-3633)

A denial of service flaw was found in the way libvirt's
virConnectListAllDomains() function computed the number of used domains.
A remote attacker able to establish a read-only connection to libvirtd
could use this flaw to make any domain operations within libvirt
unresponsive. (CVE-2014-3657)

The CVE-2014-3633 issue was discovered by Luyao Huang of Red Hat.

This update also fixes the following bug:

* Prior to this update, libvirt was setting the cpuset.mems parameter for
domains with numatune/memory[nodeset] prior to starting them. As a
consequence, domains with such a nodeset, which excluded the NUMA node with
DMA and DMA32 zones (found in /proc/zoneinfo), could not be started due to
failed KVM initialization. With this update, libvirt sets the cpuset.mems
parameter after the initialization, and domains with any nodeset (in
/numatune/memory) can be started without an error. (BZ#1135871)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3657</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141352"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141359" severity="high">
    <xccdf:title>RHSA-2014:1359: polkit-qt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Polkit-qt is a library that lets developers use the PolicyKit API through a
Qt-styled API. The polkit-qt library is used by the KDE Authentication
Agent (KAuth), which is a part of kdelibs.

It was found that polkit-qt handled authorization requests with PolicyKit
via a D-Bus API that is vulnerable to a race condition. A local user could
use this flaw to bypass intended PolicyKit authorizations. This update
modifies polkit-qt to communicate with PolicyKit via a different API that
is not vulnerable to the race condition. (CVE-2014-5033)

All polkit-qt users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1359</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5033</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141359"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141388" severity="medium">
    <xccdf:title>RHSA-2014:1388: cups security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>CUPS provides a portable printing layer for Linux, UNIX, and similar
operating systems.

A cross-site scripting (XSS) flaw was found in the CUPS web interface.
An attacker could use this flaw to perform a cross-site scripting attack
against users of the CUPS web interface. (CVE-2014-2856)

It was discovered that CUPS allowed certain users to create symbolic links
in certain directories under /var/cache/cups/. A local user with the 'lp'
group privileges could use this flaw to read the contents of arbitrary
files on the system or, potentially, escalate their privileges on the
system. (CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031)

The CVE-2014-3537 issue was discovered by Francisco Alonso of Red Hat
Product Security.

These updated cups packages also include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.6 Technical Notes, linked to in the
References section, for information on the most significant of these
changes.

All cups users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1388</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2856</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3537</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5029</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5030</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5031</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141388"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141389" severity="medium">
    <xccdf:title>RHSA-2014:1389: krb5 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a networked authentication system which allows clients and
servers to authenticate to each other with the help of a trusted third
party, the Kerberos KDC.

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

Two buffer over-read flaws were found in the way MIT Kerberos handled
certain requests. A remote, unauthenticated attacker who is able to inject
packets into a client or server application's GSSAPI session could use
either of these flaws to crash the application. (CVE-2014-4341,
CVE-2014-4342)

A double-free flaw was found in the MIT Kerberos SPNEGO initiators.
An attacker able to spoof packets to appear as though they are from an
GSSAPI acceptor could use this flaw to crash a client application that uses
MIT Kerberos. (CVE-2014-4343)

These updated krb5 packages also include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.6 Technical Notes, linked to in the
References section, for information on the most significant of these
changes.

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1418</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4345</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141389"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141390" severity="medium">
    <xccdf:title>RHSA-2014:1390: luci security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Luci is a web-based high availability administration application.

It was discovered that luci used eval() on inputs containing strings from
the cluster configuration file when generating its web pages. An attacker
with privileges to create or edit the cluster configuration could use this
flaw to execute arbitrary code as the luci user on a host running luci.
(CVE-2014-3593)

This issue was discovered by Jan Pokorný of Red Hat.

These updated luci packages also include several bug fixes and multiple
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.6 Technical
Notes, linked to in the References section, for information on the most
significant of these changes.

All luci users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1390</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3593</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141390"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141391" severity="medium">
    <xccdf:title>RHSA-2014:1391: glibc security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

An out-of-bounds write flaw was found in the way the glibc's readdir_r()
function handled file system entries longer than the NAME_MAX character
constant. A remote attacker could provide a specially crafted NTFS or CIFS
file system that, when processed by an application using readdir_r(), would
cause that application to crash or, potentially, allow the attacker to
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-4237)

It was found that getaddrinfo() did not limit the amount of stack memory
used during name resolution. An attacker able to make an application
resolve an attacker-controlled hostname or IP address could possibly cause
the application to exhaust all stack memory and crash. (CVE-2013-4458)

These updated glibc packages also include several bug fixes and two
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.6 Technical
Notes, linked to in the References section, for information on the most
significant of these changes.

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7424</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141391"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141392" severity="high">
    <xccdf:title>RHSA-2014:1392: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A NULL pointer dereference flaw was found in the way the Linux kernel's
Stream Control Transmission Protocol (SCTP) implementation handled
simultaneous connections between the same hosts. A remote attacker could
use this flaw to crash the system. (CVE-2014-5077, Important)

* An integer overflow flaw was found in the way the Linux kernel's Frame
Buffer device implementation mapped kernel memory to user space via the
mmap syscall. A local user able to access a frame buffer device file
(/dev/fb*) could possibly use this flaw to escalate their privileges on the
system. (CVE-2013-2596, Important)

* A flaw was found in the way the ipc_rcu_putref() function in the Linux
kernel's IPC implementation handled reference counter decrementing.
A local, unprivileged user could use this flaw to trigger an Out of Memory
(OOM) condition and, potentially, crash the system. (CVE-2013-4483,
Moderate)

* It was found that the permission checks performed by the Linux kernel
when a netlink message was received were not sufficient. A local,
unprivileged user could potentially bypass these restrictions by passing a
netlink socket as stdout or stderr to a more privileged process and
altering the output of this process. (CVE-2014-0181, Moderate)

* It was found that the try_to_unmap_cluster() function in the Linux
kernel's Memory Managment subsystem did not properly handle page locking in
certain cases, which could potentially trigger the BUG_ON() macro in the
mlock_vma_page() function. A local, unprivileged user could use this flaw
to crash the system. (CVE-2014-3122, Moderate)

* A flaw was found in the way the Linux kernel's kvm_iommu_map_pages()
function handled IOMMU mapping failures. A privileged user in a guest with
an assigned host device could use this flaw to crash the host.
(CVE-2014-3601, Moderate)

* Multiple use-after-free flaws were found in the way the Linux kernel's
Advanced Linux Sound Architecture (ALSA) implementation handled user
controls. A local, privileged user could use either of these flaws to crash
the system. (CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, Moderate)

* A flaw was found in the way the Linux kernel's VFS subsystem handled
reference counting when performing unmount operations on symbolic links.
A local, unprivileged user could use this flaw to exhaust all available
memory on the system or, potentially, trigger a use-after-free error,
resulting in a system crash or privilege escalation. (CVE-2014-5045,
Moderate)

* An integer overflow flaw was found in the way the lzo1x_decompress_safe()
function of the Linux kernel's LZO implementation processed Literal Runs.
A local attacker could, in extremely rare cases, use this flaw to crash the
system or, potentially, escalate their privileges on the system.
(CVE-2014-4608, Low)

Red Hat would like to thank Vladimir Davydov of Parallels for reporting
CVE-2013-4483, Jack Morgenstein of Mellanox for reporting CVE-2014-3601,
Vasily Averin of Parallels for reporting CVE-2014-5045, and Don A.
Bailey from Lab Mouse Security for reporting CVE-2014-4608. The security
impact of the CVE-2014-3601 issue was discovered by Michael Tsirkin of
Red Hat.

This update also fixes several hundred bugs and adds numerous enhancements.
Refer to the Red Hat Enterprise Linux 6.6 Release Notes for information on
the most significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.6 Release Notes and
Technical Notes. The system must be rebooted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1392</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6689</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-4483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3122</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4608</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4653</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5077</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141392"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141397" severity="high">
    <xccdf:title>RHSA-2014:1397: rsyslog security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rsyslog packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon or, potentially, execute arbitrary code as the user running
the rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the rsyslog service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1397</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3634</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141397"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141436" severity="medium">
    <xccdf:title>RHSA-2014:1436: X11 client libraries security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The X11 (Xorg) libraries provide library routines that are used within all
X Window applications.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way various X11 client libraries handled certain protocol
data. An attacker able to submit invalid protocol data to an X11 server via
a malicious X11 client could use either of these flaws to potentially
escalate their privileges on the system. (CVE-2013-1981, CVE-2013-1982,
CVE-2013-1983, CVE-2013-1984, CVE-2013-1985, CVE-2013-1986, CVE-2013-1987,
CVE-2013-1988, CVE-2013-1989, CVE-2013-1990, CVE-2013-1991, CVE-2013-2003,
CVE-2013-2062, CVE-2013-2064)

Multiple array index errors, leading to heap-based buffer out-of-bounds
write flaws, were found in the way various X11 client libraries handled
data returned from an X11 server. A malicious X11 server could possibly use
this flaw to execute arbitrary code with the privileges of the user running
an X11 client. (CVE-2013-1997, CVE-2013-1998, CVE-2013-1999, CVE-2013-2000,
CVE-2013-2001, CVE-2013-2002, CVE-2013-2066)

A buffer overflow flaw was found in the way the XListInputDevices()
function of X.Org X11's libXi runtime library handled signed numbers.
A malicious X11 server could possibly use this flaw to execute arbitrary
code with the privileges of the user running an X11 client. (CVE-2013-1995)

A flaw was found in the way the X.Org X11 libXt runtime library used
uninitialized pointers. A malicious X11 server could possibly use this flaw
to execute arbitrary code with the privileges of the user running an X11
client. (CVE-2013-2005)

Two stack-based buffer overflow flaws were found in the way libX11, the
Core X11 protocol client library, processed certain user-specified files.
A malicious X11 server could possibly use this flaw to crash an X11 client
via a specially crafted file. (CVE-2013-2004)

The xkeyboard-config package has been upgraded to upstream version 2.11,
which provides a number of bug fixes and enhancements over the previous
version. (BZ#1077471)

This update also fixes the following bugs:

* Previously, updating the mesa-libGL package did not update the libX11
package, although it was listed as a dependency of mesa-libGL. This bug has
been fixed and updating mesa-libGL now updates all dependent packages as
expected. (BZ#1054614)

* Previously, closing a customer application could occasionally cause the X
Server to terminate unexpectedly. After this update, the X Server no longer
hangs when a user closes a customer application. (BZ#971626)

All X11 client libraries users are advised to upgrade to these updated
packages, which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1436</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1984</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1985</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1987</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1989</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1992</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1995</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2004</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2062</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7439</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141436"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141507" severity="low">
    <xccdf:title>RHSA-2014:1507: trousers security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>TrouSerS is an implementation of the Trusted Computing Group's Software
Stack (TSS) specification. You can use TrouSerS to write applications that
make use of your TPM hardware. TPM hardware can create, store and use RSA
keys securely (without ever being exposed in memory), verify a platform's
software state using cryptographic hashes and more.

A flaw was found in the way tcsd, the daemon that manages Trusted Computing
resources, processed incoming TCP packets. A remote attacker could send a
specially crafted TCP packet that, when processed by tcsd, could cause the
daemon to crash. Note that by default tcsd accepts requests on localhost
only. (CVE-2012-0698)

Red Hat would like to thank Andrew Lutomirski for reporting this issue.

The trousers package has been upgraded to upstream version 0.3.13, which
provides a number of bug fixes and enhancements over the previous version,
including corrected internal symbol names to avoid collisions with other
applications, fixed memory leaks, added IPv6 support, fixed buffer handling
in tcsd, as well as changed the license to BSD. (BZ#633584, BZ#1074634)

All trousers users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-0698</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141507"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141552" severity="medium">
    <xccdf:title>RHSA-2014:1552: openssh security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation.
These packages include the core files necessary for both the OpenSSH client
and server.

It was discovered that OpenSSH clients did not correctly verify DNS SSHFP
records. A malicious server could use this flaw to force a connecting
client to skip the DNS SSHFP record check and require the user to perform
manual host verification of the DNS SSHFP record. (CVE-2014-2653)

It was found that OpenSSH did not properly handle certain AcceptEnv
parameter values with wildcard characters. A remote attacker could use this
flaw to bypass intended environment variable restrictions. (CVE-2014-2532)

This update also fixes the following bugs:

* Based on the SP800-131A information security standard, the generation of
a digital signature using the Digital Signature Algorithm (DSA) with the
key size of 1024 bits and RSA with the key size of less than 2048 bits is
disallowed after the year 2013. After this update, ssh-keygen no longer
generates keys with less than 2048 bits in FIPS mode. However, the sshd
service accepts keys of size 1024 bits as well as larger keys for
compatibility reasons. (BZ#993580)

* Previously, the openssh utility incorrectly set the oom_adj value to -17
for all of its children processes. This behavior was incorrect because the
children processes were supposed to have this value set to 0. This update
applies a patch to fix this bug and oom_adj is now properly set to 0 for
all children processes as expected. (BZ#1010429)

* Previously, if the sshd service failed to verify the checksum of an
installed FIPS module using the fipscheck library, the information about
this failure was only provided at the standard error output of sshd. As a
consequence, the user could not notice this message and be uninformed when
a system had not been properly configured for FIPS mode. To fix this bug,
this behavior has been changed and sshd now sends such messages via the
syslog service. (BZ#1020803)

* When keys provided by the pkcs11 library were removed from the ssh agent
using the "ssh-add -e" command, the user was prompted to enter a PIN.
With this update, a patch has been applied to allow the user to remove the
keys provided by pkcs11 without the PIN. (BZ#1042519)

In addition, this update adds the following enhancements:

* With this update, ControlPersist has been added to OpenSSH. The option in
conjunction with the ControlMaster configuration directive specifies that
the master connection remains open in the background after the initial
client connection has been closed. (BZ#953088)

* When the sshd daemon is configured to force the internal SFTP session,
and the user attempts to use a connection other than SFTP, the appropriate
message is logged to the /var/log/secure file. (BZ#997377)

* Support for Elliptic Curve Cryptography modes for key exchange (ECDH) and
host user keys (ECDSA) as specified by RFC5656 has been added to the
openssh packages. However, they are not enabled by default and the user has
to enable them manually. For more information on how to configure ECDSA and
ECDH with OpenSSH, see: https://access.redhat.com/solutions/711953
(BZ#1028335)

All openssh users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2653</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141552"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141606" severity="medium">
    <xccdf:title>RHSA-2014:1606: file security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The "file" command is used to identify a particular file according to the
type of data contained in the file. The command can identify various file
types, including ELF binaries, system libraries, RPM packages, and
different graphics formats.

Multiple denial of service flaws were found in the way file parsed certain
Composite Document Format (CDF) files. A remote attacker could use either
of these flaws to crash file, or an application using file, via a specially
crafted CDF file. (CVE-2014-0237, CVE-2014-0238, CVE-2014-3479,
CVE-2014-3480, CVE-2012-1571)

Two denial of service flaws were found in the way file handled indirect and
search rules. A remote attacker could use either of these flaws to cause
file, or an application using file, to crash or consume an excessive amount
of CPU. (CVE-2014-1943, CVE-2014-2270)

This update also fixes the following bugs:

* Previously, the output of the "file" command contained redundant white
spaces. With this update, the new STRING_TRIM flag has been introduced to
remove the unnecessary white spaces. (BZ#664513)

* Due to a bug, the "file" command could incorrectly identify an XML
document as a LaTex document. The underlying source code has been modified
to fix this bug and the command now works as expected. (BZ#849621)

* Previously, the "file" command could not recognize .JPG files and
incorrectly labeled them as "Minix filesystem". This bug has been fixed and
the command now properly detects .JPG files. (BZ#873997)

* Under certain circumstances, the "file" command incorrectly detected
NETpbm files as "x86 boot sector". This update applies a patch to fix this
bug and the command now detects NETpbm files as expected. (BZ#884396)

* Previously, the "file" command incorrectly identified ASCII text files as
a .PIC image file. With this update, a patch has been provided to address
this bug and the command now correctly recognizes ASCII text files.
(BZ#980941)

* On 32-bit PowerPC systems, the "from" field was missing from the output
of the "file" command. The underlying source code has been modified to fix
this bug and "file" output now contains the "from" field as expected.
(BZ#1037279)

* The "file" command incorrectly detected text files as "RRDTool DB version
ool - Round Robin Database Tool". This update applies a patch to fix this
bug and the command now correctly detects text files. (BZ#1064463)

* Previously, the "file" command supported only version 1 and 2 of the QCOW
format. As a consequence, file was unable to detect a "qcow2 compat=1.1"
file created on Red Hat Enterprise Linux 7. With this update, support for
QCOW version 3 has been added so that the command now detects such files as
expected. (BZ#1067771)

All file users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1606</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-1571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2270</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3480</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141606"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141620" severity="high">
    <xccdf:title>RHSA-2014:1620: java-1.7.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141620"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141633" severity="high">
    <xccdf:title>RHSA-2014:1633: java-1.7.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141633"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141634" severity="high">
    <xccdf:title>RHSA-2014:1634: java-1.6.0-openjdk security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141634"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141635" severity="high">
    <xccdf:title>RHSA-2014:1635: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576,
CVE-2014-1577)

A flaw was found in the Alarm API, which allows applications to schedule
actions to be run in the future. A malicious web application could use this
flaw to bypass cross-origin restrictions. (CVE-2014-1583)

Red Hat would like to thank the Mozilla project for reporting these issues. 
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron 
Campen Jon Coppeard, Atte Kettunen, Holger Fuhrmannek, Abhishek Arya, 
regenrecht, and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.2.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.2.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1635</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1576</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1583</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141635"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141636" severity="high">
    <xccdf:title>RHSA-2014:1636: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

It was discovered that the Libraries component in OpenJDK failed to
properly handle ZIP archives that contain entries with a NUL byte used in
the file names. An untrusted Java application or applet could use this flaw
to bypass Java sandbox restrictions. (CVE-2014-6562)

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the Hotspot component in OpenJDK failed to properly
handle malformed Shared Archive files. A local attacker able to modify a
Shared Archive file used by a virtual machine of a different user could
possibly use this flaw to escalate their privileges. (CVE-2014-6468)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1636</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6468</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6562</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141636"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141647" severity="high">
    <xccdf:title>RHSA-2014:1647: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1577)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron
Campen Jon Coppeard, Holger Fuhrmannek, Abhishek Arya, and regenrecht as
the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.2.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.2.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1574</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1577</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1578</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1581</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141647"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141652" severity="high">
    <xccdf:title>RHSA-2014:1652: openssl security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

This update adds support for the TLS Fallback Signaling Cipher Suite Value
(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade
attacks against applications which re-connect using a lower SSL/TLS
protocol version when the initial connection indicating the highest
supported protocol version fails.

This can prevent a forceful downgrade of the communication to SSL 3.0.
The SSL 3.0 protocol was found to be vulnerable to the padding oracle
attack when using block cipher suites in cipher block chaining (CBC) mode.
This issue is identified as CVE-2014-3566, and also known under the alias
POODLE. This SSL 3.0 protocol flaw will not be addressed in a future
update; it is recommended that users configure their applications to
require at least TLS protocol version 1.0 for secure communication.

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1232123

A memory leak flaw was found in the way OpenSSL parsed the DTLS Secure
Real-time Transport Protocol (SRTP) extension data. A remote attacker could
send multiple specially crafted handshake messages to exhaust all available
memory of an SSL/TLS or DTLS server. (CVE-2014-3513)

A memory leak flaw was found in the way an OpenSSL handled failed session
ticket integrity checks. A remote attacker could exhaust all available
memory of an SSL/TLS or DTLS server by sending a large number of invalid
session tickets to that server. (CVE-2014-3567)

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to mitigate the CVE-2014-3566 issue and correct
the CVE-2014-3513 and CVE-2014-3567 issues. For the update to take effect,
all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3567</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141652"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141654" severity="high">
    <xccdf:title>RHSA-2014:1654: rsyslog7 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rsyslog7 packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon or, potentially, execute arbitrary code as the user running
the rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog7 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the rsyslog service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3634</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141654"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141655" severity="medium">
    <xccdf:title>RHSA-2014:1655: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in libxml2, a library providing support
to read, modify and write XML and HTML files. A remote attacker could
provide a specially crafted XML file that, when processed by an application
using libxml2, would lead to excessive CPU consumption (denial of service)
based on excessive entity substitutions, even if entity substitution was
disabled, which is the parser default behavior. (CVE-2014-3660)

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3660</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141655"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141657" severity="high">
    <xccdf:title>RHSA-2014:1657: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6456, CVE-2014-6457, CVE-2014-6458, CVE-2014-6476,
CVE-2014-6492, CVE-2014-6493, CVE-2014-6502, CVE-2014-6503, CVE-2014-6504,
CVE-2014-6506, CVE-2014-6511, CVE-2014-6512, CVE-2014-6515, CVE-2014-6517,
CVE-2014-6519, CVE-2014-6527, CVE-2014-6531, CVE-2014-6532, CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 72 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6456</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6476</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6527</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141657"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141658" severity="high">
    <xccdf:title>RHSA-2014:1658: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6457, CVE-2014-6458, CVE-2014-6492, CVE-2014-6493,
CVE-2014-6502, CVE-2014-6503, CVE-2014-6504, CVE-2014-6506, CVE-2014-6511,
CVE-2014-6512, CVE-2014-6515, CVE-2014-6517, CVE-2014-6531, CVE-2014-6532,
CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 85 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6493</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6512</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6531</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6532</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6558</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141658"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141669" severity="low">
    <xccdf:title>RHSA-2014:1669: qemu-kvm security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An information leak flaw was found in the way QEMU's VGA emulator accessed
frame buffer memory for high resolution displays. A privileged guest user
could use this flaw to leak memory contents of the host to the guest by
setting the display to use a high resolution in the guest. (CVE-2014-3615)

This issue was discovered by Laszlo Ersek of Red Hat.

This update also fixes the following bug:

* This update fixes a regression in the scsi_block_new_request() function,
which caused all read requests to through SG_IO if the host cache was not
used. (BZ#1141189)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3615</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141669"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141671" severity="medium">
    <xccdf:title>RHSA-2014:1671: rsyslog5 and rsyslog security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rsyslog packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog5 and rsyslog users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, the rsyslog service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3634</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141671"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141676" severity="medium">
    <xccdf:title>RHSA-2014:1676: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2014-6429, CVE-2014-6430, CVE-2014-6431, CVE-2014-6432)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2014-6421, CVE-2014-6422, CVE-2014-6423,
CVE-2014-6424, CVE-2014-6425, CVE-2014-6426, CVE-2014-6427, CVE-2014-6428)

All wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6426</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6427</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6432</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141676"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141677" severity="medium">
    <xccdf:title>RHSA-2014:1677: wireshark security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2014-6429, CVE-2014-6430, CVE-2014-6431, CVE-2014-6432)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2014-6421, CVE-2014-6422, CVE-2014-6423,
CVE-2014-6425, CVE-2014-6428)

All wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1677</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6428</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6429</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6431</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6432</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141677"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141724" severity="high">
    <xccdf:title>RHSA-2014:1724: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* A race condition flaw was found in the way the Linux kernel's KVM
subsystem handled PIT (Programmable Interval Timer) emulation. A guest user
who has access to the PIT I/O ports could use this flaw to crash the host.
(CVE-2014-3611, Important)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
Stream Control Transmission Protocol (SCTP) implementation handled
simultaneous connections between the same hosts. A remote attacker could
use this flaw to crash the system. (CVE-2014-5077, Important)

* It was found that the Linux kernel's KVM subsystem did not handle the VM
exits gracefully for the invept (Invalidate Translations Derived from EPT)
and invvpid (Invalidate Translations Based on VPID) instructions. On hosts
with an Intel processor and invept/invppid VM exit support, an unprivileged
guest user could use these instructions to crash the guest. (CVE-2014-3645,
CVE-2014-3646, Moderate)

* A use-after-free flaw was found in the way the Linux kernel's Advanced
Linux Sound Architecture (ALSA) implementation handled user controls. A
local, privileged user could use this flaw to crash the system.
(CVE-2014-4653, Moderate)

Red Hat would like to thank Lars Bull of Google for reporting
CVE-2014-3611, and the Advanced Threat Research team at Intel Security for
reporting CVE-2014-3645 and CVE-2014-3646.

Bug fixes:

* A known issue that could prevent Chelsio adapters using the cxgb4 driver
from being initialized on IBM POWER8 systems has been fixed. These
adapters can now be used on IBM POWER8 systems as expected. (BZ#1130548)

* When bringing a hot-added CPU online, the kernel did not initialize a
CPU mask properly, which could result in a kernel panic. This update
corrects the bug by ensuring that the CPU mask is properly initialized and
the correct NUMA node selected. (BZ#1134715)

* The kernel could fail to bring a CPU online if the hardware supported
both, the acpi-cpufreq and intel_pstate modules. This update ensures that
the acpi-cpufreq module is not loaded in the intel_pstate module is
loaded. (BZ#1134716)

* Due to a bug in the time accounting of the kernel scheduler, a divide
error could occur when hot adding a CPU. To fix this problem, the kernel
scheduler time accounting has been reworked. (BZ#1134717)

* The kernel did not handle exceptions caused by an invalid floating point
control (FPC) register, resulting in a kernel oops. This problem has been
fixed by placing the label to handle these exceptions to the correct place
in the code. (BZ#1138733)

* A previous change to the kernel for the PowerPC architecture changed
implementation of the compat_sys_sendfile() function. Consequently, the
64-bit sendfile() system call stopped working for files larger than 2 GB
on PowerPC. This update restores previous behavior of sendfile() on
PowerPC, and it again process files bigger than 2 GB as expected.
(BZ#1139126)

* Previously, the kernel scheduler could schedule a CPU topology update
even though the topology did not change. This could negatively affect the
CPU load balancing, cause degradation of the system performance, and
eventually result in a kernel oops. This problem has been fixed by
skipping the CPU topology update if the topology has not actually changed.
(BZ#1140300)

* Previously, recovery of a double-degraded RAID6 array could, under
certain circumstances, result in data corruption. This could happen
because the md driver was using an optimization that is safe to use only
for single-degraded arrays. This update ensures that this optimization is
skipped during the recovery of double-degraded RAID6 arrays. (BZ#1143850)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3611</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3645</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3646</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4653</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5077</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141724"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141764" severity="medium">
    <xccdf:title>RHSA-2014:1764: wget security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wget package provides the GNU Wget file retrieval utility for HTTP,
HTTPS, and FTP protocols.

A flaw was found in the way Wget handled symbolic links. A malicious FTP
server could allow Wget running in the mirror mode (using the '-m' command
line option) to write an arbitrary file to a location writable to by the
user running Wget, possibly leading to code execution. (CVE-2014-4877)

Note: This update changes the default value of the --retr-symlinks option.
The file symbolic links are now traversed by default and pointed-to files
are retrieved rather than creating a symbolic link locally.

Red Hat would like to thank the GNU Wget project for reporting this issue.
Upstream acknowledges HD Moore of Rapid7, Inc as the original reporter.

All users of wget are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1764</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4877</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141764"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141767" severity="high">
    <xccdf:title>RHSA-2014:1767: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

An out-of-bounds read flaw was found in the way the File Information
(fileinfo) extension parsed Executable and Linkable Format (ELF) files.
A remote attacker could use this flaw to crash a PHP application using
fileinfo via a specially crafted ELF file. (CVE-2014-3710)

An out of bounds read flaw was found in the way the xmlrpc extension parsed
dates in the ISO 8601 format. A specially crafted XML-RPC request or
response could possibly cause a PHP application to crash. (CVE-2014-3668)

The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat
Product Security.

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3668</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3710</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141767"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141768" severity="high">
    <xccdf:title>RHSA-2014:1768: php53 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

An out-of-bounds read flaw was found in the way the File Information
(fileinfo) extension parsed Executable and Linkable Format (ELF) files.
A remote attacker could use this flaw to crash a PHP application using
fileinfo via a specially crafted ELF file. (CVE-2014-3710)

An out of bounds read flaw was found in the way the xmlrpc extension parsed
dates in the ISO 8601 format. A specially crafted XML-RPC request or
response could possibly cause a PHP application to crash. (CVE-2014-3668)

The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat
Product Security.

All php53 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1768</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3668</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3710</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141768"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141795" severity="medium">
    <xccdf:title>RHSA-2014:1795: cups-filters security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cups-filters package contains backends, filters, and other software
that was once part of the core CUPS distribution but is now maintained
independently.

An out-of-bounds read flaw was found in the way the process_browse_data()
function of cups-browsed handled certain browse packets. A remote attacker
could send a specially crafted browse packet that, when processed by
cups-browsed, would crash the cups-browsed daemon. (CVE-2014-4337)

A flaw was found in the way the cups-browsed daemon interpreted the
"BrowseAllow" directive in the cups-browsed.conf file. An attacker able to
add a malformed "BrowseAllow" directive to the cups-browsed.conf file could
use this flaw to bypass intended access restrictions. (CVE-2014-4338)

All cups-filters users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the cups-browsed daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1795</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4337</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4338</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141795"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141801" severity="medium">
    <xccdf:title>RHSA-2014:1801: shim security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Shim is the initial UEFI bootloader that handles chaining to a trusted full
bootloader under secure boot environments.

A heap-based buffer overflow flaw was found the way shim parsed certain
IPv6 addresses. If IPv6 network booting was enabled, a malicious server
could supply a crafted IPv6 address that would cause shim to crash or,
potentially, execute arbitrary code. (CVE-2014-3676)

An out-of-bounds memory write flaw was found in the way shim processed
certain Machine Owner Keys (MOKs). A local attacker could potentially use
this flaw to execute arbitrary code on the system. (CVE-2014-3677)

An out-of-bounds memory read flaw was found in the way shim parsed certain
IPv6 packets. A specially crafted DHCPv6 packet could possibly cause shim
to crash, preventing the system from booting if IPv6 booting was enabled.
(CVE-2014-3675)

Red Hat would like to thank the SUSE Security Team for reporting these
issues.

All shim users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3675</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3676</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3677</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141801"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141803" severity="high">
    <xccdf:title>RHSA-2014:1803: mod_auth_mellon security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>mod_auth_mellon provides a SAML 2.0 authentication module for the Apache
HTTP Server.

An information disclosure flaw was found in mod_auth_mellon's session
handling that could lead to sessions overlapping in memory. A remote
attacker could potentially use this flaw to obtain data from another user's
session. (CVE-2014-8566)

It was found that uninitialized data could be read when processing a user's
logout request. By attempting to log out, a user could possibly cause the
Apache HTTP Server to crash. (CVE-2014-8567)

Red Hat would like to thank the mod_auth_mellon team for reporting these
issues. Upstream acknowledges Matthew Slowe as the original reporter of
CVE-2014-8566.

All users of mod_auth_mellon are advised to upgrade to this updated
package, which contains a backported patch to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8567</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141803"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141824" severity="high">
    <xccdf:title>RHSA-2014:1824: php security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

A stack-based buffer overflow flaw was found in the way the xmlrpc
extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC
request or response could possibly cause a PHP application to crash.
(CVE-2014-8626)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1824</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8626</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141824"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141826" severity="medium">
    <xccdf:title>RHSA-2014:1826: libvncserver security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibVNCServer is a library that allows for easy creation of VNC server or
client functionality.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way screen sizes were handled by LibVNCServer. A malicious VNC
server could use this flaw to cause a client to crash or, potentially,
execute arbitrary code in the client. (CVE-2014-6051)

A NULL pointer dereference flaw was found in LibVNCServer's framebuffer
setup. A malicious VNC server could use this flaw to cause a VNC client to
crash. (CVE-2014-6052)

A NULL pointer dereference flaw was found in the way LibVNCServer handled
certain ClientCutText message. A remote attacker could use this flaw to
crash the VNC server by sending a specially crafted ClientCutText message
from a VNC client. (CVE-2014-6053)

A divide-by-zero flaw was found in the way LibVNCServer handled the scaling
factor when it was set to "0". A remote attacker could use this flaw to
crash the VNC server using a malicious VNC client. (CVE-2014-6054)

Two stack-based buffer overflow flaws were found in the way LibVNCServer
handled file transfers. A remote attacker could use this flaw to crash the
VNC server using a malicious VNC client. (CVE-2014-6055)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges Nicolas Ruff as the original reporter.

All libvncserver users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications linked against libvncserver must be restarted for this update
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1826</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6051</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6052</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6055</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141826"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141827" severity="medium">
    <xccdf:title>RHSA-2014:1827: kdenetwork security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kdenetwork packages contain networking applications for the K Desktop
Environment (KDE). Krfb Desktop Sharing, which is a part of the kdenetwork
package, is a server application that allows session sharing between users.
Krfb uses the LibVNCServer library.

A NULL pointer dereference flaw was found in the way LibVNCServer handled
certain ClientCutText message. A remote attacker could use this flaw to
crash the VNC server by sending a specially crafted ClientCutText message
from a VNC client. (CVE-2014-6053)

A divide-by-zero flaw was found in the way LibVNCServer handled the scaling
factor when it was set to "0". A remote attacker could use this flaw to
crash the VNC server using a malicious VNC client. (CVE-2014-6054)

Two stack-based buffer overflow flaws were found in the way LibVNCServer
handled file transfers. A remote attacker could use this flaw to crash the
VNC server using a malicious VNC client. (CVE-2014-6055)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges Nicolas Ruff as the original reporter.

Note: Prior to this update, the kdenetwork packages used an embedded copy
of the LibVNCServer library. With this update, the kdenetwork packages have
been modified to use the system LibVNCServer packages. Therefore, the
update provided by RHSA-2014:1826 must be installed to fully address the
issues in krfb described above.

All kdenetwork users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of the krfb server must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6055</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141827"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141843" severity="high">
    <xccdf:title>RHSA-2014:1843: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A race condition flaw was found in the way the Linux kernel's KVM
subsystem handled PIT (Programmable Interval Timer) emulation. A guest user
who has access to the PIT I/O ports could use this flaw to crash the host.
(CVE-2014-3611, Important)

* A memory corruption flaw was found in the way the USB ConnectTech
WhiteHEAT serial driver processed completion commands sent via USB Request
Blocks buffers. An attacker with physical access to the system could use
this flaw to crash the system or, potentially, escalate their privileges on
the system. (CVE-2014-3185, Moderate)

* It was found that the Linux kernel's KVM subsystem did not handle the VM
exits gracefully for the invept (Invalidate Translations Derived from EPT)
and invvpid (Invalidate Translations Based on VPID) instructions. On hosts
with an Intel processor and invept/invppid VM exit support, an unprivileged
guest user could use these instructions to crash the guest. (CVE-2014-3645,
CVE-2014-3646, Moderate)

Red Hat would like to thank Lars Bull of Google for reporting
CVE-2014-3611, and the Advanced Threat Research team at Intel Security for
reporting CVE-2014-3645 and CVE-2014-3646.

This update also fixes the following bugs:

* This update fixes several race conditions between PCI error recovery
callbacks and potential calls of the ifup and ifdown commands in the tg3
driver. When triggered, these race conditions could cause a kernel crash.
(BZ#1142570)

* Previously, GFS2 failed to unmount a sub-mounted GFS2 file system if its
parent was also a GFS2 file system. This problem has been fixed by adding
the appropriate d_op-&gt;d_hash() routine call for the last component of the
mount point path in the path name lookup mechanism code (namei).
(BZ#1145193)

* Due to previous changes in the virtio-net driver, a Red Hat Enterprise
Linux 6.6 guest was unable to boot with the "mgr_rxbuf=off" option
specified. This was caused by providing the page_to_skb() function with an
incorrect packet length in the driver's Rx path. This problem has been
fixed and the guest in the described scenario can now boot successfully.
(BZ#1148693)

* When using one of the newer IPSec Authentication Header (AH) algorithms
with Openswan, a kernel panic could occur. This happened because the
maximum truncated ICV length was too small. To fix this problem, the
MAX_AH_AUTH_LEN parameter has been set to 64. (BZ#1149083)

* A bug in the IPMI driver caused the kernel to panic when an IPMI
interface was removed using the hotmod script. The IPMI driver has been
fixed to properly clean the relevant data when removing an IPMI interface.
(BZ#1149578)

* Due to a bug in the IPMI driver, the kernel could panic when adding an
IPMI interface that was previously removed using the hotmod script.
This update fixes this bug by ensuring that the relevant shadow structure
is initialized at the right time. (BZ#1149580)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3611</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3645</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3646</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141843"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141846" severity="medium">
    <xccdf:title>RHSA-2014:1846: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). The gnutls packages also
include the libtasn1 library, which provides Abstract Syntax Notation One
(ASN.1) parsing and structures management, and Distinguished Encoding Rules
(DER) encoding and decoding functions.

An out-of-bounds memory write flaw was found in the way GnuTLS parsed
certain ECC (Elliptic Curve Cryptography) certificates or certificate
signing requests (CSR). A malicious user could create a specially crafted
ECC certificate or a certificate signing request that, when processed by an
application compiled against GnuTLS (for example, certtool), could cause
that application to crash or execute arbitrary code with the permissions of
the user running the application. (CVE-2014-8564)

Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Sean Burford as the original reporter.

All gnutls users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the GnuTLS or libtasn1 library must
be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1846</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8564</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141846"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141859" severity="high">
    <xccdf:title>RHSA-2014:1859: mysql55-mysql security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2494,
CVE-2014-4207, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260, CVE-2014-4287, 
CVE-2014-4274, CVE-2014-6463, CVE-2014-6464, CVE-2014-6469, CVE-2014-6484, 
CVE-2014-6505, CVE-2014-6507, CVE-2014-6520, CVE-2014-6530, CVE-2014-6551, 
CVE-2014-6555, CVE-2014-6559)

These updated packages upgrade MySQL to version 5.5.40. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1859</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6559</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141859"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141861" severity="high">
    <xccdf:title>RHSA-2014:1861: mariadb security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MariaDB is a multi-user, multi-threaded SQL database server that is binary
compatible with MySQL.

This update fixes several vulnerabilities in the MariaDB database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2494,
CVE-2014-4207, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260, CVE-2014-4287,
CVE-2014-4274, CVE-2014-6463, CVE-2014-6464, CVE-2014-6469, CVE-2014-6484,
CVE-2014-6505, CVE-2014-6507, CVE-2014-6520, CVE-2014-6530, CVE-2014-6551,
CVE-2014-6555, CVE-2014-6559)

These updated packages upgrade MariaDB to version 5.5.40. Refer to the
MariaDB Release Notes listed in the References section for a complete list
of changes.

All MariaDB users should upgrade to these updated packages, which correct
these issues. After installing this update, the MariaDB server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1861</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5615</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2494</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4274</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6463</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6464</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6530</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6555</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6559</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141861"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141870" severity="high">
    <xccdf:title>RHSA-2014:1870: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A use-after-free flaw was found in the way libXfont processed certain font
files when attempting to add a new directory to the font path. A malicious,
local user could exploit this issue to potentially execute arbitrary code
with the privileges of the X.Org server. (CVE-2014-0209)

Multiple out-of-bounds write flaws were found in the way libXfont parsed
replies received from an X.org font server. A malicious X.org server could
cause an X client to crash or, possibly, execute arbitrary code with the
privileges of the X.Org server. (CVE-2014-0210, CVE-2014-0211)

Red Hat would like to thank the X.org project for reporting these issues.
Upstream acknowledges Ilja van Sprundel as the original reporter.

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0211</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141870"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141873" severity="medium">
    <xccdf:title>RHSA-2014:1873: libvirt security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

An out-of-bounds read flaw was found in the way libvirt's
qemuDomainGetBlockIoTune() function looked up the disk index in a
non-persistent (live) disk configuration while a persistent disk
configuration was being indexed. A remote attacker able to establish a
read-only connection to libvirtd could use this flaw to crash libvirtd or,
potentially, leak memory from the libvirtd process. (CVE-2014-3633)

A denial of service flaw was found in the way libvirt's
virConnectListAllDomains() function computed the number of used domains.
A remote attacker able to establish a read-only connection to libvirtd
could use this flaw to make any domain operations within libvirt
unresponsive. (CVE-2014-3657)

It was found that when the VIR_DOMAIN_XML_MIGRATABLE flag was used, the
QEMU driver implementation of the virDomainGetXMLDesc() function could
bypass the restrictions of the VIR_DOMAIN_XML_SECURE flag. A remote
attacker able to establish a read-only connection to libvirtd could use
this flaw to leak certain limited information from the domain XML data.
(CVE-2014-7823)

The CVE-2014-3633 issue was discovered by Luyao Huang of Red Hat.

This update also fixes the following bug:

When dumping migratable XML configuration of a domain, libvirt removes some
automatically added devices for compatibility with older libvirt releases.
If such XML is passed to libvirt as a domain XML that should be used during
migration, libvirt checks this XML for compatibility with the internally
stored configuration of the domain. However, prior to this update, these
checks failed because of devices that were missing (the same devices
libvirt removed). As a consequence, migration with user-supplied migratable
XML failed. Since this feature is used by OpenStack, migrating QEMU/KVM
domains with OpenStack always failed. With this update, before checking
domain configurations for compatibility, libvirt transforms both
user-supplied and internal configuration into a migratable form
(automatically added devices are removed) and checks those instead. Thus,
no matter whether the user-supplied configuration was generated as
migratable or not, libvirt does not err about missing devices, and
migration succeeds as expected. (BZ#1155564)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1873</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7823</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141873"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141885" severity="medium">
    <xccdf:title>RHSA-2014:1885: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in libxml2, a library providing support
to read, modify and write XML and HTML files. A remote attacker could
provide a specially crafted XML file that, when processed by an application
using libxml2, would lead to excessive CPU consumption (denial of service)
based on excessive entity substitutions, even if entity substitution was
disabled, which is the parser default behavior. (CVE-2014-3660)

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1885</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3660</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141885"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141893" severity="high">
    <xccdf:title>RHSA-2014:1893: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A use-after-free flaw was found in the way libXfont processed certain font
files when attempting to add a new directory to the font path. A malicious,
local user could exploit this issue to potentially execute arbitrary code
with the privileges of the X.Org server. (CVE-2014-0209)

Multiple out-of-bounds write flaws were found in the way libXfont parsed
replies received from an X.org font server. A malicious X.org server could
cause an X client to crash or, possibly, execute arbitrary code with the
privileges of the X.Org server. (CVE-2014-0210, CVE-2014-0211)

Red Hat would like to thank the X.org project for reporting these issues.
Upstream acknowledges Ilja van Sprundel as the original reporter.

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0211</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141893"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141911" severity="medium">
    <xccdf:title>RHSA-2014:1911: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language.
It has features to process text files and to perform system management
tasks.

Multiple denial of service flaws were found in the way the Ruby REXML XML
parser performed expansion of parameter entities. A specially crafted XML
document could cause REXML to use an excessive amount of CPU and memory.
(CVE-2014-8080, CVE-2014-8090)

The CVE-2014-8090 issue was discovered by Red Hat Product Security.

All ruby users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Ruby need to be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1911</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8090</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141911"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141912" severity="medium">
    <xccdf:title>RHSA-2014:1912: ruby security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Ruby is an extensible, interpreted, object-oriented, scripting language.
It has features to process text files and to perform system management
tasks.

Multiple denial of service flaws were found in the way the Ruby REXML XML
parser performed expansion of parameter entities. A specially crafted XML
document could cause REXML to use an excessive amount of CPU and memory.
(CVE-2014-8080, CVE-2014-8090)

A stack-based buffer overflow was found in the implementation of the Ruby
Array pack() method. When performing base64 encoding, a single byte could
be written past the end of the buffer, possibly causing Ruby to crash.
(CVE-2014-4975)

The CVE-2014-8090 issue was discovered by Red Hat Product Security.

All ruby users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Ruby need to be restarted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1912</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4975</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8090</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141912"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141919" severity="high">
    <xccdf:title>RHSA-2014:1919: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

This update disables SSL 3.0 support by default in Firefox. Details on how
to re-enable SSL 3.0 support are available at:
https://access.redhat.com/articles/1283153

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.3.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.3.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1594</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141919"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141924" severity="high">
    <xccdf:title>RHSA-2014:1924: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

This update disables SSL 3.0 support by default in Thunderbird. Details on
how to re-enable SSL 3.0 support are available at:
https://access.redhat.com/articles/1284233

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.3.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.3.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1924</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1592</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1594</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141924"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141956" severity="medium">
    <xccdf:title>RHSA-2014:1956: wpa_supplicant security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wpa_supplicant package contains an 802.1X Supplicant with support for
WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication
methods. It implements key negotiation with a WPA Authenticator for client
stations and controls the roaming and IEEE 802.11 authentication and
association of the WLAN driver.

A command injection flaw was found in the way the wpa_cli utility executed
action scripts. If wpa_cli was run in daemon mode to execute an action
script (specified using the -a command line option), and wpa_supplicant was
configured to connect to a P2P group, malicious P2P group parameters could
cause wpa_cli to execute arbitrary code. (CVE-2014-3686)

Red Hat would like to thank Jouni Malinen for reporting this issue.

All wpa_supplicant users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1956</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3686</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141956"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141959" severity="medium">
    <xccdf:title>RHSA-2014:1959: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the permission checks performed by the Linux kernel
when a netlink message was received were not sufficient. A local,
unprivileged user could potentially bypass these restrictions by passing a
netlink socket as stdout or stderr to a more privileged process and
altering the output of this process. (CVE-2014-0181, Moderate)

Red Hat would like to thank Andy Lutomirski for reporting this issue.

This update also fixes the following bugs:

* Previously, the kernel did not successfully deliver multicast packets
when the multicast querier was disabled. Consequently, the corosync utility
terminated unexpectedly and the affected storage node did not join its
intended cluster. With this update, multicast packets are delivered
properly when the multicast querier is disabled, and corosync handles the
node as expected. (BZ#902454)

* Previously, the kernel wrote the metadata contained in all system
information blocks on a single page of the /proc/sysinfo file. However,
when the machine configuration was very extensive and the data did not fit
on a single page, the system overwrote random memory regions, which in turn
caused data corruption when reading the /proc/sysconf file. With this
update, /proc/sysinfo automatically allocates a larger buffer if the data
output does not fit the current buffer, which prevents the data corruption.
(BZ#1131283)

* Prior to this update, the it_real_fn() function did not, in certain
cases, successfully acquire the SIGLOCK signal when the do_setitimer()
function used the ITIMER_REAL timer. As a consequence, the current process
entered an endless loop and became unresponsive. This update fixes the bug
and it_real_fn() no longer causes the kernel to become unresponsive.
(BZ#1134654)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1959</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0181</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141959"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141971" severity="high">
    <xccdf:title>RHSA-2014:1971: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>* A flaw was found in the way the Linux kernel's SCTP implementation
handled malformed or duplicate Address Configuration Change Chunks
(ASCONF). A remote attacker could use either of these flaws to crash the
system. (CVE-2014-3673, CVE-2014-3687, Important)

* A flaw was found in the way the Linux kernel's SCTP implementation
handled the association's output queue. A remote attacker could send
specially crafted packets that would cause the system to use an excessive
amount of memory, leading to a denial of service. (CVE-2014-3688,
Important)

* Two flaws were found in the way the Apple Magic Mouse/Trackpad
multi-touch driver and the Minibox PicoLCD driver handled invalid HID
reports. An attacker with physical access to the system could use these
flaws to crash the system or, potentially, escalate their privileges on the
system. (CVE-2014-3181, CVE-2014-3186, Moderate)

* A memory corruption flaw was found in the way the USB ConnectTech
WhiteHEAT serial driver processed completion commands sent via USB Request
Blocks buffers. An attacker with physical access to the system could use
this flaw to crash the system or, potentially, escalate their privileges on
the system. (CVE-2014-3185, Moderate)

* A flaw was found in the way the Linux kernel's keys subsystem handled the
termination condition in the associative array garbage collection
functionality. A local, unprivileged user could use this flaw to crash the
system. (CVE-2014-3631, Moderate)

* Multiple flaws were found in the way the Linux kernel's ALSA
implementation handled user controls. A local, privileged user could use
either of these flaws to crash the system. (CVE-2014-4654, CVE-2014-4655,
CVE-2014-4656, Moderate)

* A flaw was found in the way the Linux kernel's VFS subsystem handled
reference counting when performing unmount operations on symbolic links.
A local, unprivileged user could use this flaw to exhaust all available
memory on the system or, potentially, trigger a use-after-free error,
resulting in a system crash or privilege escalation. (CVE-2014-5045,
Moderate)

* A flaw was found in the way the get_dumpable() function return value was
interpreted in the ptrace subsystem of the Linux kernel. When
'fs.suid_dumpable' was set to 2, a local, unprivileged local user could
use this flaw to bypass intended ptrace restrictions and obtain
potentially sensitive information. (CVE-2013-2929, Low)

* A stack overflow flaw caused by infinite recursion was found in the way
the Linux kernel's UDF file system implementation processed indirect ICBs.
An attacker with physical access to the system could use a specially
crafted UDF image to crash the system. (CVE-2014-6410, Low)

* An information leak flaw in the way the Linux kernel handled media device
enumerate entities IOCTL requests could allow a local user able to access
the /dev/media0 device file to leak kernel memory bytes. (CVE-2014-1739,
Low)

* An out-of-bounds read flaw in the Logitech Unifying receiver driver could
allow an attacker with physical access to the system to crash the system
or, potentially, escalate their privileges on the system. (CVE-2014-3182,
Low)

* Multiple out-of-bounds write flaws were found in the way the Cherry
Cymotion keyboard driver, KYE/Genius device drivers, Logitech device
drivers, Monterey Genius KB29E keyboard driver, Petalynx Maxter remote
control driver, and Sunplus wireless desktop driver handled invalid HID
reports. An attacker with physical access to the system could use either of
these flaws to write data past an allocated memory buffer. (CVE-2014-3184,
Low)

* An information leak flaw was found in the RAM Disks Memory Copy (rd_mcp)
back end driver of the iSCSI Target subsystem could allow a privileged user
to leak the contents of kernel memory to an iSCSI initiator remote client.
(CVE-2014-4027, Low)

* An information leak flaw in the Linux kernel's ALSA implementation could
allow a local, privileged user to leak kernel memory to user space.
(CVE-2014-4652, Low)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1971</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-2929</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3186</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3631</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4027</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4654</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6410</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141971"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141974" severity="high">
    <xccdf:title>RHSA-2014:1974: rpm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a powerful command line driven package
management system capable of installing, uninstalling, verifying, querying,
and updating software packages. Each software package consists of an
archive of files along with information about the package such as its
version, description, and other information.

It was found that RPM wrote file contents to the target installation
directory under a temporary name, and verified its cryptographic signature
only after the temporary file has been written completely. Under certain
conditions, the system interprets the unverified temporary file contents
and extracts commands from it. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2013-6435)

This issue was discovered by Florian Weimer of Red Hat Product Security.

All rpm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against the RPM library must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1974</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6435</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141974"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141976" severity="high">
    <xccdf:title>RHSA-2014:1976: rpm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The RPM Package Manager (RPM) is a powerful command line driven package
management system capable of installing, uninstalling, verifying, querying,
and updating software packages. Each software package consists of an
archive of files along with information about the package such as its
version, description, and other information.

It was found that RPM wrote file contents to the target installation
directory under a temporary name, and verified its cryptographic signature
only after the temporary file has been written completely. Under certain
conditions, the system interprets the unverified temporary file contents
and extracts commands from it. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2013-6435)

It was found that RPM could encounter an integer overflow, leading to a
stack-based buffer overflow, while parsing a crafted CPIO header in the
payload section of an RPM file. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2014-8118)

These issues were discovered by Florian Weimer of Red Hat Product Security.

All rpm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against the RPM library must be restarted for this
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1976</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-6435</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8118</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141976"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141982" severity="high">
    <xccdf:title>RHSA-2014:1982: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple integer overflow flaws and out-of-bounds write flaws were found in
the way the X.Org server calculated memory requirements for certain X11
core protocol and GLX extension requests. A malicious, authenticated client
could use either of these flaws to crash the X.Org server or, potentially,
execute arbitrary code with root privileges. (CVE-2014-8092, CVE-2014-8093,
CVE-2014-8098)

It was found that the X.Org server did not properly handle SUN-DES-1
(Secure RPC) authentication credentials. A malicious, unauthenticated
client could use this flaw to crash the X.Org server by submitting a
specially crafted authentication request. (CVE-2014-8091)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server, or leak memory contents to the client. (CVE-2014-8097)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server. (CVE-2014-8095, CVE-2014-8096, CVE-2014-8099, CVE-2014-8100,
CVE-2014-8101, CVE-2014-8102)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8099</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8102</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141982"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141983" severity="high">
    <xccdf:title>RHSA-2014:1983: xorg-x11-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple integer overflow flaws and out-of-bounds write flaws were found in
the way the X.Org server calculated memory requirements for certain X11
core protocol and GLX extension requests. A malicious, authenticated client
could use either of these flaws to crash the X.Org server or, potentially,
execute arbitrary code with root privileges. (CVE-2014-8092, CVE-2014-8093,
CVE-2014-8098)

It was found that the X.Org server did not properly handle SUN-DES-1
(Secure RPC) authentication credentials. A malicious, unauthenticated
client could use this flaw to crash the X.Org server by submitting a
specially crafted authentication request. (CVE-2014-8091)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server, or leak memory contents to the client. (CVE-2014-8097)

An integer overflow flaw was found in the way the X.Org server calculated
memory requirements for certain DRI2 extension requests. A malicious,
authenticated client could use this flaw to crash the X.Org server.
(CVE-2014-8094)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server. (CVE-2014-8095, CVE-2014-8096, CVE-2014-8099, CVE-2014-8100,
CVE-2014-8101, CVE-2014-8102, CVE-2014-8103)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8091</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8093</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8094</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8095</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8096</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8097</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8098</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8099</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8103</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141983"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141984" severity="high">
    <xccdf:title>RHSA-2014:1984: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and processed,
would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1984</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8500</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141984"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141985" severity="high">
    <xccdf:title>RHSA-2014:1985: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and processed,
would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1985</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8500</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141985"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141997" severity="high">
    <xccdf:title>RHSA-2014:1997: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>* A flaw was found in the way the Linux kernel handled GS segment register
base switching when recovering from a #SS (stack segment) fault on an
erroneous return to user space. A local, unprivileged user could use this
flaw to escalate their privileges on the system. (CVE-2014-9322, Important)

* A flaw was found in the way the Linux kernel's SCTP implementation
handled malformed or duplicate Address Configuration Change Chunks
(ASCONF). A remote attacker could use either of these flaws to crash the
system. (CVE-2014-3673, CVE-2014-3687, Important)

* A flaw was found in the way the Linux kernel's SCTP implementation
handled the association's output queue. A remote attacker could send
specially crafted packets that would cause the system to use an excessive
amount of memory, leading to a denial of service. (CVE-2014-3688,
Important)

* A stack overflow flaw caused by infinite recursion was found in the way
the Linux kernel's UDF file system implementation processed indirect ICBs.
An attacker with physical access to the system could use a specially
crafted UDF image to crash the system. (CVE-2014-6410, Low)

* It was found that the Linux kernel's networking implementation did not
correctly handle the setting of the keepalive socket option on raw sockets.
A local user able to create a raw socket could use this flaw to crash the
system. (CVE-2012-6657, Low)

* It was found that the parse_rock_ridge_inode_internal() function of the
Linux kernel's ISOFS implementation did not correctly check relocated
directories when processing Rock Ridge child link (CL) tags. An attacker
with physical access to the system could use a specially crafted ISO image
to crash the system or, potentially, escalate their privileges on the
system. (CVE-2014-5471, CVE-2014-5472, Low)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-9322.
The CVE-2014-3673 issue was discovered by Liu Wei of Red Hat.

Bug fixes:

* This update fixes a race condition issue between the sock_queue_err_skb
function and sk_forward_alloc handling in the socket error queue
(MSG_ERRQUEUE), which could occasionally cause the kernel, for example when
using PTP, to incorrectly track allocated memory for the error queue, in
which case a traceback would occur in the system log. (BZ#1155427)

* The zcrypt device driver did not detect certain crypto cards and the
related domains for crypto adapters on System z and s390x architectures.
Consequently, it was not possible to run the system on new crypto hardware.
This update enables toleration mode for such devices so that the system
can make use of newer crypto hardware. (BZ#1158311)

* After mounting and unmounting an XFS file system several times
consecutively, the umount command occasionally became unresponsive.
This was caused by the xlog_cil_force_lsn() function that was not waiting
for completion as expected. With this update, xlog_cil_force_lsn() has been
modified to correctly wait for completion, thus fixing this bug.
(BZ#1158325)

* When using the ixgbe adapter with disabled LRO and the tx-usec or rs-usec
variables set to 0, transmit interrupts could not be set lower than the
default of 8 buffered tx frames. Consequently, a delay of TCP transfer
occurred. The restriction of a minimum of 8 buffered frames has been
removed, and the TCP delay no longer occurs. (BZ#1158326)

* The offb driver has been updated for the QEMU standard VGA adapter,
fixing an incorrect displaying of colors issue. (BZ#1158328)

* Under certain circumstances, when a discovered MTU expired, the IPv6
connection became unavailable for a short period of time. This bug has been
fixed, and the connection now works as expected. (BZ#1161418)

* A low throughput occurred when using the dm-thin driver to write to
unprovisioned or shared chunks for a thin pool with the chunk size bigger
than the max_sectors_kb variable. (BZ#1161420)

* Large write workloads on thin LVs could cause the iozone and smallfile
utilities to terminate unexpectedly. (BZ#1161421)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1997</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3687</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3688</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141997"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20141999" severity="medium">
    <xccdf:title>RHSA-2014:1999: mailx security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The mailx packages contain a mail user agent that is used to manage mail
using scripts.

A flaw was found in the way mailx handled the parsing of email addresses.
A syntactically valid email address could allow a local attacker to cause
mailx to execute arbitrary shell commands through shell meta-characters and
the direct command execution functionality. (CVE-2004-2771, CVE-2014-7844)

Note: Applications using mailx to send email to addresses obtained from
untrusted sources will still remain vulnerable to other attacks if they
accept email addresses which start with "-" (so that they can be confused
with mailx options). To counteract this issue, this update also introduces
the "--" option, which will treat the remaining command line arguments as
email addresses.

All mailx users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:1999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2004-2771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7844</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20141999"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142008" severity="high">
    <xccdf:title>RHSA-2014:2008: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel handled GS segment register
base switching when recovering from a #SS (stack segment) fault on an
erroneous return to user space. A local, unprivileged user could use this
flaw to escalate their privileges on the system. (CVE-2014-9322, Important)

Red Hat would like to thank Andy Lutomirski for reporting this issue.

All kernel users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142010" severity="high">
    <xccdf:title>RHSA-2014:2010: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel handled GS segment register
base switching when recovering from a #SS (stack segment) fault on an
erroneous return to user space. A local, unprivileged user could use this
flaw to escalate their privileges on the system. (CVE-2014-9322, Important)

Red Hat would like to thank Andy Lutomirski for reporting this issue.

All kernel users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9322</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142010"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142021" severity="high">
    <xccdf:title>RHSA-2014:2021: jasper security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>JasPer is an implementation of Part 1 of the JPEG 2000 image compression
standard.

Multiple off-by-one flaws, leading to heap-based buffer overflows, were
found in the way JasPer decoded JPEG 2000 image files. A specially crafted
file could cause an application using JasPer to crash or, possibly, execute
arbitrary code. (CVE-2014-9029)

A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG
2000 image files. A specially crafted file could cause an application using
JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8138)

A double free flaw was found in the way JasPer parsed ICC color profiles in
JPEG 2000 image files. A specially crafted file could cause an application
using JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8137)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges Jose Duart of the Google Security Team as the original
reporter.

All JasPer users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All applications using
the JasPer libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8138</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9029</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142021"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142023" severity="medium">
    <xccdf:title>RHSA-2014:2023: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

It was found that the wordexp() function would perform command substitution
even when the WRDE_NOCMD flag was specified. An attacker able to provide
specially crafted input to an application using the wordexp() function, and
not sanitizing the input correctly, could potentially use this flaw to
execute arbitrary commands with the credentials of the user running that
application. (CVE-2014-7817)

This issue was discovered by Tim Waugh of the Red Hat Developer Experience
Team.

This update also fixes the following bug:

* Prior to this update, if a file stream that was opened in append mode and
its underlying file descriptor were used at the same time and the file was
truncated using the ftruncate() function on the file descriptor, a
subsequent ftell() call on the stream incorrectly modified the file offset
by seeking to the new end of the file. This update ensures that ftell()
modifies the state of the file stream only when it is in append mode and
its buffer is not empty. As a result, the described incorrect changes to
the file offset no longer occur. (BZ#1170187)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2023</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7817</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142023"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142024" severity="high">
    <xccdf:title>RHSA-2014:2024: ntp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

Multiple buffer overflow flaws were discovered in ntpd's crypto_recv(),
ctl_putdata(), and configure() functions. A remote attacker could use
either of these flaws to send a specially crafted request packet that could
crash ntpd or, potentially, execute arbitrary code with the privileges of
the ntp user. Note: the crypto_recv() flaw requires non-default
configurations to be active, while the ctl_putdata() flaw, by default, can
only be exploited via local attackers, and the configure() flaw requires
additional authentication to exploit. (CVE-2014-9295)

It was found that ntpd automatically generated weak keys for its internal
use if no ntpdc request authentication key was specified in the ntp.conf
configuration file. A remote attacker able to match the configured IP
restrictions could guess the generated key, and possibly use it to send
ntpdc query or configuration requests. (CVE-2014-9293)

It was found that ntp-keygen used a weak method for generating MD5 keys.
This could possibly allow an attacker to guess generated MD5 keys that
could then be used to spoof an NTP client or server. Note: it is
recommended to regenerate any MD5 keys that had explicitly been generated
with ntp-keygen; the default installation does not contain such keys).
(CVE-2014-9294)

A missing return statement in the receive() function could potentially
allow a remote attacker to bypass NTP's authentication mechanism.
(CVE-2014-9296)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9294</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9295</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9296</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142024"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20142025" severity="high">
    <xccdf:title>RHSA-2014:2025: ntp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

Multiple buffer overflow flaws were discovered in ntpd's crypto_recv(),
ctl_putdata(), and configure() functions. A remote attacker could use
either of these flaws to send a specially crafted request packet that could
crash ntpd or, potentially, execute arbitrary code with the privileges of
the ntp user. Note: the crypto_recv() flaw requires non-default
configurations to be active, while the ctl_putdata() flaw, by default, can
only be exploited via local attackers, and the configure() flaw requires
additional authentication to exploit. (CVE-2014-9295)

It was found that ntpd automatically generated weak keys for its internal
use if no ntpdc request authentication key was specified in the ntp.conf
configuration file. A remote attacker able to match the configured IP
restrictions could guess the generated key, and possibly use it to send
ntpdc query or configuration requests. (CVE-2014-9293)

It was found that ntp-keygen used a weak method for generating MD5 keys.
This could possibly allow an attacker to guess generated MD5 keys that
could then be used to spoof an NTP client or server. Note: it is
recommended to regenerate any MD5 keys that had explicitly been generated
with ntp-keygen; the default installation does not contain such keys).
(CVE-2014-9294)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2014:2025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9294</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9295</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20142025"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150008" severity="low">
    <xccdf:title>RHSA-2015:0008: libvirt security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

It was found that when the VIR_DOMAIN_XML_MIGRATABLE flag was used, the
QEMU driver implementation of the virDomainGetXMLDesc() function could
bypass the restrictions of the VIR_DOMAIN_XML_SECURE flag. A remote
attacker able to establish a read-only connection to libvirtd could use
this flaw to leak certain limited information from the domain XML data.
(CVE-2014-7823)

This issue was discovered by Eric Blake of Red Hat.

This update also fixes the following bugs:

* In Red Hat Enterprise Linux 6, libvirt relies on the QEMU emulator to
supply the error message when an active commit is attempted. However, with
Red Hat Enterprise Linux 7, QEMU added support for an active commit, but an
additional interaction from libvirt to fully enable active commits is still
missing. As a consequence, attempts to perform an active commit caused
libvirt to become unresponsive. With this update, libvirt has been fixed to
detect an active commit by itself, and now properly declares the feature as
unsupported. As a result, libvirt no longer hangs when an active commit is
attempted and instead produces an error message.

Note that the missing libvirt interaction will be added in Red Hat
Enterprise Linux 7.1, adding full support for active commits. (BZ#1150379)

* Prior to this update, the libvirt API did not properly check whether a
Discretionary Access Control (DAC) security label is non-NULL before trying
to parse user/group ownership from it. In addition, the DAC security label
of a transient domain that had just finished migrating to another host is
in some cases NULL. As a consequence, when the virDomainGetBlockInfo API
was called on such a domain, the libvirtd daemon sometimes terminated
unexpectedly. With this update, libvirt properly checks DAC labels before
trying to parse them, and libvirtd thus no longer crashes in the described
scenario. (BZ#1171124)

* If a block copy operation was attempted while another block copy was
already in progress to an explicit raw destination, libvirt previously
stopped regarding the destination as raw. As a consequence, if the
qemu.conf file was edited to allow file format probing, triggering the bug
could allow a malicious guest to bypass sVirt protection by making libvirt
regard the file as non-raw. With this update, libvirt has been fixed to
consistently remember when a block copy destination is raw, and guests can
no longer circumvent sVirt protection when the host is configured to allow
format probing. (BZ#1149078)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7823</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150016" severity="medium">
    <xccdf:title>RHSA-2015:0016: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

An out-of-bounds read flaw was found in the way glibc's iconv() function
converted certain encoded data to UTF-8. An attacker able to make an
application call the iconv() function with a specially crafted argument
could use this flaw to crash that application. (CVE-2014-6040)

It was found that the wordexp() function would perform command substitution
even when the WRDE_NOCMD flag was specified. An attacker able to provide
specially crafted input to an application using the wordexp() function, and
not sanitizing the input correctly, could potentially use this flaw to
execute arbitrary commands with the credentials of the user running that
application. (CVE-2014-7817)

The CVE-2014-7817 issue was discovered by Tim Waugh of the Red Hat
Developer Experience Team.

This update also fixes the following bugs:

* Previously, when an address lookup using the getaddrinfo() function for
the AF_UNSPEC value was performed on a defective DNS server, the server in
some cases responded with a valid response for the A record, but a referral
response for the AAAA record, which resulted in a lookup failure. A prior
update was implemented for getaddrinfo() to return the valid response, but
it contained a typographical error, due to which the lookup could under
some circumstances still fail. This error has been corrected and
getaddrinfo() now returns a valid response in the described circumstances.
(BZ#1172023)

* An error in the dlopen() library function previously caused recursive
calls to dlopen() to terminate unexpectedly or to abort with a library
assertion. This error has been fixed and recursive calls to dlopen() no
longer crash or abort. (BZ#1173469)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0016</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7817</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150016"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150046" severity="high">
    <xccdf:title>RHSA-2015:0046: firefox security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-8634, CVE-2014-8639, CVE-2014-8641)

It was found that the Beacon interface implementation in Firefox did not
follow the Cross-Origin Resource Sharing (CORS) specification. A web page
containing malicious content could allow a remote attacker to conduct a
Cross-Site Request Forgery (XSRF) attack. (CVE-2014-8638)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Patrick McManus, Muneaki Nishimura,
Xiaofeng Zheng, and Mitchell Harper as the original reporters of these
issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bug:

* The default dictionary for Firefox's spell checker is now correctly set
to the system's locale language. (BZ#643954, BZ#1150572)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0046</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8639</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8641</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150046"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150047" severity="high">
    <xccdf:title>RHSA-2015:0047: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Two flaws were found in the processing of malformed web content. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2014-8634, CVE-2014-8639)

It was found that the Beacon interface implementation in Thunderbird did
not follow the Cross-Origin Resource Sharing (CORS) specification. A web
page containing malicious content could allow a remote attacker to conduct
a Cross-Site Request Forgery (XSRF) attack. (CVE-2014-8638)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Patrick McManus, Muneaki Nishimura,
and Xiaofeng Zheng as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0047</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8639</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150047"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150066" severity="medium">
    <xccdf:title>RHSA-2015:0066: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

A NULL pointer dereference flaw was found in the DTLS implementation of
OpenSSL. A remote attacker could send a specially crafted DTLS message,
which would cause an OpenSSL server to crash. (CVE-2014-3571)

A memory leak flaw was found in the way the dtls1_buffer_record() function
of OpenSSL parsed certain DTLS messages. A remote attacker could send
multiple specially crafted DTLS messages to exhaust all available memory of
a DTLS server. (CVE-2015-0206)

It was found that OpenSSL's BigNumber Squaring implementation could produce
incorrect results under certain special conditions. This flaw could
possibly affect certain OpenSSL library functionality, such as RSA
blinding. Note that this issue occurred rarely and with a low probability,
and there is currently no known way of exploiting it. (CVE-2014-3570)

It was discovered that OpenSSL would perform an ECDH key exchange with a
non-ephemeral key even when the ephemeral ECDH cipher suite was selected.
A malicious server could make a TLS/SSL client using OpenSSL use a weaker
key exchange method than the one requested by the user. (CVE-2014-3572)

It was discovered that OpenSSL would accept ephemeral RSA keys when using
non-export RSA cipher suites. A malicious server could make a TLS/SSL
client using OpenSSL use a weaker key exchange method. (CVE-2015-0204)

Multiple flaws were found in the way OpenSSL parsed X.509 certificates.
An attacker could use these flaws to modify an X.509 certificate to produce
a certificate with a different fingerprint without invalidating its
signature, and possibly bypass fingerprint-based blacklisting in
applications. (CVE-2014-8275)

It was found that an OpenSSL server would, under certain conditions, accept
Diffie-Hellman client certificates without the use of a private key.
An attacker could use a user's client certificate to authenticate as that
user, without needing the private key. (CVE-2015-0205)

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to mitigate the above issues. For the update to
take effect, all services linked to the OpenSSL library (such as httpd and
other SSL-enabled services) must be restarted or the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0066</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3570</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3572</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0206</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150066"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150067" severity="high">
    <xccdf:title>RHSA-2015:0067: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

A flaw was found in the way the Hotspot component in OpenJDK verified
bytecode from the class files. An untrusted Java application or applet
could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2014-6601)

Multiple improper permission check issues were discovered in the JAX-WS,
and RMI components in OpenJDK. An untrusted Java application or applet
could use these flaws to bypass Java sandbox restrictions. (CVE-2015-0412,
CVE-2015-0408)

A flaw was found in the way the Hotspot garbage collector handled phantom
references. An untrusted Java application or applet could use this flaw to
corrupt the Java Virtual Machine memory and, possibly, execute arbitrary
code, bypassing Java sandbox restrictions. (CVE-2015-0395)

A flaw was found in the way the DER (Distinguished Encoding Rules) decoder
in the Security component in OpenJDK handled negative length values. A
specially crafted, DER-encoded input could cause a Java application to
enter an infinite loop when decoded. (CVE-2015-0410)

A flaw was found in the way the SSL 3.0 protocol handled padding bytes when
decrypting messages that were encrypted using block ciphers in cipher block
chaining (CBC) mode. This flaw could possibly allow a man-in-the-middle
(MITM) attacker to decrypt portions of the cipher text using a padding
oracle attack. (CVE-2014-3566)

Note: This update disables SSL 3.0 by default to address this issue.
The jdk.tls.disabledAlgorithms security property can be used to re-enable
SSL 3.0 support if needed. For additional information, refer to the Red Hat
Bugzilla bug linked to in the References section.

It was discovered that the SSL/TLS implementation in the JSSE component in
OpenJDK failed to properly check whether the ChangeCipherSpec was received
during the SSL/TLS connection handshake. An MITM attacker could possibly
use this flaw to force a connection to be established without encryption
being enabled. (CVE-2014-6593)

An information leak flaw was found in the Swing component in OpenJDK. An
untrusted Java application or applet could use this flaw to bypass certain
Java sandbox restrictions. (CVE-2015-0407)

A NULL pointer dereference flaw was found in the MulticastSocket
implementation in the Libraries component of OpenJDK. An untrusted Java
application or applet could possibly use this flaw to bypass certain Java
sandbox restrictions. (CVE-2014-6587)

Multiple boundary check flaws were found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could allow an
untrusted Java application or applet to disclose portions of the Java
Virtual Machine memory. (CVE-2014-6585, CVE-2014-6591)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. (CVE-2015-0383)

The CVE-2015-0383 issue was discovered by Red Hat.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150067"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150068" severity="high">
    <xccdf:title>RHSA-2015:0068: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

A flaw was found in the way the Hotspot component in OpenJDK verified
bytecode from the class files. An untrusted Java application or applet
could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2014-6601)

Multiple improper permission check issues were discovered in the JAX-WS,
and RMI components in OpenJDK. An untrusted Java application or applet
could use these flaws to bypass Java sandbox restrictions. (CVE-2015-0412,
CVE-2015-0408)

A flaw was found in the way the Hotspot garbage collector handled phantom
references. An untrusted Java application or applet could use this flaw to
corrupt the Java Virtual Machine memory and, possibly, execute arbitrary
code, bypassing Java sandbox restrictions. (CVE-2015-0395)

A flaw was found in the way the DER (Distinguished Encoding Rules) decoder
in the Security component in OpenJDK handled negative length values. A
specially crafted, DER-encoded input could cause a Java application to
enter an infinite loop when decoded. (CVE-2015-0410)

A flaw was found in the way the SSL 3.0 protocol handled padding bytes when
decrypting messages that were encrypted using block ciphers in cipher block
chaining (CBC) mode. This flaw could possibly allow a man-in-the-middle
(MITM) attacker to decrypt portions of the cipher text using a padding
oracle attack. (CVE-2014-3566)

Note: This update disables SSL 3.0 by default to address this issue.
The jdk.tls.disabledAlgorithms security property can be used to re-enable
SSL 3.0 support if needed. For additional information, refer to the Red Hat
Bugzilla bug linked to in the References section.

It was discovered that the SSL/TLS implementation in the JSSE component in
OpenJDK failed to properly check whether the ChangeCipherSpec was received
during the SSL/TLS connection handshake. An MITM attacker could possibly
use this flaw to force a connection to be established without encryption
being enabled. (CVE-2014-6593)

An information leak flaw was found in the Swing component in OpenJDK. An
untrusted Java application or applet could use this flaw to bypass certain
Java sandbox restrictions. (CVE-2015-0407)

A NULL pointer dereference flaw was found in the MulticastSocket
implementation in the Libraries component of OpenJDK. An untrusted Java
application or applet could possibly use this flaw to bypass certain Java
sandbox restrictions. (CVE-2014-6587)

Multiple boundary check flaws were found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could allow an
untrusted Java application or applet to disclose portions of the Java
Virtual Machine memory. (CVE-2014-6585, CVE-2014-6591)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. (CVE-2015-0383)

The CVE-2015-0383 issue was discovered by Red Hat.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0068</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150068"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150069" severity="high">
    <xccdf:title>RHSA-2015:0069: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

Multiple flaws were found in the way the Hotspot component in OpenJDK
verified bytecode from the class files, and in the way this component
generated code for bytecode. An untrusted Java application or applet could
possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-6601, CVE-2015-0437)

Multiple improper permission check issues were discovered in the JAX-WS,
Libraries, and RMI components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2015-0412, CVE-2014-6549, CVE-2015-0408)

A flaw was found in the way the Hotspot garbage collector handled phantom
references. An untrusted Java application or applet could use this flaw to
corrupt the Java Virtual Machine memory and, possibly, execute arbitrary
code, bypassing Java sandbox restrictions. (CVE-2015-0395)

A flaw was found in the way the DER (Distinguished Encoding Rules) decoder
in the Security component in OpenJDK handled negative length values. A
specially crafted, DER-encoded input could cause a Java application to
enter an infinite loop when decoded. (CVE-2015-0410)

A flaw was found in the way the SSL 3.0 protocol handled padding bytes when
decrypting messages that were encrypted using block ciphers in cipher block
chaining (CBC) mode. This flaw could possibly allow a man-in-the-middle
(MITM) attacker to decrypt portions of the cipher text using a padding
oracle attack. (CVE-2014-3566)

Note: This update disables SSL 3.0 by default to address this issue.
The jdk.tls.disabledAlgorithms security property can be used to re-enable
SSL 3.0 support if needed. For additional information, refer to the Red Hat
Bugzilla bug linked to in the References section.

It was discovered that the SSL/TLS implementation in the JSSE component in
OpenJDK failed to properly check whether the ChangeCipherSpec was received
during the SSL/TLS connection handshake. An MITM attacker could possibly
use this flaw to force a connection to be established without encryption
being enabled. (CVE-2014-6593)

An information leak flaw was found in the Swing component in OpenJDK. An
untrusted Java application or applet could use this flaw to bypass certain
Java sandbox restrictions. (CVE-2015-0407)

A NULL pointer dereference flaw was found in the MulticastSocket
implementation in the Libraries component of OpenJDK. An untrusted Java
application or applet could possibly use this flaw to bypass certain Java
sandbox restrictions. (CVE-2014-6587)

Multiple boundary check flaws were found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could allow an
untrusted Java application or applet to disclose portions of the Java
Virtual Machine memory. (CVE-2014-6585, CVE-2014-6591)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. (CVE-2015-0383)

The CVE-2015-0383 issue was discovered by Red Hat.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0069</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150069"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150074" severity="high">
    <xccdf:title>RHSA-2015:0074: jasper security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>JasPer is an implementation of Part 1 of the JPEG 2000 image compression
standard.

An off-by-one flaw, leading to a heap-based buffer overflow, was found in
the way JasPer decoded JPEG 2000 image files. A specially crafted file
could cause an application using JasPer to crash or, possibly, execute
arbitrary code. (CVE-2014-8157)

An unrestricted stack memory use flaw was found in the way JasPer decoded
JPEG 2000 image files. A specially crafted file could cause an application
using JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8158)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges pyddeh as the original reporter.

All JasPer users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All applications using
the JasPer libraries must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8158</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150074"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150079" severity="high">
    <xccdf:title>RHSA-2015:0079: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-3566, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593,
CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0403, CVE-2015-0406,
CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412, CVE-2015-0413)

The CVE-2015-0383 issue was discovered by Red Hat.

Note: With this update, the Oracle Java SE now disables the SSL 3.0
protocol to address the CVE-2014-3566 issue (also known as POODLE). Refer
to the Red Hat Bugzilla bug linked to in the References section for
instructions on how to re-enable SSL 3.0 support if needed.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0413</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150079"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150080" severity="high">
    <xccdf:title>RHSA-2015:0080: java-1.8.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 8 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-3566, CVE-2014-6549, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591,
CVE-2014-6593, CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0403,
CVE-2015-0406, CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412,
CVE-2015-0413, CVE-2015-0421, CVE-2015-0437)

The CVE-2015-0383 issue was discovered by Red Hat.

Note: With this update, the Oracle Java SE now disables the SSL 3.0
protocol to address the CVE-2014-3566 issue (also known as POODLE). Refer
to the Red Hat Bugzilla bug linked to in the References section for
instructions on how to re-enable SSL 3.0 support if needed.

All users of java-1.8.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 8 Update 31 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0413</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0437</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150080"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150085" severity="high">
    <xccdf:title>RHSA-2015:0085: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

A flaw was found in the way the Hotspot component in OpenJDK verified
bytecode from the class files. An untrusted Java application or applet
could possibly use this flaw to bypass Java sandbox restrictions.
(CVE-2014-6601)

Multiple improper permission check issues were discovered in the JAX-WS,
and RMI components in OpenJDK. An untrusted Java application or applet
could use these flaws to bypass Java sandbox restrictions. (CVE-2015-0412,
CVE-2015-0408)

A flaw was found in the way the Hotspot garbage collector handled phantom
references. An untrusted Java application or applet could use this flaw to
corrupt the Java Virtual Machine memory and, possibly, execute arbitrary
code, bypassing Java sandbox restrictions. (CVE-2015-0395)

A flaw was found in the way the DER (Distinguished Encoding Rules) decoder
in the Security component in OpenJDK handled negative length values. A
specially crafted, DER-encoded input could cause a Java application to
enter an infinite loop when decoded. (CVE-2015-0410)

A flaw was found in the way the SSL 3.0 protocol handled padding bytes when
decrypting messages that were encrypted using block ciphers in cipher block
chaining (CBC) mode. This flaw could possibly allow a man-in-the-middle
(MITM) attacker to decrypt portions of the cipher text using a padding
oracle attack. (CVE-2014-3566)

Note: This update disables SSL 3.0 by default to address this issue.
The jdk.tls.disabledAlgorithms security property can be used to re-enable
SSL 3.0 support if needed. For additional information, refer to the Red Hat
Bugzilla bug linked to in the References section.

It was discovered that the SSL/TLS implementation in the JSSE component in
OpenJDK failed to properly check whether the ChangeCipherSpec was received
during the SSL/TLS connection handshake. An MITM attacker could possibly
use this flaw to force a connection to be established without encryption
being enabled. (CVE-2014-6593)

An information leak flaw was found in the Swing component in OpenJDK. An
untrusted Java application or applet could use this flaw to bypass certain
Java sandbox restrictions. (CVE-2015-0407)

A NULL pointer dereference flaw was found in the MulticastSocket
implementation in the Libraries component of OpenJDK. An untrusted Java
application or applet could possibly use this flaw to bypass certain Java
sandbox restrictions. (CVE-2014-6587)

Multiple boundary check flaws were found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could allow an
untrusted Java application or applet to disclose portions of the Java
Virtual Machine memory. (CVE-2014-6585, CVE-2014-6591)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. (CVE-2015-0383)

The CVE-2015-0383 issue was discovered by Red Hat.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0085</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150085"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150086" severity="high">
    <xccdf:title>RHSA-2015:0086: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-3566, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593,
CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0403, CVE-2015-0406,
CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412)

The CVE-2015-0383 issue was discovered by Red Hat.

Note: With this update, the Oracle Java SE now disables the SSL 3.0
protocol to address the CVE-2014-3566 issue (also known as POODLE). Refer
to the Red Hat Bugzilla bug linked to in the References section for
instructions on how to re-enable SSL 3.0 support if needed.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 91 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3566</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6591</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0395</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0403</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0406</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0407</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0408</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0410</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0412</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150086"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150087" severity="high">
    <xccdf:title>RHSA-2015:0087: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's SCTP implementation
validated INIT chunks when performing Address Configuration Change
(ASCONF). A remote attacker could use this flaw to crash the system by
sending a specially crafted SCTP packet to trigger a NULL pointer
dereference on the system. (CVE-2014-7841, Important)

* An integer overflow flaw was found in the way the Linux kernel's Advanced
Linux Sound Architecture (ALSA) implementation handled user controls.
A local, privileged user could use this flaw to crash the system.
(CVE-2014-4656, Moderate)

The CVE-2014-7841 issue was discovered by Liu Wei of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150087"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150090" severity="high">
    <xccdf:title>RHSA-2015:0090: glibc security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A heap-based buffer overflow was found in glibc's
__nss_hostname_digits_dots() function, which is used by the gethostbyname()
and gethostbyname2() glibc function calls. A remote attacker able to make
an application call either of these functions could use this flaw to
execute arbitrary code with the permissions of the user running the
application. (CVE-2015-0235)

Red Hat would like to thank Qualys for reporting this issue.

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150092" severity="high">
    <xccdf:title>RHSA-2015:0092: glibc security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A heap-based buffer overflow was found in glibc's
__nss_hostname_digits_dots() function, which is used by the gethostbyname()
and gethostbyname2() glibc function calls. A remote attacker able to make
an application call either of these functions could use this flaw to
execute arbitrary code with the permissions of the user running the
application. (CVE-2015-0235)

Red Hat would like to thank Qualys for reporting this issue.

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0092</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0235</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150092"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150100" severity="medium">
    <xccdf:title>RHSA-2015:0100: libyaml security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>YAML is a data serialization format designed for human readability and
interaction with scripting languages. LibYAML is a YAML parser and emitter
written in C.

An assertion failure was found in the way the libyaml library parsed
wrapped strings. An attacker able to load specially crafted YAML input into
an application using libyaml could cause the application to crash.
(CVE-2014-9130)

All libyaml users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against the libyaml library must be restarted for this update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0100</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9130</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150100"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150102" severity="high">
    <xccdf:title>RHSA-2015:0102: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's SCTP implementation
validated INIT chunks when performing Address Configuration Change
(ASCONF). A remote attacker could use this flaw to crash the system by
sending a specially crafted SCTP packet to trigger a NULL pointer
dereference on the system. (CVE-2014-7841, Important)

* A race condition flaw was found in the way the Linux kernel's mmap(2),
madvise(2), and fallocate(2) system calls interacted with each other while
operating on virtual memory file system files. A local user could use this
flaw to cause a denial of service. (CVE-2014-4171, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
Common Internet File System (CIFS) implementation handled mounting of file
system shares. A remote attacker could use this flaw to crash a client
system that would mount a file system share from a malicious server.
(CVE-2014-7145, Moderate)

* A flaw was found in the way the Linux kernel's splice() system call
validated its parameters. On certain file systems, a local, unprivileged
user could use this flaw to write past the maximum file size, and thus
crash the system. (CVE-2014-7822, Moderate)

* It was found that the parse_rock_ridge_inode_internal() function of the
Linux kernel's ISOFS implementation did not correctly check relocated
directories when processing Rock Ridge child link (CL) tags. An attacker
with physical access to the system could use a specially crafted ISO image
to crash the system or, potentially, escalate their privileges on the
system. (CVE-2014-5471, CVE-2014-5472, Low)

Red Hat would like to thank Akira Fujita of NEC for reporting the
CVE-2014-7822 issue. The CVE-2014-7841 issue was discovered by Liu Wei of
Red Hat.

This update also fixes the following bugs:

* Previously, a kernel panic could occur if a process reading from a locked
NFS file was killed and the lock was not released properly before the read
operations finished. Consequently, the system crashed. The code handling
file locks has been fixed, and instead of halting, the system now emits a
warning about the unreleased lock. (BZ#1172266)

* A race condition in the command abort handling logic of the ipr device
driver could cause the kernel to panic when the driver received a response
to an abort command prior to receiving other responses to the aborted
command due to the support for multiple interrupts. With this update, the
abort handler waits for the aborted command's responses first before
completing an abort operation. (BZ#1162734)

* Previously, a race condition could occur when changing a Page Table Entry
(PTE) or a Page Middle Directory (PMD) to "pte_numa" or "pmd_numa",
respectively, causing the kernel to crash. This update removes the BUG_ON()
macro from the __handle_mm_fault() function, preventing the kernel panic in
the aforementioned scenario. (BZ#1170662)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0102</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7145</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7841</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150102"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150118" severity="medium">
    <xccdf:title>RHSA-2015:0118: mariadb security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MariaDB is a multi-user, multi-threaded SQL database server that is binary
compatible with MySQL.

This update fixes several vulnerabilities in the MariaDB database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2015-0381,
CVE-2015-0382, CVE-2015-0391, CVE-2015-0411, CVE-2015-0432, CVE-2014-6568,
CVE-2015-0374)

These updated packages upgrade MariaDB to version 5.5.41. Refer to the
MariaDB Release Notes listed in the References section for a complete list
of changes.

All MariaDB users should upgrade to these updated packages, which correct
these issues. After installing this update, the MariaDB server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0118</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0381</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0432</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150118"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150164" severity="medium">
    <xccdf:title>RHSA-2015:0164: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's splice() system call
validated its parameters. On certain file systems, a local, unprivileged
user could use this flaw to write past the maximum file size, and thus
crash the system. (CVE-2014-7822, Moderate)

Red Hat would like to thank Akira Fujita of NEC for reporting this issue.

This update also fixes the following bugs:

* Previously, hot-unplugging of a virtio-blk device could in some cases
lead to a kernel panic, for example during in-flight I/O requests.
This update fixes race condition in the hot-unplug code in the
virtio_blk.ko module. As a result, hot unplugging of the virtio-blk device
no longer causes the guest kernel oops when there are in-flight I/O
requests. (BZ#1006536)

* Before this update, due to a bug in the error-handling path, a corrupted
metadata block could be used as a valid block. With this update, the error
handling path has been fixed and more checks have been added to verify the
metadata block. Now, when a corrupted metadata block is encountered, it is
properly marked as corrupted and handled accordingly. (BZ#1034403)

* Previously, an incorrectly initialized variable resulted in a random
value being stored in the variable that holds the number of default ACLs,
and is sent in the SET_PATH_INFO data structure. Consequently, the setfacl
command could, under certain circumstances, fail with an "Invalid argument"
error. With this update, the variable is correctly initialized to zero,
thus fixing the bug. (BZ#1105625)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0164</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7822</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150164"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150165" severity="medium">
    <xccdf:title>RHSA-2015:0165: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access
to Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled REPORT requests. A remote, unauthenticated attacker could use a
specially crafted REPORT request to crash mod_dav_svn. (CVE-2014-3580)

It was discovered that Subversion clients retrieved cached authentication
credentials using the MD5 hash of the server realm string without also
checking the server's URL. A malicious server able to provide a realm that
triggers an MD5 collision could possibly use this flaw to obtain the
credentials for a different realm. (CVE-2014-3528)

Red Hat would like to thank the Subversion project for reporting
CVE-2014-3580. Upstream acknowledges Evgeny Kotkov of VisualSVN as the
original reporter.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3580</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150165"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150166" severity="medium">
    <xccdf:title>RHSA-2015:0166: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access
to Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled REPORT requests. A remote, unauthenticated attacker could use a
specially crafted REPORT request to crash mod_dav_svn. (CVE-2014-3580)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled certain requests for URIs that trigger a lookup of a virtual
transaction name. A remote, unauthenticated attacker could send a request
for a virtual transaction name that does not exist, causing mod_dav_svn to
crash. (CVE-2014-8108)

It was discovered that Subversion clients retrieved cached authentication
credentials using the MD5 hash of the server realm string without also
checking the server's URL. A malicious server able to provide a realm that
triggers an MD5 collision could possibly use this flaw to obtain the
credentials for a different realm. (CVE-2014-3528)

Red Hat would like to thank the Subversion project for reporting
CVE-2014-3580 and CVE-2014-8108. Upstream acknowledges Evgeny Kotkov of
VisualSVN as the original reporter.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3528</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3580</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8108</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150166"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150249" severity="high">
    <xccdf:title>RHSA-2015:0249: samba3x security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

An uninitialized pointer use flaw was found in the Samba daemon (smbd).
A malicious Samba client could send specially crafted netlogon packets
that, when processed by smbd, could potentially lead to arbitrary code
execution with the privileges of the user running smbd (by default, the
root user). (CVE-2015-0240)

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1346913

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research
as the original reporter of this issue.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150249"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150250" severity="high">
    <xccdf:title>RHSA-2015:0250: samba4 security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

An uninitialized pointer use flaw was found in the Samba daemon (smbd).
A malicious Samba client could send specially crafted netlogon packets
that, when processed by smbd, could potentially lead to arbitrary code
execution with the privileges of the user running smbd (by default, the
root user). (CVE-2015-0240)

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1346913

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research
as the original reporter of this issue.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0250</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150250"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150251" severity="high">
    <xccdf:title>RHSA-2015:0251: samba security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

An uninitialized pointer use flaw was found in the Samba daemon (smbd).
A malicious Samba client could send specially crafted netlogon packets
that, when processed by smbd, could potentially lead to arbitrary code
execution with the privileges of the user running smbd (by default, the
root user). (CVE-2015-0240)

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1346913

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research
as the original reporter of this issue.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0251</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150251"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150252" severity="high">
    <xccdf:title>RHSA-2015:0252: samba security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

An uninitialized pointer use flaw was found in the Samba daemon (smbd).
A malicious Samba client could send specially crafted netlogon packets
that, when processed by smbd, could potentially lead to arbitrary code
execution with the privileges of the user running smbd (by default, the
root user). (CVE-2015-0240)

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1346913

Red Hat would like to thank the Samba project for reporting this issue.
Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research
as the original reporter of this issue.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150252"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150265" severity="high">
    <xccdf:title>RHSA-2015:0265: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-0836, CVE-2015-0831, CVE-2015-0827)

An information leak flaw was found in the way Firefox implemented
autocomplete forms. An attacker able to trick a user into specifying a
local file in the form could use this flaw to access the contents of that
file. (CVE-2015-0822)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Carsten Book, Christoph Diehl, Gary Kwong, Jan de
Mooij, Liz Henry, Byron Campen, Tom Schuster, Ryan VanderMeulen, Paul
Bandha, Abhishek Arya, and Armin Razmdjou as the original reporters of
these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0265</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0836</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150265"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150266" severity="high">
    <xccdf:title>RHSA-2015:0266: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-0836, CVE-2015-0831, CVE-2015-0827)

An information leak flaw was found in the way Thunderbird implemented
autocomplete forms. An attacker able to trick a user into specifying a
local file in the form could use this flaw to access the contents of that
file. (CVE-2015-0822)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Carsten Book, Christoph Diehl, Gary Kwong, Jan de
Mooij, Liz Henry, Byron Campen, Tom Schuster, Ryan VanderMeulen, Paul
Bandha, Abhishek Arya, and Armin Razmdjou as the original reporters of
these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0266</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0836</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150266"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150290" severity="high">
    <xccdf:title>RHSA-2015:0290: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's XFS file system handled
replacing of remote attributes under certain conditions. A local user with
access to XFS file system mount could potentially use this flaw to escalate
their privileges on the system. (CVE-2015-0274, Important)

* It was found that the Linux kernel's KVM implementation did not ensure
that the host CR4 control register value remained unchanged across VM
entries on the same virtual CPU. A local, unprivileged user could use this
flaw to cause denial of service on the system. (CVE-2014-3690, Moderate)

* A flaw was found in the way Linux kernel's Transparent Huge Pages (THP)
implementation handled non-huge page migration. A local, unprivileged user
could use this flaw to crash the kernel by migrating transparent hugepages.
(CVE-2014-3940, Moderate)

* An out-of-bounds memory access flaw was found in the syscall tracing
functionality of the Linux kernel's perf subsystem. A local, unprivileged
user could use this flaw to crash the system. (CVE-2014-7825, Moderate)

* An out-of-bounds memory access flaw was found in the syscall tracing
functionality of the Linux kernel's ftrace subsystem. On a system with
ftrace syscall tracing enabled, a local, unprivileged user could use this
flaw to crash the system, or escalate their privileges. (CVE-2014-7826,
Moderate)

* A race condition flaw was found in the Linux kernel's ext4 file system
implementation that allowed a local, unprivileged user to crash the system
by simultaneously writing to a file and toggling the O_DIRECT flag using
fcntl(F_SETFL) on that file. (CVE-2014-8086, Moderate)

* A flaw was found in the way the Linux kernel's netfilter subsystem
handled generic protocol tracking. As demonstrated in the Stream Control
Transmission Protocol (SCTP) case, a remote attacker could use this flaw to
bypass intended iptables rule restrictions when the associated connection
tracking module was not loaded on the system. (CVE-2014-8160, Moderate)

* It was found that due to excessive files_lock locking, a soft lockup
could be triggered in the Linux kernel when performing asynchronous I/O
operations. A local, unprivileged user could use this flaw to crash the
system. (CVE-2014-8172, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
madvise MADV_WILLNEED functionality handled page table locking. A local,
unprivileged user could use this flaw to crash the system. (CVE-2014-8173,
Moderate)

* An information leak flaw was found in the Linux kernel's IEEE 802.11
wireless networking implementation. When software encryption was used, a
remote attacker could use this flaw to leak up to 8 bytes of plaintext.
(CVE-2014-8709, Low)

* A stack-based buffer overflow flaw was found in the TechnoTrend/Hauppauge
DEC USB device driver. A local user with write access to the corresponding
device could use this flaw to crash the kernel or, potentially, elevate
their privileges on the system. (CVE-2014-8884, Low)

Red Hat would like to thank Eric Windisch of the Docker project for
reporting CVE-2015-0274, Andy Lutomirski for reporting CVE-2014-3690, and
Robert Święcki for reporting CVE-2014-7825 and CVE-2014-7826.

This update also fixes several hundred bugs and adds numerous enhancements.
Refer to the Red Hat Enterprise Linux 7.1 Release Notes for information on
the most significant of these changes, and the following Knowledgebase
article for further information: https://access.redhat.com/articles/1352803

All Red Hat Enterprise Linux 7 users are advised to install these updated
packages, which correct these issues and add these enhancements. The system
must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7826</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8173</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0274</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150290"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150301" severity="medium">
    <xccdf:title>RHSA-2015:0301: hivex security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Hive files are undocumented binary files that Windows uses to store the
Windows Registry on disk. Hivex is a library that can read and write to
these files.

It was found that hivex attempted to read beyond its allocated buffer when
reading a hive file with a very small size or with a truncated or
improperly formatted content. An attacker able to supply a specially
crafted hive file to an application using the hivex library could possibly
use this flaw to execute arbitrary code with the privileges of the user
running that application. (CVE-2014-9273)

Red Hat would like to thank Mahmoud Al-Qudsi of NeoSmart Technologies for
reporting this issue.

The hivex package has been upgraded to upstream version 1.3.10, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1023978)

This update also fixes the following bugs:

* Due to an error in the hivex_value_data_cell_offset() function, the hivex
utility could, in some cases, print an "Argument list is too long" message
and terminate unexpectedly when processing hive files from the Windows
Registry. This update fixes the underlying code and hivex now processes
hive files as expected. (BZ#1145056)

* A typographical error in the Win::Hivex.3pm manual page has been
corrected. (BZ#1099286)

Users of hivex are advised to upgrade to these updated packages, which
correct these issues and adds these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9273</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150301"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150323" severity="low">
    <xccdf:title>RHSA-2015:0323: libvirt security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libvirt library is a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems.

It was found that QEMU's qemuDomainMigratePerform() and qemuDomainMigrateFinish2() functions did not correctly perform a domain unlock on a failed ACL check. A remote attacker able to establish a connection to libvirtd could use this flaw to lock a domain of a more privileged user, causing a denial of service. (CVE-2014-8136)

It was discovered that the virDomainSnapshotGetXMLDesc() and virDomainSaveImageGetXMLDesc() functions did not sufficiently limit the usage of the VIR_DOMAIN_XML_SECURE flag when fine-grained ACLs were enabled. A remote attacker able to establish a connection to libvirtd could use this flaw to obtain certain sensitive information from the domain XML file. (CVE-2015-0236)

The CVE-2015-0236 issue was found by Luyao Huang of Red Hat.

Bug fixes:

* The libvirtd daemon previously attempted to search for SELinux contexts even when SELinux was disabled on the host. Consequently, libvirtd logged "Unable to lookup SELinux process context" error messages every time a client connected to libvirtd and SELinux was disabled. libvirtd now verifies whether SELinux is enabled before searching for SELinux contexts, and no longer logs the error messages on a host with SELinux disabled. (BZ#1135155)

* The libvirt utility passed incomplete PCI addresses to QEMU. Consequently, assigning a PCI device that had a PCI address with a non-zero domain to a guest failed. Now, libvirt properly passes PCI domain to QEMU when assigning PCI devices, which prevents the described problem. (BZ#1127080)

* Because the virDomainSetMaxMemory API did not allow changing the current memory in the LXC driver, the "virsh setmaxmem" command failed when attempting to set the maximum memory to be lower than the current memory. Now, "virsh setmaxmem" sets the current memory to the intended value of the maximum memory, which avoids the mentioned problem. (BZ#1091132)

* Attempting to start a non-existent domain caused network filters to stay locked for read-only access. Because of this, subsequent attempts to gain read-write access to network filters triggered a deadlock. Network filters are now properly unlocked in the described scenario, and the deadlock no longer occurs. (BZ#1088864)

* If a guest configuration had an active nwfilter using the DHCP snooping feature and an attempt was made to terminate libvirtd before the associated nwfilter rule snooped the guest IP address from DHCP packets, libvirtd became unresponsive. This problem has been fixed by setting a longer wait time for snooping the guest IP address. (BZ#1075543)

Enhancements:

* A new "migrate_host" option is now available in /etc/libvirt/qemu.conf, which allows users to set a custom IP address to be used for incoming migrations. (BZ#1087671)

* With this update, libvirt is able to create a compressed memory-only crash dump of a QEMU domain. This type of crash dump is directly readable by the GNU Debugger and requires significantly less hard disk space than the standard crash dump. (BZ#1035158)

* Support for reporting the NUMA node distance of the host has been added to libvirt. This enhances the current libvirt capabilities for reporting NUMA topology of the host, and allows for easier optimization of new domains. (BZ#1086331)

* The XML file of guest and host capabilities generated by the "virsh capabilities" command has been enhanced to list the following information, where relevant: the interface speed and link status of the host, the PCI Express (PCIe) details, the host's hardware support for I/O virtualization, and a report on the huge memory pages. (BZ#1076960, BZ#1076957, BZ#1076959, BZ#1076962)

These packages also include a number of other bug fixes and enhancements. For additional details, see the "Bugs Fixed" section below.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0323</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8136</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0236</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150323"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150325" severity="low">
    <xccdf:title>RHSA-2015:0325: httpd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

A flaw was found in the way httpd handled HTTP Trailer headers when processing requests using chunked encoding. A malicious client could use Trailer headers to set additional HTTP headers after header processing was performed by other modules. This could, for example, lead to a bypass of header restrictions defined with mod_headers. (CVE-2013-5704)

A NULL pointer dereference flaw was found in the way the mod_cache httpd module handled Content-Type headers. A malicious HTTP server could cause the httpd child process to crash when the Apache HTTP server was configured to proxy to a server with caching enabled. (CVE-2014-3581)

This update also fixes the following bugs:

* Previously, the mod_proxy_fcgi Apache module always kept the back-end connections open even when they should have been closed. As a consequence, the number of open file descriptors was increasing over the time. With this update, mod_proxy_fcgi has been fixed to check the state of the back-end connections, and it closes the idle back-end connections as expected. (BZ#1168050)

* An integer overflow occurred in the ab utility when a large request count was used. Consequently, ab terminated unexpectedly with a segmentation fault while printing statistics after the benchmark. This bug has been fixed, and ab no longer crashes in this scenario. (BZ#1092420)

* Previously, when httpd was running in the foreground and the user pressed Ctrl+C to interrupt the httpd processes, a race condition in signal handling occurred. The SIGINT signal was sent to all children followed by SIGTERM from the main process, which interrupted the SIGINT handler. Consequently, the affected processes became unresponsive or terminated unexpectedly. With this update, the SIGINT signals in the child processes are ignored, and httpd no longer hangs or crashes in this scenario. (BZ#1131006)

In addition, this update adds the following enhancements:

* With this update, the mod_proxy module of the Apache HTTP Server supports the Unix Domain Sockets (UDS). This allows mod_proxy back ends to listen on UDS sockets instead of TCP sockets, and as a result, mod_proxy can be used to connect UDS back ends. (BZ#1168081)

* This update adds support for using the SetHandler directive together with the mod_proxy module. As a result, it is possible to configure SetHandler to use proxy for incoming requests, for example, in the following format: SetHandler "proxy:fcgi://127.0.0.1:9000". (BZ#1136290)

* The htaccess API changes introduced in httpd 2.4.7 have been backported to httpd shipped with Red Hat Enterprise Linux 7.1. These changes allow for the MPM-ITK module to be compiled as an httpd module. (BZ#1059143)

All httpd users are advised to upgrade to these updated packages, which contain backported patches to correct these issues and add these enhancements. After installing the updated packages, the httpd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0325</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5704</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3581</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150325"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150327" severity="medium">
    <xccdf:title>RHSA-2015:0327: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

An out-of-bounds read flaw was found in the way glibc's iconv() function
converted certain encoded data to UTF-8. An attacker able to make an
application call the iconv() function with a specially crafted argument
could use this flaw to crash that application. (CVE-2014-6040)

It was found that the files back end of Name Service Switch (NSS) did not
isolate iteration over an entire database from key-based look-up API calls.
An application performing look-ups on a database while iterating over it
could enter an infinite loop, leading to a denial of service.
(CVE-2014-8121)

This update also fixes the following bugs:

* Due to problems with buffer extension and reallocation, the nscd daemon
terminated unexpectedly with a segmentation fault when processing long
netgroup entries. With this update, the handling of long netgroup entries
has been corrected and nscd no longer crashes in the described scenario.
(BZ#1138520)

* If a file opened in append mode was truncated with the ftruncate()
function, a subsequent ftell() call could incorrectly modify the file
offset. This update ensures that ftell() modifies the stream state only
when it is in append mode and the buffer for the stream is not empty.
(BZ#1156331)

* A defect in the C library headers caused builds with older compilers to
generate incorrect code for the btowc() function in the older compatibility C++ standard library. Applications calling btowc() in the compatibility C++ standard library became unresponsive. With this update, the C library headers have been corrected, and the compatibility C++ standard library shipped with Red Hat Enterprise Linux has been rebuilt. Applications that rely on the compatibility C++ standard library no longer hang when calling btowc(). (BZ#1120490)

* Previously, when using netgroups and the nscd daemon was set up to cache netgroup information, the sudo utility denied access to valid users. The bug in nscd has been fixed, and sudo now works in netgroups as
expected. (BZ#1080766)

Users of glibc are advised to upgrade to these updated packages, which fix these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0327</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6040</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8121</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150327"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150330" severity="low">
    <xccdf:title>RHSA-2015:0330: pcre security and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PCRE is a Perl-compatible regular expression library.

A flaw was found in the way PCRE handled certain malformed regular
expressions. This issue could cause an application (for example, Konqueror)
linked against PCRE to crash while parsing malicious regular expressions.
(CVE-2014-8964)

This update also adds the following enhancement:

* Support for the little-endian variant of IBM Power Systems has been added to the pcre packages. (BZ#1123498, BZ#1125642)

All pcre users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8964</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150330"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150349" severity="high">
    <xccdf:title>RHSA-2015:0349: qemu-kvm security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm packages provide the user-space component for running virtual machines using KVM.

It was found that the Cirrus blit region checks were insufficient. A privileged guest user could use this flaw to write outside of VRAM-allocated buffer boundaries in the host's QEMU process address space with attacker-provided data. (CVE-2014-8106)

An uninitialized data structure use flaw was found in the way the set_pixel_format() function sanitized the value of bits_per_pixel. An attacker able to access a guest's VNC console could use this flaw to crash the guest. (CVE-2014-7815)

It was found that certain values that were read when loading RAM during migration were not validated. A user able to alter the savevm data (either on the disk or over the wire during migration) could use either of these flaws to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process. (CVE-2014-7840)

A NULL pointer dereference flaw was found in the way QEMU handled UDP packets with a source port and address of 0 when QEMU's user networking was in use. A local guest user could use this flaw to crash the guest. (CVE-2014-3640)

Red Hat would like to thank James Spadaro of Cisco for reporting CVE-2014-7815, and Xavier Mehrenberger and Stephane Duverger of Airbus for reporting CVE-2014-3640. The CVE-2014-8106 issue was found by Paolo Bonzini of Red Hat, and the CVE-2014-7840 issue was discovered by Michael S. Tsirkin of Red Hat.

Bug fixes:

* The KVM utility executed demanding routing update system calls every time it performed an MSI vector mask/unmask operation. Consequently, guests running legacy systems such as Red Hat Enterprise Linux 5 could, under certain circumstances, experience significant slowdown. Now, the routing system calls during mask/unmask operations are skipped, and the performance of legacy guests is now more consistent. (BZ#1098976)

* Due to a bug in the Internet Small Computer System Interface (iSCSI) driver, a qemu-kvm process terminated unexpectedly with a segmentation fault when the "write same" command was executed in guest mode under the iSCSI protocol. This update fixes the bug, and the "write same" command now functions in guest mode under iSCSI as intended. (BZ#1083413)

* The QEMU command interface did not properly handle resizing of cache memory during guest migration, causing QEMU to terminate unexpectedly with a segmentation fault. This update fixes the related code, and QEMU no longer crashes in the described situation. (BZ#1066338)

Enhancements:

* The maximum number of supported virtual CPUs (vCPUs) in a KVM guest has been increased to 240. This increases the number of virtual processing units that the user can assign to the guest, and therefore improves its performance potential. (BZ#1134408)

* Support for the 5th Generation Intel Core processors has been added to the QEMU hypervisor, the KVM kernel code, and the libvirt API. This allows KVM guests to use the following instructions and features: ADCX, ADOX, RDSFEED, PREFETCHW, and supervisor mode access prevention (SMAP). (BZ#1116117)

* The "dump-guest-memory" command now supports crash dump compression. This makes it possible for users who cannot use the "virsh dump" command to require less hard disk space for guest crash dumps. In addition, saving a compressed guest crash dump frequently takes less time than saving a non-compressed one. (BZ#1157798)

* This update introduces support for flight recorder tracing, which uses SystemTap to automatically capture qemu-kvm data while the guest machine is running. For detailed instructions on how to configure and use flight recorder tracing, see the Virtualization Deployment and Administration Guide, linked to in the References section below. (BZ#1088112)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0349</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8106</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150349"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150377" severity="medium">
    <xccdf:title>RHSA-2015:0377: libreoffice security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibreOffice is an open source, community-developed office productivity
suite. It includes key desktop applications, such as a word processor, a
spreadsheet, a presentation manager, a formula editor, and a drawing
program. LibreOffice replaces OpenOffice and provides a similar but
enhanced and extended office suite.

It was found that LibreOffice documents executed macros unconditionally,
without user approval, when these documents were opened using LibreOffice.
An attacker could use this flaw to execute arbitrary code as the user
running LibreOffice by embedding malicious VBA scripts in the document as
macros. (CVE-2014-0247)

A flaw was found in the OLE (Object Linking and Embedding) generation in
LibreOffice. An attacker could use this flaw to embed malicious OLE code in
a LibreOffice document, allowing for arbitrary code execution.
(CVE-2014-3575)

A use-after-free flaw was found in the "Remote Control" capabilities of the
LibreOffice Impress application. An attacker could use this flaw to
remotely execute code with the permissions of the user running LibreOffice
Impress. (CVE-2014-3693)

The libreoffice packages have been upgraded to upstream version 4.2.6.3,
which provides a number of bug fixes and enhancements over the previous
version. Among others:

* Improved OpenXML interoperability.

* Additional statistic functions in Calc (for interoperability with Excel
and Excel's Add-in "Analysis ToolPak").

* Various performance improvements in Calc.

* Apple Keynote and Abiword import.

* Improved MathML export.

* New Start screen with thumbnails of recently opened documents.

* Visual clue in Slide Sorter when a slide has a transition or an
animation.

* Improvements for trend lines in charts.

* Support for BCP-47 language tags. (BZ#1119709)

All libreoffice users are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0377</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0247</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3693</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150377"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150383" severity="medium">
    <xccdf:title>RHSA-2015:0383: ppc64-diag security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ppc64-diag packages provide diagnostic tools for Linux on the 64-bit
PowerPC platforms. The platform diagnostics write events reported by the
firmware to the service log, provide automated responses to urgent events,
and notify system administrators or connected service frameworks about the
reported events.

Multiple insecure temporary file use flaws were found in the way the
ppc64-diag utility created certain temporary files. A local attacker could
possibly use either of these flaws to perform a symbolic link attack and
overwrite arbitrary files with the privileges of the user running
ppc64-diag, or obtain sensitive information from the temporary files.
(CVE-2014-4038, CVE-2014-4039)

The ppc64-diag packages have been upgraded to upstream version 2.6.7, which
provides a number of bug fixes and enhancements over the previous version
including support for hot plugging of QEMU PCI devices. (BZ#1088493,
BZ#1084062)

This update also fixes the following bugs:

* Prior to this update, the rtas_errd daemon was not started by default on
system boot. With this update, rtas_errd has been modified to start
automatically by default. (BZ#1170146)

* Previously, the /var/log/dump file was not automatically created when
installing the ppc64-diag package. This bug has been fixed, and
/var/log/dump is now created at package install time as expected.
(BZ#1175808)

In addition, this update adds the following enhancement:

* This update adds support for building the ppc64-diag packages on the
little-endian variant of IBM Power Systems platform architecture. (BZ#1124007)

Users of ppc64-diag are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4039</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150383"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150384" severity="low">
    <xccdf:title>RHSA-2015:0384: powerpc-utils security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The powerpc-utils packages provide various utilities for the PowerPC platform.

A flaw was found in the way the snap utility of powerpc-utils generated an archive containing a configuration snapshot of a service. A local attacker could obtain sensitive information from the generated archive such as plain text passwords. (CVE-2014-4040)

The powerpc-utils packages have been upgraded to the upstream version 1.2.24, which provides a number of bug fixes and enhancements over the previous version. (BZ#1088539, BZ#1167865, BZ#1161552)

This update also fixes the following bugs:

* Previously, the lsdevinfo command did not correctly process the path to the device, which made the path unreadable in the console output of lsdevinfo. With this update, lsdevinfo has been updated and the path is now displayed correctly. (BZ#1079246)

* Previously, after migrating several Linux partitions, Resource Monitoring and Control (RMC) was inactive and Machine Type, Model, and Serial number (MTMS) were set incorrectly, so the subsequent validation operation failed. This bug has been fixed, and validation is now successful after migration and suspend. (BZ#1083221)

* Previously, when the drmgr tool attempted to remove the last CPU from the system, drmgr became unresponsive or terminated unexpectedly. This bug has been fixed, and drmgr no longer hangs or crashes in the described case. (BZ#1152313)

* With this update, the drmgr utility has been fixed to correctly gather Logical Memory Block (LMB) information while performing Mem Dynamic Logical Partitioning (DLPAR) on little-endian varian of IBM Power Systems CPU architecture as expected (BZ#1170856).

* Previously, the "ppc64_cpu --threads-per-core" command returned incorrect data with the --smt option enabled. This bug has been fixed and "ppc64_cpu --threads-per-core" now reports correctly with enabled --smt. (BZ#1179263)

In addition, this update adds the following enhancements:

* This update adds support for the Red Hat Enterprise Linux for POWER, little endian CPU architecture to the powerpc-utils package. (BZ#1124006)

* This update adds support for hot plugging of the qemu virtio device with the drmgr command to the powerpc-utils package.(BZ#1083791)

* The deprecated snap tool has been removed from the powerpc-utils packages. Its functionality has been integrated into the sosreport tool. (BZ#1172087)

* With this update, a dependency on the perl-Data-Dumper package required by the rtas_dump utility has been added to powerpc-utils packages. (BZ#1175812) 

Users of powerpc-utils are advised to upgrade to these updated packages, which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0384</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4040</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150384"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150416" severity="high">
    <xccdf:title>RHSA-2015:0416: 389-ds-base security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

An information disclosure flaw was found in the way the 389 Directory Server stored information in the Changelog that is exposed via the 'cn=changelog' LDAP sub-tree. An unauthenticated user could in certain cases use this flaw to read data from the Changelog, which could include sensitive information such as plain-text passwords.
(CVE-2014-8105)

It was found that when the nsslapd-unhashed-pw-switch 389 Directory Server configuration option was set to "off", it did not prevent the writing of unhashed passwords into the Changelog. This could potentially allow an authenticated user able to access the Changelog to read sensitive information. (CVE-2014-8112)

The CVE-2014-8105 issue was discovered by Petr Špaček of the Red Hat Identity Management Engineering Team, and the CVE-2014-8112 issue was discovered by Ludwig Krispenz of the Red Hat Identity Management Engineering Team.

Enhancements:

* Added new WinSync configuration parameters: winSyncSubtreePair for synchronizing multiple subtrees, as well as winSyncWindowsFilter and winSyncDirectoryFilter for synchronizing restricted sets by filters. (BZ#746646)

* It is now possible to stop, start, or configure plug-ins without the need to restart the server for the change to take effect. (BZ#994690)

* Access control related to the MODDN and MODRDN operations has been updated: the source and destination targets can be specified in the same access control instruction. (BZ#1118014)

* The nsDS5ReplicaBindDNGroup attribute for using a group distinguished name in binding to replicas has been added. (BZ#1052754)

* WinSync now supports range retrieval. If more than the MaxValRange number of attribute values exist per attribute, WinSync synchronizes all the attributes to the directory server using the range retrieval. (BZ#1044149)

* Support for the RFC 4527 Read Entry Controls and RFC 4533 Content Synchronization Operation LDAP standards has been added. (BZ#1044139, BZ#1044159)

* The Referential Integrity (referint) plug-in can now use an alternate configuration area. The PlugInArg plug-in configuration now uses unique configuration attributes. Configuration changes no longer require a server restart. (BZ#1044203)

* The logconv.pl log analysis tool now supports gzip, bzip2, and xz compressed files and also TAR archives and compressed TAR archives of these files. (BZ#1044188)

* Only the Directory Manager could add encoded passwords or force users to change their password after a reset. Users defined in the passwordAdminDN attribute can now also do this. (BZ#1118007)

* The "nsslapd-memberofScope" configuration parameter has been added to the MemberOf plug-in. With MemberOf enabled and a scope defined, moving a group out of scope with a MODRDN operation failed. Moving a member entry out of scope now correctly removes the memberof value. (BZ#1044170)

* The alwaysRecordLoginAttr attribute has been addded to the Account Policy plug-in configuration entry, which allows to distinguish between an attribute for checking the activity of an account and an attribute to be updated at successful login. (BZ#1060032)

* A root DSE search, using the ldapsearch command with the '-s base -b ""' options, returns only the user attributes instead of the operational attributes. The "nsslapd-return-default" option has been added for backward compatibility. (BZ#1118021)

* The configuration of the MemberOf plug-in can be stored in a suffix mapped to a back-end database, which allows MemberOf configuration to be replicated. (BZ#1044205)

* Added support for the SSL versions from the range supported by the NSS library available on the system. Due to the POODLE vulnerability, SSLv3 is disabled by default even if NSS supports it. (BZ#1044191)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0416</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8105</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8112</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150416"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150425" severity="medium">
    <xccdf:title>RHSA-2015:0425: openssh security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These packages include the core files necessary for both the OpenSSH client and server.

It was discovered that OpenSSH clients did not correctly verify DNS SSHFP records. A malicious server could use this flaw to force a connecting client to skip the DNS SSHFP record check and require the user to perform manual host verification of the DNS SSHFP record. (CVE-2014-2653)

It was found that when OpenSSH was used in a Kerberos environment, remote authenticated users were allowed to log in as a different user if they were listed in the ~/.k5users file of that user, potentially bypassing intended authentication restrictions. (CVE-2014-9278)

The openssh packages have been upgraded to upstream version 6.6.1, which provides a number of bug fixes and enhancements over the previous version. (BZ#1059667)

Bug fixes:

* An existing /dev/log socket is needed when logging using the syslog utility, which is not possible for all chroot environments based on the user's home directories. As a consequence, the sftp commands were not logged in the chroot setup without /dev/log in the internal sftp subsystem. With this update, openssh has been enhanced to detect whether /dev/log exists. If /dev/log does not exist, processes in the chroot environment use their master processes for logging. (BZ#1083482)

* The buffer size for a host name was limited to 64 bytes. As a consequence, when a host name was 64 bytes long or longer, the ssh-keygen utility failed. The buffer size has been increased to fix this bug, and ssh-keygen no longer fails in the described situation. (BZ#1097665)

* Non-ASCII characters have been replaced by their octal representations in banner messages in order to prevent terminal re-programming attacks. Consequently, banners containing UTF-8 strings were not correctly displayed in a client. With this update, banner messages are processed according to RFC 3454, control characters have been removed, and banners containing UTF-8 strings are now displayed correctly. (BZ#1104662)

* Red Hat Enterprise Linux uses persistent Kerberos credential caches, which are shared between sessions. Previously, the GSSAPICleanupCredentials option was set to "yes" by default. Consequently, removing a Kerberos cache on logout could remove unrelated credentials of other sessions, which could make the system unusable. To fix this bug, GSSAPICleanupCredentials is set by default to "no". (BZ#1134447)

* Access permissions for the /etc/ssh/moduli file were set to 0600, which was unnecessarily strict. With this update, the permissions for /etc/ssh/moduli have been changed to 0644 to make the access to the file easier. (BZ#1134448)

* Due to the KRB5CCNAME variable being truncated, the Kerberos ticket cache was not found after login using a Kerberos-enabled SSH connection. The underlying source code has been modified to fix this bug, and Kerberos authentication works as expected in the described situation. (BZ#1161173)

Enhancements:

* When the sshd daemon is configured to force the internal SFTP session, a connection other then SFTP is used, the appropriate message is logged to the /var/log/secure file. (BZ#1130198)

* The sshd-keygen service was run using the "ExecStartPre=-/usr/sbin/sshd-keygen" option in the sshd.service unit file. With this update, the separate sshd-keygen.service unit file has been added, and sshd.service has been adjusted to require sshd-keygen.service. (BZ#1134997)

Users of openssh are advised to upgrade to these updated packages, which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2653</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9278</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150425"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150430" severity="medium">
    <xccdf:title>RHSA-2015:0430: virt-who security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The virt-who package provides an agent that collects information about
virtual guests present in the system and reports them to the
subscription manager.

It was discovered that the /etc/sysconfig/virt-who configuration file,
which may contain hypervisor authentication credentials, was
world-readable. A local user could use this flaw to obtain authentication
credentials from this file. (CVE-2014-0189)

Red Hat would like to thank Sal Castiglione for reporting this issue.

The virt-who package has been upgraded to upstream version 0.11, which
provides a number of bug fixes and enhancements over the previous version.
The most notable bug fixes and enhancements include:

* Support for remote libvirt.
* A fix for using encrypted passwords.
* Bug fixes and enhancements that increase the stability of virt-who.
(BZ#1122489)

This update also fixes the following bugs:

* Prior to this update, the virt-who agent failed to read the list of
virtual guests provided by the VDSM daemon. As a consequence, when in VDSM
mode, the virt-who agent was not able to send updates about virtual guests
to Subscription Asset Manager (SAM) and Red Hat Satellite. With this
update, the agent reads the list of guests when in VDSM mode correctly and
reports to SAM and Satellite as expected. (BZ#1153405)

* Previously, virt-who used incorrect information when connecting to Red
Hat Satellite 5. Consequently, virt-who could not connect to Red Hat
Satellite 5 servers. The incorrect parameter has been corrected, and
virt-who can now successfully connect to Red Hat Satellite 5. (BZ#1158859)

* Prior to this update, virt-who did not decode the hexadecimal
representation of a password before decrypting it. As a consequence, the
decrypted password did not match the original password, and attempts to
connect using the password failed. virt-who has been updated to decode the
encrypted password and, as a result, virt-who now handles storing
credentials using encrypted passwords as expected. (BZ#1161607)

In addition, this update adds the following enhancement:

* With this update, virt-who is able to read the list of guests from a
remote libvirt hypervisor. (BZ#1127965)

Users of virt-who are advised to upgrade to this updated package, which
corrects these issues and adds these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0430</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0189</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150430"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150439" severity="medium">
    <xccdf:title>RHSA-2015:0439: krb5 security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO acceptor for continuation tokens. A remote, unauthenticated attacker could use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer overflow was found in the KADM5 administration server (kadmind) when it was used with an LDAP back end for the KDC database. A remote, authenticated attacker could potentially use this flaw to execute arbitrary code on the system running kadmind. (CVE-2014-4345)

A use-after-free flaw was found in the way the MIT Kerberos libgssapi_krb5 library processed valid context deletion tokens. An attacker able to make an application using the GSS-API library (libgssapi) call the gss_process_context_token() function could use this flaw to crash that application. (CVE-2014-5352)

If kadmind were used with an LDAP back end for the KDC database, a remote, authenticated attacker with the permissions to set the password policy could crash kadmind by attempting to use a named ticket policy object as a password policy for a principal. (CVE-2014-5353)

A double-free flaw was found in the way MIT Kerberos handled invalid External Data Representation (XDR) data. An authenticated user could use this flaw to crash the MIT Kerberos administration server (kadmind), or other applications using Kerberos libraries, using specially crafted XDR packets. (CVE-2014-9421)

It was found that the MIT Kerberos administration server (kadmind) incorrectly accepted certain authentication requests for two-component server principal names. A remote attacker able to acquire a key with a particularly named principal (such as "kad/x") could use this flaw to impersonate any user to kadmind, and perform administrative actions as that user. (CVE-2014-9422)

An information disclosure flaw was found in the way MIT Kerberos RPCSEC_GSS implementation (libgssrpc) handled certain requests. An attacker could send a specially crafted request to an application using libgssrpc to disclose a limited portion of uninitialized memory used by that application. (CVE-2014-9423)

Two buffer over-read flaws were found in the way MIT Kerberos handled certain requests. A remote, unauthenticated attacker able to inject packets into a client or server application's GSSAPI session could use either of these flaws to crash the application. (CVE-2014-4341, CVE-2014-4342)

A double-free flaw was found in the MIT Kerberos SPNEGO initiators. An attacker able to spoof packets to appear as though they are from an GSSAPI acceptor could use this flaw to crash a client application that uses MIT Kerberos. (CVE-2014-4343)

Red Hat would like to thank the MIT Kerberos project for reporting the CVE-2014-5352, CVE-2014-9421, CVE-2014-9422, and CVE-2014-9423 issues. MIT Kerberos project acknowledges Nico Williams for helping with the analysis of CVE-2014-5352.

The krb5 packages have been upgraded to upstream version 1.12, which provides a number of bug fixes and enhancements, including:

* Added plug-in interfaces for principal-to-username mapping and verifying authorization to user accounts.

* When communicating with a KDC over a connected TCP or HTTPS socket, the client gives the KDC more time to reply before it transmits the request to another server. (BZ#1049709, BZ#1127995)

This update also fixes multiple bugs, for example:

* The Kerberos client library did not recognize certain exit statuses that the resolver libraries could return when looking up the addresses of servers configured in the /etc/krb5.conf file or locating Kerberos servers using DNS service location. The library could treat non-fatal return codes as fatal errors. Now, the library interprets the specific return codes correctly. (BZ#1084068, BZ#1109102)

In addition, this update adds various enhancements. Among others:

* Added support for contacting KDCs and kpasswd servers through HTTPS proxies implementing the Kerberos KDC Proxy (KKDCP) protocol. (BZ#1109919)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4341</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4342</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4343</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9422</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9423</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150439"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150442" severity="medium">
    <xccdf:title>RHSA-2015:0442: ipa security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Two cross-site scripting (XSS) flaws were found in jQuery, which impacted the Identity Management web administrative interface, and could allow an authenticated user to inject arbitrary HTML or web script into the interface. (CVE-2010-5312, CVE-2012-6662)

Note: The IdM version provided by this update no longer uses jQuery.

This update adds several enhancements that are described in more detail in the Red Hat Enterprise Linux 7.1 Release Notes, linked to in the References section, including:

* Added the "ipa-cacert-manage" command, which renews the Certification Authority (CA) file. (BZ#886645)

* Added the ID Views feature. (BZ#891984)

* IdM now supports using one-time password (OTP) authentication and allows gradual migration from proprietary OTP solutions to the IdM OTP solution. (BZ#919228)

* Added the "ipa-backup" and "ipa-restore" commands to allow manual backups. (BZ#951581)

* Added a solution for regulating access permissions to specific sections of the IdM server. (BZ#976382)

This update also fixes several bugs, including:

* Previously, when IdM servers were configured to require the Transport Layer Security protocol version 1.1 (TLSv1.1) or later in the httpd server, the "ipa" command-line utility failed. With this update, running "ipa" works as expected with TLSv1.1 or later. (BZ#1156466)

In addition, this update adds multiple enhancements, including:

* The "ipa-getkeytab" utility can now optionally fetch existing keytabs from the KDC. Previously, retrieving an existing keytab was not supported, as the only option was to generate a new key. (BZ#1007367)

* You can now create and manage a "." root zone on IdM servers. DNS queries sent to the IdM DNS server use this configured zone instead of the public zone. (BZ#1056202)

* The IdM server web UI has been updated and is now based on the Patternfly framework, offering better responsiveness. (BZ#1108212)

* A new user attribute now enables provisioning systems to add custom tags for user objects. The tags can be used for automember rules or for additional local interpretation. (BZ#1108229)

* This update adds a new DNS zone type to ensure that forward and master zones are better separated. As a result, the IdM DNS interface complies with the forward zone semantics in BIND. (BZ#1114013)

* This update adds a set of Apache modules that external applications can use to achieve tighter interaction with IdM beyond simple authentication. (BZ#1107555)

* IdM supports configuring automember rules for automated assignment of users or hosts in respective groups according to their characteristics, such as the "userClass" or "departmentNumber" attributes. Previously, the rules could be applied only to new entries. This update allows applying the rules also to existing users or hosts. (BZ#1108226)

* The extdom plug-in translates Security Identifiers (SIDs) of Active Directory (AD) users and groups to names and POSIX IDs. With this update, extdom returns the full member list for groups and the full list of group memberships for a user, the GECOS field, the home directory, as well as the login shell of a user. Also, an optional list of key-value pairs contains the SID of the requested object if the SID is available. (BZ#1030699)

All ipa users are advised to upgrade to these updated packages, which contain backported patches to correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0442</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6662</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150442"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150535" severity="low">
    <xccdf:title>RHSA-2015:0535: GNOME Shell security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>GNOME Shell and the packages it depends upon provide the core user interface of the Red Hat Enterprise Linux desktop, including functions such as navigating between windows and launching applications.

It was found that the GNOME shell did not disable the Print Screen key when the screen was locked. This could allow an attacker with physical access to a system with a locked screen to crash the screen-locking application by creating a large amount of screenshots. (CVE-2014-7300)

This update also fixes the following bugs:

* The Timed Login feature, which automatically logs in a specified user after a specified period of time, stopped working after the first user of the GUI logged out. This has been fixed, and the specified user is always logged in if no one else logs in. (BZ#1043571)

* If two monitors were arranged vertically with the secondary monitor above the primary monitor, it was impossible to move windows onto the secondary monitor. With this update, windows can be moved through the upper edge of the first monitor to the secondary monitor. (BZ#1075240)

* If the Gnome Display Manager (GDM) user list was disabled and a user entered the user name, the password prompt did not appear. Instead, the user had to enter the user name one more time. The GDM code that contained this error has been fixed, and users can enter their user names and passwords as expected. (BZ#1109530)

* Prior to this update, only a small area was available on the GDM login screen for a custom text banner. As a consequence, when a long banner was used, it did not fit into the area, and the person reading the banner had to use scrollbars to view the whole text. With this update, more space is used for the banner if necessary, which allows the user to read the message conveniently. (BZ#1110036)

* When the Cancel button was pressed while an LDAP user name and password was being validated, the GDM code did not handle the situation correctly. As a consequence, GDM became unresponsive, and it was impossible to return to the login screen. The affected code has been fixed, and LDAP user validation can be canceled, allowing another user to log in instead. (BZ#1137041)

* If the window focus mode in GNOME was set to "mouse" or "sloppy", navigating through areas of a pop-up menu displayed outside its parent window caused the window to lose its focus. Consequently, the menu was not usable. This has been fixed, and the window focus is kept in under this scenario. (BZ#1149585)

* If user authentication is configured to require a smart card to log in, user names are obtained from the smart card. The authentication is then performed by entering the smart card PIN. Prior to this update, the login screen allowed a user name to be entered if no smart card was inserted, but due to a bug in the underlying code, the screen became unresponsive. If, on the other hand, a smart card was used for authentication, the user was logged in as soon as the authentication was complete. As a consequence, it was impossible to select a session other than GNOME Classic. Both of these problems have been fixed. Now, a smart card is required when this type of authentication is enabled, and any other installed session can be selected by the user. (BZ#1159385, BZ#1163474)

In addition, this update adds the following enhancement:

* Support for quad-buffer OpenGL stereo visuals has been added. As a result, OpenGL applications that use quad-buffer stereo can be run and properly displayed within the GNOME desktop when used with a video driver and hardware with the necessary capabilities. (BZ#861507, BZ#1108890, BZ#1108891, BZ#1108893)

All GNOME Shell users are advised to upgrade to these updated packages, which contain backported patches to correct these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0535</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7300</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150535"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150628" severity="high">
    <xccdf:title>RHSA-2015:0628: 389-ds-base security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

An information disclosure flaw was found in the way the 389 Directory
Server stored information in the Changelog that is exposed via the
'cn=changelog' LDAP sub-tree. An unauthenticated user could in certain
cases use this flaw to read data from the Changelog, which could include
sensitive information such as plain-text passwords. (CVE-2014-8105)

This issue was discovered by Petr Špaček of the Red Hat Identity Management
Engineering Team.

This update also fixes the following bugs:

* In multi-master replication (MMR), deleting a single-valued attribute of
a Directory Server (DS) entry was previously in some cases not correctly
replicated. Consequently, the entry state in the replica systems did not
reflect the intended changes. This bug has been fixed and the removal of a
single-valued attribute is now properly replicated. (BZ#1179099)

* Prior to this update, the Directory Server (DS) always checked the ACI
syntax. As a consequence, removing an ACI failed with a syntax error.
With this update, the ACI check is stopped when the ACI is going to be
removed, and the removal thus works as expected. (BZ#1179100)

In addition, this update adds the following enhancement:

* The buffer size limit for the 389-ds-base application has been increased
to 2MB in order to match the buffer size limit of Simple Authentication and
Security Layer (SASL) and Basic Encoding Rules (BER). (BZ#1179595)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add this
enhancement. After installing this update, the 389 server service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8105</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150628"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150642" severity="high">
    <xccdf:title>RHSA-2015:0642: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-0836, CVE-2015-0831, CVE-2015-0827)

An information leak flaw was found in the way Thunderbird implemented
autocomplete forms. An attacker able to trick a user into specifying a
local file in the form could use this flaw to access the contents of that
file. (CVE-2015-0822)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Carsten Book, Christoph Diehl, Gary Kwong, Jan de
Mooij, Liz Henry, Byron Campen, Tom Schuster, Ryan VanderMeulen, Paul
Bandha, Abhishek Arya, and Armin Razmdjou as the original reporters of
these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0642</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0827</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0831</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0836</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150642"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150672" severity="medium">
    <xccdf:title>RHSA-2015:0672: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled trust anchor management. A remote
attacker could use this flaw to cause the BIND daemon (named) to crash
under certain conditions. (CVE-2015-1349)

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0672</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1349</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150672"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150674" severity="high">
    <xccdf:title>RHSA-2015:0674: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's Infiniband subsystem did not
properly sanitize input parameters while registering memory regions from
user space via the (u)verbs API. A local user with access to a
/dev/infiniband/uverbsX device could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-8159,
Important)

* A flaw was found in the way the Linux kernel's splice() system call
validated its parameters. On certain file systems, a local, unprivileged
user could use this flaw to write past the maximum file size, and thus
crash the system. (CVE-2014-7822, Moderate)

* A flaw was found in the way the Linux kernel's netfilter subsystem
handled generic protocol tracking. As demonstrated in the Stream Control
Transmission Protocol (SCTP) case, a remote attacker could use this flaw to
bypass intended iptables rule restrictions when the associated connection
tracking module was not loaded on the system. (CVE-2014-8160, Moderate)

* It was found that the fix for CVE-2014-3601 was incomplete: the Linux
kernel's kvm_iommu_map_pages() function still handled IOMMU mapping
failures incorrectly. A privileged user in a guest with an assigned host
device could use this flaw to crash the host. (CVE-2014-8369, Moderate)

Red Hat would like to thank Mellanox for reporting CVE-2014-8159, and Akira
Fujita of NEC for reporting CVE-2014-7822.

Bug fixes:

* The maximum amount of entries in the IPv6 route table
(net.ipv6.route.max_size) was 4096, and every route towards this maximum
size limit was counted. Communication to more systems was impossible when
the limit was exceeded. Now, only cached routes are counted, which
guarantees that the kernel does not run out of memory, but the user can now
install as many routes as the memory allows until the kernel indicates it
can no longer handle the amount of memory and returns an error message.

In addition, the default "net.ipv6.route.max_size" value has been increased
to 16384 for performance improvement reasons. (BZ#1177581)

* When the user attempted to scan for an FCOE-served Logical Unit Number
(LUN), after an initial LUN scan, a kernel panic occurred in
bnx2fc_init_task. System scanning for LUNs is now stable after LUNs have
been added. (BZ#1179098)

* Under certain conditions, such as when attempting to scan the network for
LUNs, a race condition in the bnx2fc driver could trigger a kernel panic in
bnx2fc_init_task. A patch fixing a locking issue that caused the race
condition has been applied, and scanning the network for LUNs no longer
leads to a kernel panic. (BZ#1179098)

* Previously, it was not possible to boot the kernel on Xen hypervisor in
PVHVM mode if more than 32 vCPUs were specified in the guest configuration.
Support for more than 32 vCPUs has been added, and the kernel now boots
successfully in the described situation. (BZ#1179343)

* When the NVMe driver allocated a namespace queue, it indicated that it
was a request-based driver when it was actually a block I/O-based driver.
Consequently, when NVMe driver was loaded along with a request-based dm
device, the system could terminate unexpectedly or become unresponsive when
attempting to access data. The NVMe driver no longer sets the
QUEUE_FLAG_STACKABLE bit when allocating a namespace queue and
device-mapper no longer perceives NVMe driver as request-based; system
hangs or crashes no longer occur. (BZ#1180555)

* If a user attempted to apply an NVRAM firmware update when running the
tg3 module provided with Red Hat Enterprise Linux 6.6 kernels, the update
could fail. As a consequence, the Network Interface Card (NIC) could stay
in an unusable state and this could prevent the entire system from booting.
The tg3 module has been updated to correctly apply firmware updates.
(BZ#1182903)

* Support for key sizes of 256 and 192 bits has been added to AES-NI.
(BZ#1184332)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8160</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8369</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150674"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150696" severity="high">
    <xccdf:title>RHSA-2015:0696: freetype security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently.

Multiple integer overflow flaws and an integer signedness flaw, leading to
heap-based buffer overflows, were found in the way FreeType handled Mac
fonts. If a specially crafted font file was loaded by an application linked
against FreeType, it could cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2014-9673, CVE-2014-9674)

Multiple flaws were found in the way FreeType handled fonts in various
formats. If a specially crafted font file was loaded by an application
linked against FreeType, it could cause the application to crash or,
possibly, disclose a portion of the application memory. (CVE-2014-9657,
CVE-2014-9658, CVE-2014-9660, CVE-2014-9661, CVE-2014-9663, CVE-2014-9664,
CVE-2014-9667, CVE-2014-9669, CVE-2014-9670, CVE-2014-9671, CVE-2014-9675)

All freetype users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The X server must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0696</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9660</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9661</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9663</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9667</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9669</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9670</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9673</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9674</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9675</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150696"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150700" severity="medium">
    <xccdf:title>RHSA-2015:0700: unzip security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The unzip utility is used to list, test, or extract files from a
zip archive.

A buffer overflow was found in the way unzip uncompressed certain extra
fields of a file. A specially crafted Zip archive could cause unzip to
crash or, possibly, execute arbitrary code when the archive was tested with
unzip's '-t' option. (CVE-2014-9636)

A buffer overflow flaw was found in the way unzip computed the CRC32
checksum of certain extra fields of a file. A specially crafted Zip archive
could cause unzip to crash when the archive was tested with unzip's '-t'
option. (CVE-2014-8139)

An integer underflow flaw, leading to a buffer overflow, was found in the
way unzip uncompressed certain extra fields of a file. A specially crafted
Zip archive could cause unzip to crash when the archive was tested with
unzip's '-t' option. (CVE-2014-8140)

A buffer overflow flaw was found in the way unzip handled Zip64 files.
A specially crafted Zip archive could possibly cause unzip to crash when
the archive was uncompressed. (CVE-2014-8141)

Red Hat would like to thank oCERT for reporting the CVE-2014-8139,
CVE-2014-8140, and CVE-2014-8141 issues. oCERT acknowledges Michele
Spagnuolo of the Google Security Team as the original reporter of
these issues.

All unzip users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8141</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150700"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150715" severity="medium">
    <xccdf:title>RHSA-2015:0715: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An invalid pointer use flaw was found in OpenSSL's ASN1_TYPE_cmp()
function. A remote attacker could crash a TLS/SSL client or server using
OpenSSL via a specially crafted X.509 certificate when the
attacker-supplied certificate was verified by the application.
(CVE-2015-0286)

An integer underflow flaw, leading to a buffer overflow, was found in the
way OpenSSL decoded malformed Base64-encoded inputs. An attacker able to
make an application using OpenSSL decode a specially crafted Base64-encoded
input (such as a PEM file) could use this flaw to cause the application to
crash. Note: this flaw is not exploitable via the TLS/SSL protocol because
the data being transferred is not Base64-encoded. (CVE-2015-0292)

A denial of service flaw was found in the way OpenSSL handled SSLv2
handshake messages. A remote attacker could use this flaw to cause a
TLS/SSL server using OpenSSL to exit on a failed assertion if it had both
the SSLv2 protocol and EXPORT-grade cipher suites enabled. (CVE-2015-0293)

A use-after-free flaw was found in the way OpenSSL imported malformed
Elliptic Curve private keys. A specially crafted key file could cause an
application using OpenSSL to crash when imported. (CVE-2015-0209)

An out-of-bounds write flaw was found in the way OpenSSL reused certain
ASN.1 structures. A remote attacker could possibly use a specially crafted
ASN.1 structure that, when parsed by an application, would cause that
application to crash. (CVE-2015-0287)

A NULL pointer dereference flaw was found in OpenSSL's X.509 certificate
handling implementation. A specially crafted X.509 certificate could cause
an application using OpenSSL to crash if the application attempted to
convert the certificate to a certificate request. (CVE-2015-0288)

A NULL pointer dereference was found in the way OpenSSL handled certain
PKCS#7 inputs. An attacker able to make an application using OpenSSL
verify, decrypt, or parse a specially crafted PKCS#7 input could cause that
application to crash. TLS/SSL clients and servers using OpenSSL were not
affected by this flaw. (CVE-2015-0289)

Red Hat would like to thank the OpenSSL project for reporting
CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,
and CVE-2015-0293. Upstream acknowledges Stephen Henson of the OpenSSL
development team as the original reporter of CVE-2015-0286, Emilia Käsper
of the OpenSSL development team as the original reporter of CVE-2015-0287,
Brian Carpenter as the original reporter of CVE-2015-0288, Michal Zalewski
of Google as the original reporter of CVE-2015-0289, Robert Dugal and David
Ramos as the original reporters of CVE-2015-0292, and Sean Burford of
Google and Emilia Käsper of the OpenSSL development team as the original
reporters of CVE-2015-0293.

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150715"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150716" severity="medium">
    <xccdf:title>RHSA-2015:0716: openssl security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An invalid pointer use flaw was found in OpenSSL's ASN1_TYPE_cmp()
function. A remote attacker could crash a TLS/SSL client or server using
OpenSSL via a specially crafted X.509 certificate when the
attacker-supplied certificate was verified by the application.
(CVE-2015-0286)

An integer underflow flaw, leading to a buffer overflow, was found in the
way OpenSSL decoded malformed Base64-encoded inputs. An attacker able to
make an application using OpenSSL decode a specially crafted Base64-encoded
input (such as a PEM file) could use this flaw to cause the application to
crash. Note: this flaw is not exploitable via the TLS/SSL protocol because
the data being transferred is not Base64-encoded. (CVE-2015-0292)

A denial of service flaw was found in the way OpenSSL handled SSLv2
handshake messages. A remote attacker could use this flaw to cause a
TLS/SSL server using OpenSSL to exit on a failed assertion if it had both
the SSLv2 protocol and EXPORT-grade cipher suites enabled. (CVE-2015-0293)

A use-after-free flaw was found in the way OpenSSL imported malformed
Elliptic Curve private keys. A specially crafted key file could cause an
application using OpenSSL to crash when imported. (CVE-2015-0209)

An out-of-bounds write flaw was found in the way OpenSSL reused certain
ASN.1 structures. A remote attacker could possibly use a specially crafted
ASN.1 structure that, when parsed by an application, would cause that
application to crash. (CVE-2015-0287)

A NULL pointer dereference flaw was found in OpenSSL's X.509 certificate
handling implementation. A specially crafted X.509 certificate could cause
an application using OpenSSL to crash if the application attempted to
convert the certificate to a certificate request. (CVE-2015-0288)

A NULL pointer dereference was found in the way OpenSSL handled certain
PKCS#7 inputs. An attacker able to make an application using OpenSSL
verify, decrypt, or parse a specially crafted PKCS#7 input could cause that
application to crash. TLS/SSL clients and servers using OpenSSL were not
affected by this flaw. (CVE-2015-0289)

Red Hat would like to thank the OpenSSL project for reporting
CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,
and CVE-2015-0293. Upstream acknowledges Stephen Henson of the OpenSSL
development team as the original reporter of CVE-2015-0286, Emilia Käsper
of the OpenSSL development team as the original reporter of CVE-2015-0287,
Brian Carpenter as the original reporter of CVE-2015-0288, Michal Zalewski
of Google as the original reporter of CVE-2015-0289, Robert Dugal and David
Ramos as the original reporters of CVE-2015-0292, and Sean Burford of
Google and Emilia Käsper of the OpenSSL development team as the original
reporters of CVE-2015-0293.

This update also fixes the following bug:

* When a wrapped Advanced Encryption Standard (AES) key did not require any
padding, it was incorrectly padded with 8 bytes, which could lead to data
corruption and interoperability problems. With this update, the rounding
algorithm in the RFC 5649 key wrapping implementation has been fixed. As a
result, the wrapped key conforms to the specification, which prevents the
described problems. (BZ#1197667)

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0209</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0286</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150716"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150718" severity="high">
    <xccdf:title>RHSA-2015:0718: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Two flaws were found in the processing of malformed web content. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2015-0817, CVE-2015-0818)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges ilxu1a and Mariusz Mlynski as the original reporters
of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.5.3 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0718</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0817</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0818</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150718"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150726" severity="high">
    <xccdf:title>RHSA-2015:0726: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's Infiniband subsystem did not
properly sanitize input parameters while registering memory regions from
user space via the (u)verbs API. A local user with access to a
/dev/infiniband/uverbsX device could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-8159,
Important)

* A use-after-free flaw was found in the way the Linux kernel's SCTP
implementation handled authentication key reference counting during INIT
collisions. A remote attacker could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2015-1421,
Important)

Red Hat would like to thank Mellanox for reporting the CVE-2014-8159 issue.
The CVE-2015-1421 issue was discovered by Sun Baoliang of Red Hat.

This update also fixes the following bugs:

* In certain systems with multiple CPUs, when a crash was triggered on one
CPU with an interrupt handler and this CPU sent Non-Maskable Interrupt
(NMI) to another CPU, and, at the same time, ioapic_lock had already been
acquired, a deadlock occurred in ioapic_lock. As a consequence, the kdump
service could become unresponsive. This bug has been fixed and kdump now
works as expected. (BZ#1197742)

* On Lenovo X1 Carbon 3rd Gen, X250, and T550 laptops, the thinkpad_acpi
module was not properly loaded, and thus the function keys and radio
switches did not work. This update applies a new string pattern of BIOS
version, which fixes this bug, and function keys and radio switches now
work as intended. (BZ#1197743)

* During a heavy file system load involving many worker threads, all worker
threads in the pool became blocked on a resource, and no manager thread
existed to create more workers. As a consequence, the running processes
became unresponsive. With this update, the logic around manager creation
has been changed to assure that the last worker thread becomes a manager
thread and does not start executing work items. Now, a manager thread
exists, spawns new workers as needed, and processes no longer hang.
(BZ#1197744)

* If a thin-pool's metadata enters read-only or fail mode, for example, due
to thin-pool running out of metadata or data space, any attempt to make
metadata changes such as creating a thin device or snapshot thin device
should error out cleanly. However, previously, the kernel code returned
verbose and alarming error messages to the user. With this update, due to
early trapping of attempt to make metadata changes, informative errors are
displayed, no longer unnecessarily alarming the user. (BZ#1197745)

* When running Red Hat Enterprise Linux as a guest on Microsoft Hyper-V
hypervisor, the storvsc module did not return the correct error code for
the upper level Small Computer System Interface (SCSI) subsystem. As a
consequence, a SCSI command failed and storvsc did not handle such a
failure properly under some conditions, for example, when RAID devices were
created on top of storvsc devices. An upstream patch has been applied to
fix this bug, and storvsc now returns the correct error code in the
described situation. (BZ#1197749)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0726</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1421</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150726"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150727" severity="high">
    <xccdf:title>RHSA-2015:0727: kernel-rt security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's Infiniband subsystem did not
properly sanitize input parameters while registering memory regions from
user space via the (u)verbs API. A local user with access to a
/dev/infiniband/uverbsX device could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-8159,
Important)

* A use-after-free flaw was found in the way the Linux kernel's SCTP
implementation handled authentication key reference counting during INIT
collisions. A remote attacker could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2015-1421,
Important)

Red Hat would like to thank Mellanox for reporting the CVE-2014-8159 issue.
The CVE-2015-1421 issue was discovered by Sun Baoliang of Red Hat.

The kernel-rt packages have been upgraded to version 3.10.0-229.1.2, which
provides a number of bug fixes over the previous version, including:

- The kdump service could become unresponsive due to a deadlock in the
kernel call ioapic_lock.

- Attempt to make metadata changes such as creating a thin device or
snapshot thin device did not error out cleanly.

(BZ#1203359)

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues. The system must be rebooted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1421</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150727"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150728" severity="medium">
    <xccdf:title>RHSA-2015:0728: ipa and slapi-nis security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Identity Management is a centralized authentication, identity
management, and authorization solution for both traditional and cloud-based
enterprise environments. It integrates components of the Red Hat Directory
Server, MIT Kerberos, Red Hat Certificate System, NTP, and DNS. It provides
web browser and command-line interfaces. Its administration tools allow an
administrator to quickly install, set up, and administer a group of domain
controllers to meet the authentication and identity management requirements
of large-scale Linux and UNIX deployments.

The ipa component provides centrally managed Identity, Policy, and Audit.
The slapi-nis component provides NIS Server and Schema Compatibility
plug-ins for Directory Server.

It was discovered that the IPA extdom Directory Server plug-in did not
correctly perform memory reallocation when handling user account
information. A request for a list of groups for a user that belongs to a
large number of groups would cause a Directory Server to crash.
(CVE-2015-1827)

It was discovered that the slapi-nis Directory Server plug-in did not
correctly perform memory reallocation when handling user account
information. A request for information about a group with many members, or
a request for a user that belongs to a large number of groups, would cause
a Directory Server to enter an infinite loop and consume an excessive
amount of CPU time. (CVE-2015-0283)

These issues were discovered by Sumit Bose of Red Hat.

This update fixes the following bugs:

* Previously, users of IdM were not properly granted the default permission
to read the "facsimiletelephonenumber" user attribute. This update adds
"facsimiletelephonenumber" to the Access Control Instruction (ACI) for user
data, which makes the attribute readable to authenticated users as
expected. (BZ#1198430)

* Prior to this update, when a DNS zone was saved in an LDAP database
without a dot character (.) at the end, internal DNS commands and
operations, such as dnsrecord-* or dnszone-*, failed. With this update, DNS
commands always supply the DNS zone with a dot character at the end, which
prevents the described problem. (BZ#1198431)

* After a full-server IdM restore operation, the restored server in some
cases contained invalid data. In addition, if the restored server was used
to reinitialize a replica, the replica then contained invalid data as well.
To fix this problem, the IdM API is now created correctly during the
restore operation, and *.ldif files are not skipped during the removal of
RUV data. As a result, the restored server and its replica no longer
contain invalid data. (BZ#1199060)

* Previously, a deadlock in some cases occurred during an IdM upgrade,
which could cause the IdM server to become unresponsive. With this update,
the Schema Compatibility plug-in has been adjusted not to parse the subtree
that contains the configuration of the DNA plug-in, which prevents this
deadlock from triggering. (BZ#1199128)

* When using the extdom plug-in of IdM to handle large groups, user lookups
and group lookups previously failed due to insufficient buffer size.
With this update, the getgrgid_r() call gradually increases the buffer
length if needed, and the described failure of extdom thus no longer
occurs. (BZ#1203204)

Users of ipa and slapi-nis are advised to upgrade to these updated
packages, which correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1827</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150728"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150729" severity="high">
    <xccdf:title>RHSA-2015:0729: setroubleshoot security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The setroubleshoot packages provide tools to help diagnose SELinux
problems. When Access Vector Cache (AVC) messages are returned, an alert
can be generated that provides information about the problem and helps to
track its resolution.

It was found that setroubleshoot did not sanitize file names supplied in a
shell command look-up for RPMs associated with access violation reports.
An attacker could use this flaw to escalate their privileges on the system
by supplying a specially crafted file to the underlying shell command.
(CVE-2015-1815)

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
reporting this issue.

All setroubleshoot users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1815</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150729"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150749" severity="medium">
    <xccdf:title>RHSA-2015:0749: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

It was discovered that libxml2 loaded external parameter entities even when
entity substitution was disabled. A remote attacker able to provide a
specially crafted XML file to an application linked against libxml2 could
use this flaw to conduct XML External Entity (XXE) attacks, possibly
resulting in a denial of service or an information leak on the system.
(CVE-2014-0191)

The CVE-2014-0191 issue was discovered by Daniel P. Berrange of Red Hat.

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0191</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150749"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150750" severity="medium">
    <xccdf:title>RHSA-2015:0750: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

An information leak flaw was found in the way the PostgreSQL database
server handled certain error messages. An authenticated database user could
possibly obtain the results of a query they did not have privileges to
execute by observing the constraint violation error messages produced when
the query was executed. (CVE-2014-8161)

A buffer overflow flaw was found in the way PostgreSQL handled certain
numeric formatting. An authenticated database user could use a specially
crafted timestamp formatting template to cause PostgreSQL to crash or,
under certain conditions, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2015-0241)

A stack-buffer overflow flaw was found in PostgreSQL's pgcrypto module.
An authenticated database user could use this flaw to cause PostgreSQL to
crash or, potentially, execute arbitrary code with the permissions of the
user running PostgreSQL. (CVE-2015-0243)

A flaw was found in the way PostgreSQL handled certain errors that were
generated during protocol synchronization. An authenticated database user
could use this flaw to inject queries into an existing connection.
(CVE-2015-0244)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Stephen Frost as the original reporter of
CVE-2014-8161; Andres Freund, Peter Geoghegan, Bernd Helmle, and Noah Misch
as the original reporters of CVE-2015-0241; Marko Tiikkaja as the original
reporter of CVE-2015-0243; and Emil Lenngren as the original reporter of
CVE-2015-0244.

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8161</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0244</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150750"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150766" severity="high">
    <xccdf:title>RHSA-2015:0766: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-0813, CVE-2015-0815, CVE-2015-0801)

A flaw was found in the way documents were loaded via resource URLs in, for
example, Mozilla's PDF.js PDF file viewer. An attacker could use this flaw
to bypass certain restrictions and under certain conditions even execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2015-0816)

A flaw was found in the Beacon interface implementation in Firefox. A web
page containing malicious content could allow a remote attacker to conduct
a Cross-Site Request Forgery (CSRF) attack. (CVE-2015-0807)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Byron Campen, Steve Fink, Mariusz
Mlynski, Christoph Kerschbaumer, Muneaki Nishimura, Olli Pettay, Boris
Zbarsky, and Aki Helin as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0766</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0816</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150766"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150767" severity="high">
    <xccdf:title>RHSA-2015:0767: flac security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The flac packages contain a decoder and an encoder for the FLAC (Free
Lossless Audio Codec) audio file format.

A buffer overflow flaw was found in the way flac decoded FLAC audio files.
An attacker could create a specially crafted FLAC audio file that could
cause an application using the flac library to crash or execute arbitrary
code when the file was read. (CVE-2014-9028)

A buffer over-read flaw was found in the way flac processed certain ID3v2
metadata. An attacker could create a specially crafted FLAC audio file that
could cause an application using the flac library to crash when the file
was read. (CVE-2014-8962)

All flac users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, all applications linked against the flac library must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0767</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8962</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9028</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150767"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150771" severity="high">
    <xccdf:title>RHSA-2015:0771: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-0813, CVE-2015-0815, CVE-2015-0801)

A flaw was found in the way documents were loaded via resource URLs.
An attacker could use this flaw to bypass certain restrictions and under
certain conditions even execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2015-0816)

A flaw was found in the Beacon interface implementation in Thunderbird.
A web page containing malicious content could allow a remote attacker to
conduct a Cross-Site Request Forgery (CSRF) attack. (CVE-2015-0807)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, Byron Campen, Steve Fink, Mariusz
Mlynski, Christoph Kerschbaumer, Muneaki Nishimura, Olli Pettay, Boris
Zbarsky, and Aki Helin as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0771</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0801</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0815</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0816</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150771"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150783" severity="high">
    <xccdf:title>RHSA-2015:0783: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's Infiniband subsystem did not
properly sanitize input parameters while registering memory regions from
user space via the (u)verbs API. A local user with access to a
/dev/infiniband/uverbsX device could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-8159,
Important)

* An insufficient bound checking flaw was found in the Xen hypervisor's
implementation of acceleration support for the "REP MOVS" instructions.
A privileged HVM guest user could potentially use this flaw to crash the
host. (CVE-2014-8867, Important)

Red Hat would like to thank Mellanox for reporting CVE-2014-8159, and the
Xen project for reporting CVE-2014-8867.

This update also fixes the following bugs:

* Under memory pressure, cached data was previously flushed to the backing
server using the PID of the thread responsible for flushing the data in the
Server Message Block (SMB) headers instead of the PID of the thread which
actually wrote the data. As a consequence, when a file was locked by the
writing thread prior to writing, the server considered writes by the thread
flushing the pagecache as being a separate process from writing to a locked
file, and thus rejected the writes. In addition, the data to be written was
discarded. This update ensures that the correct PID is sent to the server,
and data corruption is avoided when data is being written from a client
under memory pressure. (BZ#1169304)

* This update adds support for new cryptographic hardware in toleration
mode for IBM System z. (BZ#1182522)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8867</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150783"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150794" severity="medium">
    <xccdf:title>RHSA-2015:0794: krb5 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a networked authentication system which allows clients and
servers to authenticate to each other with the help of a trusted third
party, the Kerberos KDC.

The following security issues are fixed with this release:

A use-after-free flaw was found in the way the MIT Kerberos libgssapi_krb5
library processed valid context deletion tokens. An attacker able to make
an application using the GSS-API library (libgssapi) could call the
gss_process_context_token() function and use this flaw to crash that
application. (CVE-2014-5352)

If kadmind were used with an LDAP back end for the KDC database, a remote,
authenticated attacker who has the permissions to set the password policy
could crash kadmind by attempting to use a named ticket policy object as a
password policy for a principal. (CVE-2014-5353)

It was found that the krb5_read_message() function of MIT Kerberos did not
correctly sanitize input, and could create invalid krb5_data objects.
A remote, unauthenticated attacker could use this flaw to crash a Kerberos
child process via a specially crafted request. (CVE-2014-5355)

A double-free flaw was found in the way MIT Kerberos handled invalid
External Data Representation (XDR) data. An authenticated user could use
this flaw to crash the MIT Kerberos administration server (kadmind), or
other applications using Kerberos libraries, via specially crafted XDR
packets. (CVE-2014-9421)

It was found that the MIT Kerberos administration server (kadmind)
incorrectly accepted certain authentication requests for two-component
server principal names. A remote attacker able to acquire a key with a
particularly named principal (such as "kad/x") could use this flaw to
impersonate any user to kadmind, and perform administrative actions as that
user. (CVE-2014-9422)

Red Hat would like to thank the MIT Kerberos project for reporting
CVE-2014-5352, CVE-2014-9421, and CVE-2014-9422. The MIT Kerberos project
acknowledges Nico Williams for assisting with the analysis of
CVE-2014-5352.

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0794</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5352</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5353</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9422</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150794"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150797" severity="medium">
    <xccdf:title>RHSA-2015:0797: xorg-x11-server security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A buffer over-read flaw was found in the way the X.Org server handled
XkbGetGeometry requests. A malicious, authorized client could use this flaw
to disclose portions of the X.Org server memory, or cause the X.Org server
to crash using a specially crafted XkbGetGeometry request. (CVE-2015-0255)

This issue was discovered by Olivier Fourdan of Red Hat.

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0255</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150797"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150800" severity="medium">
    <xccdf:title>RHSA-2015:0800: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was discovered that OpenSSL would accept ephemeral RSA keys when using
non-export RSA cipher suites. A malicious server could make a TLS/SSL
client using OpenSSL use a weaker key exchange method. (CVE-2015-0204)

An integer underflow flaw, leading to a buffer overflow, was found in the
way OpenSSL decoded malformed Base64-encoded inputs. An attacker able to
make an application using OpenSSL decode a specially crafted Base64-encoded
input (such as a PEM file) could use this flaw to cause the application to
crash. Note: this flaw is not exploitable via the TLS/SSL protocol because
the data being transferred is not Base64-encoded. (CVE-2015-0292)

A denial of service flaw was found in the way OpenSSL handled SSLv2
handshake messages. A remote attacker could use this flaw to cause a
TLS/SSL server using OpenSSL to exit on a failed assertion if it had both
the SSLv2 protocol and EXPORT-grade cipher suites enabled. (CVE-2015-0293)

Multiple flaws were found in the way OpenSSL parsed X.509 certificates.
An attacker could use these flaws to modify an X.509 certificate to produce
a certificate with a different fingerprint without invalidating its
signature, and possibly bypass fingerprint-based blacklisting in
applications. (CVE-2014-8275)

An out-of-bounds write flaw was found in the way OpenSSL reused certain
ASN.1 structures. A remote attacker could possibly use a specially crafted
ASN.1 structure that, when parsed by an application, would cause that
application to crash. (CVE-2015-0287)

A NULL pointer dereference flaw was found in OpenSSL's X.509 certificate
handling implementation. A specially crafted X.509 certificate could cause
an application using OpenSSL to crash if the application attempted to
convert the certificate to a certificate request. (CVE-2015-0288)

A NULL pointer dereference was found in the way OpenSSL handled certain
PKCS#7 inputs. An attacker able to make an application using OpenSSL
verify, decrypt, or parse a specially crafted PKCS#7 input could cause that
application to crash. TLS/SSL clients and servers using OpenSSL were not
affected by this flaw. (CVE-2015-0289)

Red Hat would like to thank the OpenSSL project for reporting 
CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292, and 
CVE-2015-0293. Upstream acknowledges Emilia Käsper of the OpenSSL 
development team as the original reporter of CVE-2015-0287, Brian Carpenter 
as the original reporter of CVE-2015-0288, Michal Zalewski of Google as the 
original reporter of CVE-2015-0289, Robert Dugal and David Ramos as the 
original reporters of CVE-2015-0292, and Sean Burford of Google and Emilia 
Käsper of the OpenSSL development team as the original reporters of 
CVE-2015-0293.

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0800</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0289</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0292</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0293</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0703</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150800"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150806" severity="high">
    <xccdf:title>RHSA-2015:0806: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)

A flaw was found in the way the Hotspot component in OpenJDK handled
phantom references. An untrusted Java application or applet could use this
flaw to corrupt the Java Virtual Machine memory and, possibly, execute
arbitrary code, bypassing Java sandbox restrictions. (CVE-2015-0460)

A flaw was found in the way the JSSE component in OpenJDK parsed X.509
certificate options. A specially crafted certificate could cause JSSE to
raise an exception, possibly causing an application using JSSE to exit
unexpectedly. (CVE-2015-0488)

A flaw was discovered in the Beans component in OpenJDK. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2015-0477)

A directory traversal flaw was found in the way the jar tool extracted JAR
archive files. A specially crafted JAR archive could cause jar to overwrite
arbitrary files writable by the user running jar when the archive was
extracted. (CVE-2005-1080, CVE-2015-0480)

It was found that the RSA implementation in the JCE component in OpenJDK
did not follow recommended practices for implementing RSA signatures.
(CVE-2015-0478)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150806"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150807" severity="high">
    <xccdf:title>RHSA-2015:0807: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)

A flaw was found in the way the Hotspot component in OpenJDK handled
phantom references. An untrusted Java application or applet could use this
flaw to corrupt the Java Virtual Machine memory and, possibly, execute
arbitrary code, bypassing Java sandbox restrictions. (CVE-2015-0460)

A flaw was found in the way the JSSE component in OpenJDK parsed X.509
certificate options. A specially crafted certificate could cause JSSE to
raise an exception, possibly causing an application using JSSE to exit
unexpectedly. (CVE-2015-0488)

A flaw was discovered in the Beans component in OpenJDK. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2015-0477)

A directory traversal flaw was found in the way the jar tool extracted JAR
archive files. A specially crafted JAR archive could cause jar to overwrite
arbitrary files writable by the user running jar when the archive was
extracted. (CVE-2005-1080, CVE-2015-0480)

It was found that the RSA implementation in the JCE component in OpenJDK
did not follow recommended practices for implementing RSA signatures.
(CVE-2015-0478)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0807</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150807"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150808" severity="high">
    <xccdf:title>RHSA-2015:0808: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)

A flaw was found in the way the Hotspot component in OpenJDK handled
phantom references. An untrusted Java application or applet could use this
flaw to corrupt the Java Virtual Machine memory and, possibly, execute
arbitrary code, bypassing Java sandbox restrictions. (CVE-2015-0460)

A flaw was found in the way the JSSE component in OpenJDK parsed X.509
certificate options. A specially crafted certificate could cause JSSE to
raise an exception, possibly causing an application using JSSE to exit
unexpectedly. (CVE-2015-0488)

A flaw was discovered in the Beans component in OpenJDK. An untrusted Java
application or applet could use this flaw to bypass certain Java sandbox
restrictions. (CVE-2015-0477)

A directory traversal flaw was found in the way the jar tool extracted JAR
archive files. A specially crafted JAR archive could cause jar to overwrite
arbitrary files writable by the user running jar when the archive was
extracted. (CVE-2005-1080, CVE-2015-0480)

It was found that the RSA implementation in the JCE component in OpenJDK
did not follow recommended practices for implementing RSA signatures.
(CVE-2015-0478)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150808"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150809" severity="high">
    <xccdf:title>RHSA-2015:0809: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)

A flaw was found in the way the Hotspot component in OpenJDK handled
phantom references. An untrusted Java application or applet could use this
flaw to corrupt the Java Virtual Machine memory and, possibly, execute
arbitrary code, bypassing Java sandbox restrictions. (CVE-2015-0460)

A flaw was found in the way the JSSE component in OpenJDK parsed X.509
certificate options. A specially crafted certificate could cause JSSE to
raise an exception, possibly causing an application using JSSE to exit
unexpectedly. (CVE-2015-0488)

Multiple flaws were discovered in the Beans and Hotspot components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2015-0477, CVE-2015-0470)

A directory traversal flaw was found in the way the jar tool extracted JAR
archive files. A specially crafted JAR archive could cause jar to overwrite
arbitrary files writable by the user running jar when the archive was
extracted. (CVE-2005-1080, CVE-2015-0480)

It was found that the RSA implementation in the JCE component in OpenJDK
did not follow recommended practices for implementing RSA signatures.
(CVE-2015-0478)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0809</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150809"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150854" severity="high">
    <xccdf:title>RHSA-2015:0854: java-1.8.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 8 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2005-1080, CVE-2015-0458, CVE-2015-0459, CVE-2015-0460, CVE-2015-0469,
CVE-2015-0470, CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0484,
CVE-2015-0486, CVE-2015-0488, CVE-2015-0491, CVE-2015-0492)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.8.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 8 Update 45 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0854</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0470</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150854"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150857" severity="high">
    <xccdf:title>RHSA-2015:0857: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2005-1080, CVE-2015-0458, CVE-2015-0459, CVE-2015-0460, CVE-2015-0469,
CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0484, CVE-2015-0488,
CVE-2015-0491, CVE-2015-0492)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 79 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0857</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0492</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150857"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150858" severity="high">
    <xccdf:title>RHSA-2015:0858: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2005-1080, CVE-2015-0458, CVE-2015-0459, CVE-2015-0460, CVE-2015-0469,
CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0488, CVE-2015-0491)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 95 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0858</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2005-1080</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0469</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0477</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0491</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150858"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150863" severity="medium">
    <xccdf:title>RHSA-2015:0863: glibc security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A buffer overflow flaw was found in the way glibc's gethostbyname_r() and
other related functions computed the size of a buffer when passed a
misaligned buffer as input. An attacker able to make an application call
any of these functions with a misaligned buffer could use this flaw to
crash the application or, potentially, execute arbitrary code with the
permissions of the user running the application. (CVE-2015-1781)

It was discovered that, under certain circumstances, glibc's getaddrinfo()
function would send DNS queries to random file descriptors. An attacker
could potentially use this flaw to send DNS queries to unintended
recipients, resulting in information disclosure or data loss due to the
application encountering corrupted data. (CVE-2013-7423)

The CVE-2015-1781 issue was discovered by Arjun Shankar of Red Hat.

This update also fixes the following bug:

* Previously, the nscd daemon did not properly reload modified data when
the user edited monitored nscd configuration files. As a consequence, nscd
returned stale data to system processes. This update adds a system of
inotify-based monitoring and stat-based backup monitoring for nscd
configuration files. As a result, nscd now detects changes to its
configuration files and reloads the data properly, which prevents it from
returning stale data. (BZ#1194149)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1781</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150863"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150864" severity="high">
    <xccdf:title>RHSA-2015:0864: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way seunshare, a utility for running executables
under a different security context, used the capng_lock functionality of
the libcap-ng library. The subsequent invocation of suid root binaries that
relied on the fact that the setuid() system call, among others, also sets
the saved set-user-ID when dropping the binaries' process privileges, could
allow a local, unprivileged user to potentially escalate their privileges
on the system. Note: the fix for this issue is the kernel part of the
overall fix, and introduces the PR_SET_NO_NEW_PRIVS functionality and the
related SELinux exec transitions support. (CVE-2014-3215, Important)

* A use-after-free flaw was found in the way the Linux kernel's SCTP
implementation handled authentication key reference counting during INIT
collisions. A remote attacker could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2015-1421,
Important)

* It was found that the Linux kernel's KVM implementation did not ensure
that the host CR4 control register value remained unchanged across VM
entries on the same virtual CPU. A local, unprivileged user could use this
flaw to cause a denial of service on the system. (CVE-2014-3690, Moderate)

* An out-of-bounds memory access flaw was found in the syscall tracing
functionality of the Linux kernel's perf subsystem. A local, unprivileged
user could use this flaw to crash the system. (CVE-2014-7825, Moderate)

* An out-of-bounds memory access flaw was found in the syscall tracing
functionality of the Linux kernel's ftrace subsystem. On a system with
ftrace syscall tracing enabled, a local, unprivileged user could use this
flaw to crash the system, or escalate their privileges. (CVE-2014-7826,
Moderate)

* It was found that the Linux kernel memory resource controller's (memcg)
handling of OOM (out of memory) conditions could lead to deadlocks.
An attacker able to continuously spawn new processes within a single
memory-constrained cgroup during an OOM event could use this flaw to lock
up the system. (CVE-2014-8171, Moderate)

* A race condition flaw was found in the way the Linux kernel keys
management subsystem performed key garbage collection. A local attacker
could attempt accessing a key while it was being garbage collected, which
would cause the system to crash. (CVE-2014-9529, Moderate)

* A stack-based buffer overflow flaw was found in the TechnoTrend/Hauppauge
DEC USB device driver. A local user with write access to the corresponding
device could use this flaw to crash the kernel or, potentially, elevate
their privileges on the system. (CVE-2014-8884, Low)

* An information leak flaw was found in the way the Linux kernel's ISO9660
file system implementation accessed data on an ISO9660 image with RockRidge
Extension Reference (ER) records. An attacker with physical access to the
system could use this flaw to disclose up to 255 bytes of kernel memory.
(CVE-2014-9584, Low)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-3215
and CVE-2014-3690, Robert Święcki for reporting CVE-2014-7825 and
CVE-2014-7826, and Carl Henrik Lunde for reporting CVE-2014-9584. The
CVE-2015-1421 issue was discovered by Sun Baoliang of Red Hat.

This update also fixes several bugs. Documentation for these changes is
available from the Technical Notes document linked to in the References
section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3690</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7825</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7826</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8884</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1421</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150864"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150867" severity="high">
    <xccdf:title>RHSA-2015:0867: qemu-kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

It was found that the Cirrus blit region checks were insufficient. A
privileged guest user could use this flaw to write outside of VRAM-
allocated buffer boundaries in the host's QEMU process address space with
attacker-provided data. (CVE-2014-8106)

This issue was found by Paolo Bonzini of Red Hat.

This update also fixes the following bug:

* Previously, the effective downtime during the last phase of a live
migration would sometimes be much higher than the maximum downtime
specified by 'migration_downtime' in vdsm.conf. This problem has been
corrected. The value of 'migration_downtime' is now honored and the
migration is aborted if the downtime cannot be achieved. (BZ#1142756)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0867</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8106</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150867"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150869" severity="high">
    <xccdf:title>RHSA-2015:0869: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

It was found that KVM's Write to Model Specific Register (WRMSR)
instruction emulation would write non-canonical values passed in by the
guest to certain MSRs in the host's context. A privileged guest user could
use this flaw to crash the host. (CVE-2014-3610)

A race condition flaw was found in the way the Linux kernel's KVM subsystem
handled PIT (Programmable Interval Timer) emulation. A guest user who has
access to the PIT I/O ports could use this flaw to crash the host.
(CVE-2014-3611)

Red Hat would like to thank Lars Bull of Google and Nadav Amit for
reporting the CVE-2014-3610 issue, and Lars Bull of Google for reporting
the CVE-2014-3611 issue.

All kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Note: The procedure in
the Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3610</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3611</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150869"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150895" severity="high">
    <xccdf:title>RHSA-2015:0895: 389-ds-base security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

A flaw was found in the way Red Hat Directory Server performed
authorization of modrdn operations. An unauthenticated attacker able to
issue an ldapmodrdn call to the directory server could use this flaw to
perform unauthorized modifications of entries in the directory server.
(CVE-2015-1854)

This issue was discovered by Simo Sorce of Red Hat.

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0895</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1854</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150895"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150980" severity="high">
    <xccdf:title>RHSA-2015:0980: pcs security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pcs packages provide a command-line tool and a web UI to configure and
manage the Pacemaker and Corosync tools.

It was found that the pcs daemon did not sign cookies containing session
data that were sent to clients connecting via the pcsd web UI. A remote
attacker could use this flaw to forge cookies and bypass authorization
checks, possibly gaining elevated privileges in the pcsd web UI.
(CVE-2015-1848)

This issue was discovered by Tomas Jelinek of Red Hat.

This update also fixes the following bug:

* Previously, the Corosync tool allowed the two_node option and the
auto_tie_breaker option to exist in the corosync.conf file at the same
time. As a consequence, if both options were included, auto_tie_breaker was
silently ignored and the two_node fence race decided which node would
survive in the event of a communication break. With this update, the pcs
daemon has been fixed so that it does not produce corosync.conf files with
both two_node and auto_tie_breaker included. In addition, if both two_node
and auto_tie_breaker are detected in corosync.conf, Corosync issues a
message at start-up and disables two_node mode. As a result,
auto_tie_breaker effectively overrides two_node mode if both options are
specified. (BZ#1205848)

All pcs users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the pcsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0980</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3983</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150980"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150981" severity="high">
    <xccdf:title>RHSA-2015:0981: kernel-rt security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* A buffer overflow flaw was found in the way the Linux kernel's Intel
AES-NI instructions optimized version of the RFC4106 GCM mode decryption
functionality handled fragmented packets. A remote attacker could use this
flaw to crash, or potentially escalate their privileges on, a system over a
connection with an active AEC-GCM mode IPSec security association.
(CVE-2015-3331, Important)

The kernel-rt packages have been upgraded to version 3.10.0-229.4.1, which
provides a number of bug fixes and enhancements over the previous version,
including:

* Audit subsystem not resolving path name on directory watches
* audit watches do not track correctly after a rename
* auditctl output is changed in RHEL 7
* megaraid_sas: non-booting system with intel_iommu=on kernel parameter
* GFS2: kernel NULL pointer dereference in gfs2_inplace_reserve
* Crypto adapter cannot be brought online - affect all HW
* crypto/seqiv.c: wrong check of return code from crypto_rng_get_bytes
* Backport crypto: sha256_ssse3 - also test for BMI2
* Null pointer at team_handle_frame+0x62/0x100 [team]
* AES CTR x86_64 "by8" AVX optimization
* Intel RDSEED - Fix for entropy counting
* Intel SHA1 multi-buffer crypto implementation
* Intel SHA1 AVX2 optimization support
* mlx4_en: HW timestamp ends up in error queue of socket which does not
have SO_TIMESTAMPING enabled

(BZ#1209963)

This update also fixes the following bugs:

* Prior to this update, heavy lock contention occurred on systems with
greater than 32 cores when large numbers of tasks went idle simultaneously.
Consequently, all the idle CPUs attempted to acquire the run-queue (rq)
lock of a CPU with extra tasks in order to pull those run-able tasks.
This increased scheduler latency due to the lock contention. Instead of
each idle CPU attempting to acquire the run-queue lock, now each idle CPU
will send an IPI to let the overloaded CPU select one core to pull tasks
from it. The result is less spin-lock contention on the rq lock and
produces improved scheduler response time. (BZ#1210924)

* The CONFIG_NO_HZ logic enabled/disabled the timer tick every time a CPU
went into an idle state. This timer tick manipulation caused the system
performance (throughput) to suffer. The CONFIG_NO_HZ configuration setting
is now turned off by default, which increases the throughput due to the
lower idle overhead while allowing system administrators to enable it
selectively in their environment. (BZ#1210597)

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3331</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150983" severity="medium">
    <xccdf:title>RHSA-2015:0983: tomcat security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that the ChunkedInputFilter in Tomcat did not fail
subsequent attempts to read input after malformed chunked encoding was
detected. A remote attacker could possibly use this flaw to make Tomcat
process part of the request body as new request, or cause a denial of
service. (CVE-2014-0227)

All Tomcat 7 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the tomcat service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0983</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0227</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150983"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150986" severity="medium">
    <xccdf:title>RHSA-2015:0986: kexec-tools security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kexec-tools packages contain the /sbin/kexec binary and utilities that
together form the user-space component of the kernel's kexec feature.
The /sbin/kexec binary facilitates a new kernel to boot using the kernel's
kexec feature either on a normal or a panic reboot. The kexec fastboot
mechanism allows booting a Linux kernel from the context of an already
running kernel.

It was found that the module-setup.sh script provided by kexec-tools
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files. (CVE-2015-0267)

This issue was discovered by Harald Hoyer of Red Hat.

This update also fixes the following bug:

* On Red Hat Enterprise Linux Atomic Host systems, the kdump tool
previously saved kernel crash dumps in the /sysroot/crash file instead of
the /var/crash file. The parsing error that caused this problem has been
fixed, and the kernel crash dumps are now correctly saved in /var/crash.
(BZ#1206464)

In addition, this update adds the following enhancement:

* The makedumpfile command now supports the new sadump format that can
represent more than 16 TB of physical memory space. This allows users of
makedumpfile to read dump files over 16 TB, generated by sadump on certain
upcoming server models. (BZ#1208753)

All kexec-tools users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0986</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0267</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150986"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150987" severity="high">
    <xccdf:title>RHSA-2015:0987: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A buffer overflow flaw was found in the way the Linux kernel's Intel
AES-NI instructions optimized version of the RFC4106 GCM mode decryption
functionality handled fragmented packets. A remote attacker could use this
flaw to crash, or potentially escalate their privileges on, a system over a
connection with an active AEC-GCM mode IPSec security association.
(CVE-2015-3331, Important)

This update also fixes the following bugs:

* Previously, the kernel audit subsystem did not correctly track file path
names which could lead to empty, or "(null)" path names in the PATH audit
records. This update fixes the bug by correctly tracking file path names
and displaying the names in the audit PATH records. (BZ#1197746)

* Due to a change in the internal representation of field types,
AUDIT_LOGINUID set to -1 (4294967295) by the audit API was asymmetrically
converted to an AUDIT_LOGINUID_SET field with a value of 0, unrecognized by
an older audit API. To fix this bug, the kernel takes note about the way
the rule has been formulated and reports the rule in the originally given
form. As a result, older versions of audit provide a report as expected, in
the AUDIT_LOGINUID field type form, whereas the newer versions can migrate
to the new AUDIT_LOGINUID_SET filed type. (BZ#1197748)

* The GFS2 file system "Splice Read" operation, which is used for the
sendfile() function, was not properly allocating a required multi-block
reservation structure in memory. Consequently, when the GFS2 block
allocator was called to assign blocks of data, it attempted to dereference
the structure, which resulted in a kernel panic. With this update, "Splice
read" operation properly allocates the necessary reservation structure in
memory prior to calling the block allocator, and sendfile() thus works
properly for GFS2. (BZ#1201256)

* Moving an Open vSwitch (OVS) internal vport to a different net name space
and subsequently deleting that name space led to a kernel panic. This bug
has been fixed by removing the OVS internal vport at net name space
deletion. (BZ#1202357)

* Previously, the kernel audit subsystem was not correctly handling file
and directory moves, leading to audit records that did not match the audit
file watches. This fix correctly handles moves such that the audit file
watches work correctly. (BZ#1202358)

* Due to a regression, the crypto adapter could not be set online. A patch
has been provided that fixes the device registration process so that the
device can be used also before the registration process is completed, thus
fixing this bug. (BZ#1205300)

* Due to incorrect calculation for entropy during the entropy addition, the
amount of entropy in the /dev/random file could be overestimated.
The formula for the entropy addition has been changed, thus fixing this
bug. (BZ#1211288)

* Previously, the ansi_cprng and drbg utilities did not obey the call
convention and returned the positive value on success instead of the
correct value of zero. Consequently, Internet Protocol Security (IPsec)
terminated unexpectedly when ansi_cprng or drbg were used. With this
update, ansi_cprng and drbg have been changed to return zero on success,
and IPsec now functions correctly. (BZ#1211487)

* Due to a failure to clear the timestamp flag when reusing a tx descriptor
in the mlx4_en driver, programs that did not request a hardware timestamp
packet on their sent data received it anyway, resulting in unexpected
behavior in certain applications. With this update, when reusing the tx
descriptor in the mlx4_en driver in the aforementioned situation, the
hardware timestamp flag is cleared, and applications now behave as
expected. (BZ#1209240)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0987</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3331</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150987"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150988" severity="high">
    <xccdf:title>RHSA-2015:0988: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-2708, CVE-2015-0797, CVE-2015-2710, CVE-2015-2713)

A heap-based buffer overflow flaw was found in the way Firefox processed
compressed XML data. An attacker could create specially crafted compressed
XML content that, when processed by Firefox, could cause it to crash or
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2015-2716)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jesse Ruderman, Mats Palmgren, Byron Campen, Steve
Fink, Aki Helin, Atte Kettunen, Scott Bell, and Ucha Gobejishvili as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.0 ESR, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0988</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0797</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2716</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4496</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150988"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150990" severity="high">
    <xccdf:title>RHSA-2015:0990: pcs security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pcs packages provide a command-line tool and a web UI to configure and
manage the Pacemaker and Corosync tools.

It was found that the pcs daemon did not sign cookies containing session
data that were sent to clients connecting via the pcsd web UI. A remote
attacker could use this flaw to forge cookies and bypass authorization
checks, possibly gaining elevated privileges in the pcsd web UI. Note: the
pcsd web UI is not enabled by default. (CVE-2015-1848)

This issue was discovered by Tomas Jelinek of Red Hat.

This update also fixes the following bug:

* When the IPv6 protocol was disabled on a system, starting the pcsd daemon
on this system previously failed. This update adds the ability for pcsd to
fall back to IPv4 when IPv6 is not available. As a result, pcsd starts
properly and uses IPv4 if IPv6 is disabled. (BZ#1212115)

All pcs users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the pcsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0990</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3983</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150990"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150991" severity="medium">
    <xccdf:title>RHSA-2015:0991: tomcat6 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that the ChunkedInputFilter in Tomcat did not fail
subsequent attempts to read input after malformed chunked encoding was
detected. A remote attacker could possibly use this flaw to make Tomcat
process part of the request body as new request, or cause a denial of
service. (CVE-2014-0227)

This update also fixes the following bug:

* Before this update, the tomcat6 init script did not try to kill the
tomcat process if an attempt to stop it was unsuccessful, which would
prevent tomcat from restarting properly. The init script was modified to
correct this issue. (BZ#1207048)

All Tomcat 6 users are advised to upgrade to these updated packages, which
correct these issues. Tomcat must be restarted for this update to take
effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0991</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0227</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150991"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150998" severity="high">
    <xccdf:title>RHSA-2015:0998: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An out-of-bounds memory access flaw was found in the way QEMU's virtual
Floppy Disk Controller (FDC) handled FIFO buffer access while processing
certain FDC commands. A privileged guest user could use this flaw to crash
the guest or, potentially, execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-3456)

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting
this issue.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0998</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3456</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150998"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20150999" severity="high">
    <xccdf:title>RHSA-2015:0999: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An out-of-bounds memory access flaw was found in the way QEMU's virtual
Floppy Disk Controller (FDC) handled FIFO buffer access while processing
certain FDC commands. A privileged guest user could use this flaw to crash
the guest or, potentially, execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-3456)

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting
this issue.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:0999</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3456</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20150999"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151002" severity="high">
    <xccdf:title>RHSA-2015:1002: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

An out-of-bounds memory access flaw was found in the way QEMU's virtual
Floppy Disk Controller (FDC) handled FIFO buffer access while processing
certain FDC commands. A privileged guest user could use this flaw to crash
the guest or, potentially, execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-3456)

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting
this issue.

All xen users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, all running fully-virtualized guests must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1002</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3456</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151002"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151003" severity="high">
    <xccdf:title>RHSA-2015:1003: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems.

An out-of-bounds memory access flaw was found in the way QEMU's virtual
Floppy Disk Controller (FDC) handled FIFO buffer access while processing
certain FDC commands. A privileged guest user could use this flaw to crash
the guest or, potentially, execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-3456)

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting
this issue.

All kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Note: The procedure in
the Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1003</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3456</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151003"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151012" severity="high">
    <xccdf:title>RHSA-2015:1012: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-2708, CVE-2015-2710, CVE-2015-2713)

A heap-based buffer overflow flaw was found in the way Thunderbird
processed compressed XML data. An attacker could create specially crafted
compressed XML content that, when processed by Thunderbird, could cause it
to crash or execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-2716)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jesse Ruderman, Mats Palmgren, Byron Campen, Steve
Fink, Atte Kettunen, Scott Bell, and Ucha Gobejishvili as the original
reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.7. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.7, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2716</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151012"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151042" severity="high">
    <xccdf:title>RHSA-2015:1042: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's implementation of vectored pipe read
and write functionality did not take into account the I/O vectors that were
already processed when retrying after a failed atomic access operation,
potentially resulting in memory corruption due to an I/O vector array
overrun. A local, unprivileged user could use this flaw to crash the system
or, potentially, escalate their privileges on the system. (CVE-2015-1805,
Important)

The security impact of this issue was discovered by Red Hat.

This update fixes the following bugs:

* Due to a bug in the lpfc_device_reset_handler() function, a scsi command
timeout could lead to a system crash. With this update,
lpfc_device_reset_handler recovers storage without crashing. (BZ#1070964)

* Due to the code decrementing the reclaim_in_progress counter without
having incremented it first, severe spinlock contention occurred in the
shrink_zone() function even though the vm.max_reclaims_in_progress feature
was set to 1. This update provides a patch fixing the underlying source
code, and spinlock contention no longer occurs in this scenario.
(BZ#1164105)

* A TCP socket using SACK that had a retransmission but recovered from it,
failed to reset the retransmission timestamp. As a consequence, on certain
connections, if a packet had to be re-transmitted, the retrans_stamp
variable was only cleared when the next acked packet was received.
This could lead to an early abortion of the TCP connection if this next
packet also got lost. With this update, the socket clears retrans_stamp
when the recovery is completed, thus fixing the bug. (BZ#1205521)

* Previously, the signal delivery paths did not clear the TS_USEDFPU flag,
which could cause problems in the switch_to() function and lead to
floating-point unit (FPU) corruption. With this update, TS_USEDFPU is
cleared as expected, and FPU is no longer under threat of corruption.
(BZ#1193505)

* A race condition in the exit_sem() function previously caused the
semaphore undo list corruption. As a consequence, a kernel crash could
occur. The corruption in the semaphore undo list has been fixed, and the
kernel no longer crashes in this situation. (BZ#1124574)

* Previously, when running the "virsh blockresize [Device] [Newsize]"
command to resize the disk, the new size was not reflected in a Red Hat
Enterprise Linux 5 Virtual Machine (VM). With this update, the new size is
now reflected online immediately in a Red Hat Enterprise Linux 5 VM so it
is no longer necessary to reboot the VM to see the new disk size.
(BZ#1200855)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1042</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1805</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151042"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151072" severity="medium">
    <xccdf:title>RHSA-2015:1072: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A flaw was found in the way the TLS protocol composes the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them do decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenSSL to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Future updates may raise this limit to
1024 bits.

All openssl users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1072</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151072"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151081" severity="high">
    <xccdf:title>RHSA-2015:1081: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's implementation of vectored pipe read
and write functionality did not take into account the I/O vectors that were
already processed when retrying after a failed atomic access operation,
potentially resulting in memory corruption due to an I/O vector array
overrun. A local, unprivileged user could use this flaw to crash the system
or, potentially, escalate their privileges on the system. (CVE-2015-1805,
Important)

* A buffer overflow flaw was found in the way the Linux kernel's Intel
AES-NI instructions optimized version of the RFC4106 GCM mode decryption
functionality handled fragmented packets. A remote attacker could use this
flaw to crash, or potentially escalate their privileges on, a system over a
connection with an active AES-GCM mode IPSec security association.
(CVE-2015-3331, Important)

* An information leak flaw was found in the way the Linux kernel changed
certain segment registers and thread-local storage (TLS) during a context
switch. A local, unprivileged user could use this flaw to leak the user
space TLS base address of an arbitrary process. (CVE-2014-9419, Low)

* It was found that the Linux kernel's ISO file system implementation did
not correctly limit the traversal of Rock Ridge extension Continuation
Entries (CE). An attacker with physical access to the system could use this
flaw to trigger an infinite loop in the kernel, resulting in a denial of
service. (CVE-2014-9420, Low)

* An information leak flaw was found in the way the Linux kernel's Virtual
Dynamic Shared Object (vDSO) implementation performed address
randomization. A local, unprivileged user could use this flaw to leak
kernel memory addresses to user-space. (CVE-2014-9585, Low)

Red Hat would like to thank Carl Henrik Lunde for reporting 
CVE-2014-9420. The security impact of the CVE-2015-1805 issue was 
discovered by Red Hat.

This update also fixes several bugs and adds various enhancements.
Documentation for these changes is available from the Technical Notes
document linked to in the References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3331</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151081"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151083" severity="high">
    <xccdf:title>RHSA-2015:1083: abrt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. 

It was found that ABRT was vulnerable to multiple race condition and 
symbolic link flaws. A local attacker could use these flaws to potentially 
escalate their privileges on the system. (CVE-2015-3315)

It was discovered that the kernel-invoked coredump processor provided by 
ABRT wrote core dumps to files owned by other system users. This could 
result in information disclosure if an application crashed while its 
current directory was a directory writable to by other users (such as 
/tmp). (CVE-2015-3142)

It was discovered that the default event handling scripts installed by ABRT 
did not handle symbolic links correctly. A local attacker with write access 
to an ABRT problem directory could use this flaw to escalate their 
privileges. (CVE-2015-1869)

It was found that the ABRT event scripts created a user-readable copy of an 
sosreport file in ABRT problem directories, and included excerpts of 
/var/log/messages selected by the user-controlled process name, leading to 
an information disclosure. (CVE-2015-1870)

It was discovered that, when moving problem reports between certain 
directories, abrt-handle-upload did not verify that the new problem 
directory had appropriate permissions and did not contain symbolic links. 
An attacker able to create a crafted problem report could use this flaw to 
expose other parts of ABRT to attack, or to overwrite arbitrary files on
the system. (CVE-2015-3147)

Multiple directory traversal flaws were found in the abrt-dbus D-Bus 
service. A local attacker could use these flaws to read and write arbitrary 
files as the root user. (CVE-2015-3151)

It was discovered that the abrt-dbus D-Bus service did not properly check 
the validity of the problem directory argument in the ChownProblemDir, 
DeleteElement, and DeleteProblem methods. A local attacker could use this 
flaw to take ownership of arbitrary files and directories, or to delete
files and directories as the root user. (CVE-2015-3150)

It was discovered that the abrt-action-install-debuginfo-to-abrt-cache 
helper program did not properly filter the process environment before 
invoking abrt-action-install-debuginfo. A local attacker could use this 
flaw to escalate their privileges on the system. (CVE-2015-3159)

All users of abrt are advised to upgrade to these updated packages, which 
correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3315</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151083"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151087" severity="high">
    <xccdf:title>RHSA-2015:1087: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

A flaw was found in the way QEMU's AMD PCnet Ethernet emulation handled
multi-TMD packets with a length above 4096 bytes. A privileged guest user
in a guest with an AMD PCNet ethernet card enabled could potentially use
this flaw to execute arbitrary code on the host with the privileges of the
hosting QEMU process. (CVE-2015-3209)

Red Hat would like to thank Matt Tait of Google's Project Zero security
team for reporting this issue.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1087</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3209</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151087"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151090" severity="high">
    <xccdf:title>RHSA-2015:1090: wpa_supplicant security and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wpa_supplicant package contains an 802.1X Supplicant with support for
WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication
methods. It implements key negotiation with a WPA Authenticator for client
stations and controls the roaming and IEEE 802.11 authentication and
association of the WLAN driver.

A buffer overflow flaw was found in the way wpa_supplicant handled SSID
information in the Wi-Fi Direct / P2P management frames. A specially
crafted frame could allow an attacker within Wi-Fi radio range to cause
wpa_supplicant to crash or, possibly, execute arbitrary code.
(CVE-2015-1863)

An integer underflow flaw, leading to a buffer over-read, was found in the
way wpa_supplicant handled WMM Action frames. A specially crafted frame
could possibly allow an attacker within Wi-Fi radio range to cause
wpa_supplicant to crash. (CVE-2015-4142)

Red Hat would like to thank Jouni Malinen of the wpa_supplicant upstream
for reporting the CVE-2015-1863 issue. Upstream acknowledges Alibaba
security team as the original reporter.

This update also adds the following enhancement:

* Prior to this update, wpa_supplicant did not provide a way to require the
host name to be listed in an X.509 certificate's Common Name or Subject
Alternative Name, and only allowed host name suffix or subject substring
checks. This update introduces a new configuration directive,
'domain_match', which adds a full host name check. (BZ#1178263)

All wpa_supplicant users are advised to upgrade to this updated package,
which contains backported patches to correct these issues and add this
enhancement. After installing this update, the wpa_supplicant service will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1090</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1863</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4142</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151090"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151115" severity="medium">
    <xccdf:title>RHSA-2015:1115: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An invalid free flaw was found in the way OpenSSL handled certain DTLS
handshake messages. A malicious DTLS client or server could cause a DTLS
server or client using OpenSSL to crash or, potentially, execute arbitrary
code. (CVE-2014-8176)

A flaw was found in the way the OpenSSL packages shipped with Red Hat
Enterprise Linux 6 and 7 performed locking in the ssleay_rand_bytes()
function. This issue could possibly cause a multi-threaded application
using OpenSSL to perform an out-of-bounds read and crash. (CVE-2015-3216)

An out-of-bounds read flaw was found in the X509_cmp_time() function of
OpenSSL. A specially crafted X.509 certificate or a Certificate Revocation
List (CRL) could possibly cause a TLS/SSL server or client using OpenSSL
to crash. (CVE-2015-1789)

A race condition was found in the session handling code of OpenSSL. This
issue could possibly cause a multi-threaded TLS/SSL client using OpenSSL
to double free session ticket data and crash. (CVE-2015-1791)

A flaw was found in the way OpenSSL handled Cryptographic Message Syntax
(CMS) messages. A CMS message with an unknown hash function identifier
could cause an application using OpenSSL to enter an infinite loop. 
(CVE-2015-1792)

A NULL pointer dereference was found in the way OpenSSL handled certain
PKCS#7 inputs. A specially crafted PKCS#7 input with missing
EncryptedContent data could cause an application using OpenSSL to crash.
(CVE-2015-1790)

Red Hat would like to thank the OpenSSL project for reporting
CVE-2014-8176, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791 and
CVE-2015-1792 flaws. Upstream acknowledges Praveen Kariyanahalli and Ivan
Fratric as the original reporters of CVE-2014-8176, Robert Swiecki and
Hanno Böck as the original reporters of CVE-2015-1789, Michal Zalewski as
the original reporter of CVE-2015-1790, Emilia Käsper as the original
report of  CVE-2015-1791 and Johannes Bauer as the original reporter of
CVE-2015-1792.

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1115</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1791</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1792</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3216</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151115"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151123" severity="high">
    <xccdf:title>RHSA-2015:1123: cups security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>CUPS provides a portable printing layer for Linux, UNIX, and similar
operating systems.

A string reference count bug was found in cupsd, causing premature freeing
of string objects. An attacker can submit a malicious print job that
exploits this flaw to dismantle ACLs protecting privileged operations,
allowing a replacement configuration file to be uploaded which in turn
allows the attacker to run arbitrary code in the CUPS server (CVE-2015-1158)

A cross-site scripting flaw was found in the cups web templating engine. An 
attacker could use this flaw to bypass the default configuration settings 
that bind the CUPS scheduler to the 'localhost' or loopback interface.
(CVE-2015-1159)

An integer overflow leading to a heap-based buffer overflow was found in
the way cups handled compressed raster image files. An attacker could
create a specially-crafted image file, which when passed via the cups
Raster filter, could cause the cups filter to crash. (CVE-2014-9679)

Red Hat would like to thank the CERT/CC for reporting CVE-2015-1158 and 
CVE-2015-1159 issues.

All cups users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1123</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9679</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1158</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1159</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151123"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151135" severity="high">
    <xccdf:title>RHSA-2015:1135: php security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way the PHP module for the Apache httpd web server
handled pipelined requests. A remote attacker could use this flaw to
trigger the execution of a PHP script in a deinitialized interpreter,
causing it to crash or, possibly, execute arbitrary code. (CVE-2015-3330)

A flaw was found in the way PHP parsed multipart HTTP POST requests. A
specially crafted request could cause PHP to use an excessive amount of CPU
time. (CVE-2015-4024)

An uninitialized pointer use flaw was found in PHP's Exif extension. A
specially crafted JPEG or TIFF file could cause a PHP application using the
exif_read_data() function to crash or, possibly, execute arbitrary code
with the privileges of the user running that PHP application.
(CVE-2015-0232)

An integer overflow flaw leading to a heap-based buffer overflow was found
in the way PHP's FTP extension parsed file listing FTP server responses. A
malicious FTP server could use this flaw to cause a PHP application to
crash or, possibly, execute arbitrary code. (CVE-2015-4022)

Multiple flaws were discovered in the way PHP performed object
unserialization. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash or, possibly, execute
arbitrary code. (CVE-2014-8142, CVE-2015-0231, CVE-2015-0273,
CVE-2015-2787, CVE-2015-4147, CVE-2015-4148, CVE-2015-4599, CVE-2015-4600,
CVE-2015-4601, CVE-2015-4602, CVE-2015-4603)

It was found that certain PHP functions did not properly handle file names
containing a NULL character. A remote attacker could possibly use this flaw
to make a PHP script access unexpected files and bypass intended file
system access restrictions. (CVE-2015-2348, CVE-2015-4025, CVE-2015-4026,
CVE-2015-3411, CVE-2015-3412, CVE-2015-4598)

Multiple flaws were found in the way the way PHP's Phar extension parsed
Phar archives. A specially crafted archive could cause PHP to crash or,
possibly, execute arbitrary code when opened. (CVE-2015-2301,
CVE-2015-2783, CVE-2015-3307, CVE-2015-3329, CVE-2015-4021)

Multiple flaws were found in PHP's File Information (fileinfo) extension.
A remote attacker could cause a PHP application to crash if it used
fileinfo to identify type of attacker supplied files. (CVE-2014-9652,
CVE-2015-4604, CVE-2015-4605)

A heap buffer overflow flaw was found in the enchant_broker_request_dict()
function of PHP's enchant extension. An attacker able to make a PHP
application enchant dictionaries could possibly cause it to crash.
(CVE-2014-9705)

A buffer over-read flaw was found in the GD library used by the PHP gd
extension. A specially crafted GIF file could cause a PHP application using
the imagecreatefromgif() function to crash. (CVE-2014-9709)

This update also fixes the following bugs:

* The libgmp library in some cases terminated unexpectedly with a
segmentation fault when being used with other libraries that use the GMP
memory management. With this update, PHP no longer changes libgmp memory
allocators, which prevents the described crash from occurring. (BZ#1212305)

* When using the Open Database Connectivity (ODBC) API, the PHP process
in some cases terminated unexpectedly with a segmentation fault. The
underlying code has been adjusted to prevent this crash. (BZ#1212299)

* Previously, running PHP on a big-endian system sometimes led to memory
corruption in the fileinfo module. This update adjusts the behavior of
the PHP pointer so that it can be freed without causing memory corruption.
(BZ#1212298)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1135</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2348</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4025</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4604</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4605</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151135"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151137" severity="high">
    <xccdf:title>RHSA-2015:1137: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's implementation of vectored pipe read
and write functionality did not take into account the I/O vectors that were
already processed when retrying after a failed atomic access operation,
potentially resulting in memory corruption due to an I/O vector array
overrun. A local, unprivileged user could use this flaw to crash the system
or, potentially, escalate their privileges on the system. (CVE-2015-1805,
Important)

* A race condition flaw was found in the way the Linux kernel keys
management subsystem performed key garbage collection. A local attacker
could attempt accessing a key while it was being garbage collected, which
would cause the system to crash. (CVE-2014-9529, Moderate)

* A flaw was found in the way the Linux kernel's 32-bit emulation
implementation handled forking or closing of a task with an 'int80' entry.
A local user could potentially use this flaw to escalate their privileges
on the system. (CVE-2015-2830, Low)

* It was found that the Linux kernel's ISO file system implementation did
not correctly limit the traversal of Rock Ridge extension Continuation
Entries (CE). An attacker with physical access to the system could use this
flaw to trigger an infinite loop in the kernel, resulting in a denial of
service. (CVE-2014-9420, Low)

* An information leak flaw was found in the way the Linux kernel's ISO9660
file system implementation accessed data on an ISO9660 image with RockRidge
Extension Reference (ER) records. An attacker with physical access to the
system could use this flaw to disclose up to 255 bytes of kernel memory.
(CVE-2014-9584, Low)

* A flaw was found in the way the nft_flush_table() function of the Linux
kernel's netfilter tables implementation flushed rules that were
referencing deleted chains. A local user who has the CAP_NET_ADMIN
capability could use this flaw to crash the system. (CVE-2015-1573, Low)

* An integer overflow flaw was found in the way the Linux kernel randomized
the stack for processes on certain 64-bit architecture systems, such as
x86-64, causing the stack entropy to be reduced by four. (CVE-2015-1593,
Low)

Red Hat would like to thank Carl Henrik Lunde for reporting CVE-2014-9420
and CVE-2014-9584. The security impact of the CVE-2015-1805 issue was
discovered by Red Hat.

This update also fixes several bugs. Documentation for these changes is
available from the following Knowledgebase article:
https://access.redhat.com/articles/1469163

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1137</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2830</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151137"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151139" severity="high">
    <xccdf:title>RHSA-2015:1139: kernel-rt security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's implementation of vectored pipe read
and write functionality did not take into account the I/O vectors that were
already processed when retrying after a failed atomic access operation,
potentially resulting in memory corruption due to an I/O vector array
overrun. A local, unprivileged user could use this flaw to crash the system
or, potentially, escalate their privileges on the system. (CVE-2015-1805,
Important)

* A race condition flaw was found in the way the Linux kernel keys
management subsystem performed key garbage collection. A local attacker
could attempt accessing a key while it was being garbage collected, which
would cause the system to crash. (CVE-2014-9529, Moderate)

* A flaw was found in the way the Linux kernel's 32-bit emulation
implementation handled forking or closing of a task with an 'int80' entry.
A local user could potentially use this flaw to escalate their privileges
on the system. (CVE-2015-2830, Low)

* It was found that the Linux kernel's ISO file system implementation did
not correctly limit the traversal of Rock Ridge extension Continuation
Entries (CE). An attacker with physical access to the system could use this
flaw to trigger an infinite loop in the kernel, resulting in a denial of
service. (CVE-2014-9420, Low)

* An information leak flaw was found in the way the Linux kernel's ISO9660
file system implementation accessed data on an ISO9660 image with RockRidge
Extension Reference (ER) records. An attacker with physical access to the
system could use this flaw to disclose up to 255 bytes of kernel memory.
(CVE-2014-9584, Low)

* A flaw was found in the way the nft_flush_table() function of the Linux
kernel's netfilter tables implementation flushed rules that were
referencing deleted chains. A local user who has the CAP_NET_ADMIN
capability could use this flaw to crash the system. (CVE-2015-1573, Low)

* An integer overflow flaw was found in the way the Linux kernel randomized
the stack for processes on certain 64-bit architecture systems, such as
x86-64, causing the stack entropy to be reduced by four. (CVE-2015-1593,
Low)

Red Hat would like to thank Carl Henrik Lunde for reporting CVE-2014-9420
and CVE-2014-9584. The security impact of CVE-2015-1805 was discovered by
Red Hat.

The kernel-rt packages have been upgraded to version 3.10.0-229.7.2, which
provides a number of bug fixes and enhancements over the previous version,
including:

* storvsc: get rid of overly verbose warning messages
* storvsc: force discovery of LUNs that may have been removed
* storvsc: in responce to a scan event, scan the hos
* storvsc: NULL pointer dereference fix
* futex: Mention key referencing differences between shared and private
futexes
* futex: Ensure get_futex_key_refs() always implies a barrier
* kernel module: set nx before marking module MODULE_STATE_COMING
* kernel module: Clean up ro/nx after early module load failures
* btrfs: make xattr replace operations atomic
* megaraid_sas: revert: Add release date and update driver version
* radeon: fix kernel segfault in hwmonitor

(BZ#1223955)

Bug fix:

* There is an XFS optimization that depended on a spinlock to disable
preemption using the preempt_disable() function. When CONFIG_PREEMPT_RT is
enabled on realtime kernels, spinlocks do not disable preemption while
held, so the XFS critical section was not protected from preemption.
Systems on the Realtime kernel-rt could lock up in this XFS optimization
when a task that locked all the counters was then preempted by a realtime
task, causing all callers of that lock to block indefinitely. This update
disables the optimization when building a kernel with
CONFIG_PREEMPT_RT_FULL enabled. (BZ#1223955)

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1139</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9420</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9529</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9584</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2830</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151139"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151153" severity="medium">
    <xccdf:title>RHSA-2015:1153: mailman security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage email discussion lists.

It was found that mailman did not sanitize the list name before passing it
to certain MTAs. A local attacker could use this flaw to execute arbitrary
code as the user running mailman. (CVE-2015-2775)

This update also fixes the following bugs:

* Previously, it was impossible to configure Mailman in a way that
Domain-based Message Authentication, Reporting &amp; Conformance (DMARC) would
recognize Sender alignment for Domain Key Identified Mail (DKIM)
signatures. Consequently, Mailman list subscribers that belonged to a mail
server with a "reject" policy for DMARC, such as yahoo.com or AOL.com, were
unable to receive Mailman forwarded messages from senders residing in any
domain that provided DKIM signatures. With this update, domains with a
"reject" DMARC policy are recognized correctly, and Mailman list
administrators are able to configure the way these messages are handled. As
a result, after a proper configuration, subscribers now correctly receive
Mailman forwarded messages in this scenario. (BZ#1229288)

* Previously, the /etc/mailman file had incorrectly set permissions, which
in some cases caused removing Mailman lists to fail with a "'NoneType'
object has no attribute 'close'" message. With this update, the permissions
value for /etc/mailman is correctly set to 2775 instead of 0755, and
removing Mailman lists now works as expected. (BZ#1229307)

* Prior to this update, the mailman utility incorrectly installed the
tmpfiles configuration in the /etc/tmpfiles.d/ directory. As a consequence,
changes made to mailman tmpfiles configuration were overwritten if the
mailman packages were reinstalled or updated. The mailman utility now
installs the tmpfiles configuration in the /usr/lib/tmpfiles.d/ directory,
and changes made to them by the user are preserved on reinstall or update.
(BZ#1229306)

All mailman users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1153</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2775</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151153"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151154" severity="medium">
    <xccdf:title>RHSA-2015:1154: libreswan security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Libreswan is an implementation of IPsec &amp; IKE for Linux. IPsec is the
Internet Protocol Security and uses strong cryptography to provide both
authentication and encryption services. These services allow you to build
secure tunnels through untrusted networks such as virtual private network
(VPN).

A flaw was discovered in the way Libreswan's IKE daemon processed certain
IKEv1 payloads. A remote attacker could send specially crafted IKEv1
payloads that, when processed, would lead to a denial of service (daemon
crash). (CVE-2015-3204)

Red Hat would like to thank Javantea for reporting this issue.

This update fixes the following bugs:

* Previously, the programs/pluto/state.h and
programs/pluto/kernel_netlink.c files had a maximum SELinux context size
of 257 and 1024 respectively. These restrictions set by libreswan limited
the size of the context that can be exchanged by pluto (the IPSec daemon)
when using a Labeled Internet Protocol Security (IPsec). The SElinux
labels for Labeled IPsec have been extended to 4096 bytes and the
mentioned restrictions no longer exist. (BZ#1198650)

* On some architectures, the kernel AES_GCM IPsec algorithm did not work
properly with acceleration drivers. On those kernels, some acceleration
modules are added to the modprobe blacklist. However, Libreswan was
ignoring this blacklist, leading to AES_GCM failures. This update adds
support for the module blacklist to the libreswan packages and thus
prevents the AES_GCM failures from occurring. (BZ#1208022)

* An IPv6 issue has been resolved that prevented ipv6-icmp Neighbour
Discovery from working properly once an IPsec tunnel is established (and
one endpoint reboots). When upgrading, ensure that /etc/ipsec.conf is
loading all /etc/ipsec.d/*conf files using the /etc/ipsec.conf "include"
statement, or explicitly include this new configuration file in
/etc/ipsec.conf. (BZ#1208023)

* A FIPS self-test prevented libreswan from properly starting in FIPS mode.
This bug has been fixed and libreswan now works in FIPS mode as expected.
(BZ#1211146)

In addition, this update adds the following enhancements:

* A new option "seedbits=" has been added to pre-seed the Network Security
Services (NSS) pseudo random number generator (PRNG) function with entropy
from the /dev/random file on startup. This option is disabled by default.
It can be enabled by setting the "seedbits=" option in the "config setup"
section in the /etc/ipsec.conf file. (BZ#1198649)

* The build process now runs a Cryptographic Algorithm Validation Program
(CAVP) certification test on the Internet Key Exchange version 1 and 2
(IKEv1 and IKEv2) PRF/PRF+ functions. (BZ#1213652)

All libreswan users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3204</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151185" severity="medium">
    <xccdf:title>RHSA-2015:1185: nss security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support 
cross-platform development of security-enabled client and server
applications.

A flaw was found in the way the TLS protocol composes the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them do decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in NSS to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Future updates may raise this limit to
1024 bits.

The nss and nss-util packages have been upgraded to upstream versions
3.19.1. The upgraded versions provide a number of bug fixes and
enhancements over the previous versions.

Users of nss and nss-util are advised to upgrade to these updated packages,
which fix these security flaws, bugs, and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151185"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151189" severity="high">
    <xccdf:title>RHSA-2015:1189: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems.

A flaw was found in the way QEMU's AMD PCnet Ethernet emulation handled
multi-TMD packets with a length above 4096 bytes. A privileged guest user
in a guest with an AMD PCNet ethernet card enabled could potentially use
this flaw to execute arbitrary code on the host with the privileges of the
hosting QEMU process. (CVE-2015-3209)

Red Hat would like to thank Matt Tait of Google's Project Zero security
team for reporting this issue.

All kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Note: The procedure in
the Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3209</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151189"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151193" severity="medium">
    <xccdf:title>RHSA-2015:1193: xerces-c security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Xerces-C is a validating XML parser written in a portable subset of C++.

A flaw was found in the way the Xerces-C XML parser processed certain XML
documents. A remote attacker could provide specially crafted XML input
that, when parsed by an application using Xerces-C, would cause that
application to crash. (CVE-2015-0252)

All xerces-c users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0252</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151193"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151194" severity="medium">
    <xccdf:title>RHSA-2015:1194: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A double-free flaw was found in the connection handling. An unauthenticated
attacker could exploit this flaw to crash the PostgreSQL back end by
disconnecting at approximately the same time as the authentication time out
is triggered. (CVE-2015-3165)

It was discovered that PostgreSQL did not properly check the return values
of certain standard library functions. If the system is in a state that
would cause the standard library functions to fail, for example memory
exhaustion, an authenticated user could exploit this flaw to disclose
partial memory contents or cause the GSSAPI authentication to use an
incorrect keytab file. (CVE-2015-3166)

It was discovered that the pgcrypto module could return different error
messages when decrypting certain data with an incorrect key. This can help
an authenticated user to launch a possible cryptographic attack, although
no suitable attack is currently known. (CVE-2015-3167)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Benkocs Norbert Attila as the original
reporter of CVE-2015-3165 and Noah Misch as the original reporter of
CVE-2015-3166 and CVE-2015-3167.

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the
postgresql service is running, it will be automatically restarted after
installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3165</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3166</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3167</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151194"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151197" severity="medium">
    <xccdf:title>RHSA-2015:1197: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An out-of-bounds read flaw was found in the X509_cmp_time() function of
OpenSSL. A specially crafted X.509 certificate or a Certificate Revocation
List (CRL) could possibly cause a TLS/SSL server or client using OpenSSL
to crash. (CVE-2015-1789)

A NULL pointer dereference was found in the way OpenSSL handled certain
PKCS#7 inputs. A specially crafted PKCS#7 input with missing
EncryptedContent data could cause an application using OpenSSL to crash.
(CVE-2015-1790)

A flaw was found in the way the TLS protocol composes the Diffie-Hellman 
(DH) key exchange. A man-in-the-middle attacker could use this flaw to 
force the use of weak 512 bit export-grade keys during the key exchange, 
allowing them to decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenSSL to 
reject DH key sizes below 768 bits, which prevents sessions to be 
downgraded to export-grade keys. Future updates may raise this limit to 
1024 bits.

Red Hat would like to thank the OpenSSL project for reporting CVE-2015-1789
and CVE-2015-1790. Upstream acknowledges Robert Swiecki and Hanno Böck as
the original reporters of CVE-2015-1789, and Michal Zalewski as the
original reporter of CVE-2015-1790.

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1789</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1790</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151207" severity="high">
    <xccdf:title>RHSA-2015:1207: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-2724, CVE-2015-2725, CVE-2015-2722, CVE-2015-2727,
CVE-2015-2728, CVE-2015-2729, CVE-2015-2731, CVE-2015-2733, CVE-2015-2734,
CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739,
CVE-2015-2740)

It was found that Firefox skipped key-pinning checks when handling an error
that could be overridden by the user (for example an expired certificate
error). This flaw allowed a user to override a pinned certificate, which is
an action the user should not be able to perform. (CVE-2015-2741)

A flaw was discovered in Mozilla's PDF.js PDF file viewer. When combined
with another vulnerability, it could allow execution of arbitrary code with
the privileges of the user running Firefox. (CVE-2015-2743)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bob Clary, Christian Holler, Bobby Holley, Andrew
McCreight, Terrence Cole, Steve Fink, Mats Palmgren, Wes Kocher, Andreas
Pehrson, Jann Horn, Paul Bandha, Holger Fuhrmannek, Herre, Looben Yan,
Ronald Crane, and Jonas Jenwald as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.1 ESR, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2722</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2727</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2728</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2743</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151207"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151210" severity="medium">
    <xccdf:title>RHSA-2015:1210: abrt security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality.

It was found that ABRT was vulnerable to multiple race condition and
symbolic link flaws. A local attacker could use these flaws to potentially
escalate their privileges on the system. (CVE-2015-3315)

It was discovered that the kernel-invoked coredump processor provided by
ABRT wrote core dumps to files owned by other system users. This could
result in information disclosure if an application crashed while its
current directory was a directory writable to by other users (such as
/tmp). (CVE-2015-3142)

It was discovered that the default event handling scripts installed by ABRT
did not handle symbolic links correctly. A local attacker with write access
to an ABRT problem directory could use this flaw to escalate their
privileges. (CVE-2015-1869)

It was found that the ABRT event scripts created a user-readable copy of an
sosreport file in ABRT problem directories, and included excerpts of
/var/log/messages selected by the user-controlled process name, leading to
an information disclosure. (CVE-2015-1870)

It was discovered that, when moving problem reports between certain
directories, abrt-handle-upload did not verify that the new problem
directory had appropriate permissions and did not contain symbolic links.
An attacker able to create a crafted problem report could use this flaw to
expose other parts of ABRT, or to overwrite arbitrary files on the system.
(CVE-2015-3147)

It was discovered that the abrt-action-install-debuginfo-to-abrt-cache
helper program did not properly filter the process environment before
invoking abrt-action-install-debuginfo. A local attacker could use this
flaw to escalate their privileges on the system. (CVE-2015-3159)

The CVE-2015-1869, CVE-2015-1870, CVE-2015-3142, CVE-2015-3147, and
CVE-2015-3159 issues were discovered by Florian Weimer of Red Hat
Product Security.

All users of abrt are advised to upgrade to these updated packages, which
correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1869</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1870</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3142</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3315</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151210"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151218" severity="medium">
    <xccdf:title>RHSA-2015:1218: php security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way PHP parsed multipart HTTP POST requests. A
specially crafted request could cause PHP to use an excessive amount of CPU
time. (CVE-2015-4024)

An uninitialized pointer use flaw was found in PHP's Exif extension. A
specially crafted JPEG or TIFF file could cause a PHP application using the
exif_read_data() function to crash or, possibly, execute arbitrary code
with the privileges of the user running that PHP application.
(CVE-2015-0232)

An integer overflow flaw leading to a heap-based buffer overflow was found
in the way PHP's FTP extension parsed file listing FTP server responses. A
malicious FTP server could use this flaw to cause a PHP application to
crash or, possibly, execute arbitrary code. (CVE-2015-4022)

Multiple flaws were discovered in the way PHP performed object
unserialization. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash or, possibly, execute
arbitrary code. (CVE-2015-0273, CVE-2015-2787, CVE-2015-4147,
CVE-2015-4148, CVE-2015-4599, CVE-2015-4600, CVE-2015-4601, CVE-2015-4602,
CVE-2015-4603)

It was found that certain PHP functions did not properly handle file names
containing a NULL character. A remote attacker could possibly use this flaw
to make a PHP script access unexpected files and bypass intended file
system access restrictions. (CVE-2015-4026, CVE-2015-3411, CVE-2015-3412,
CVE-2015-4598)

Multiple flaws were found in the way the way PHP's Phar extension parsed
Phar archives. A specially crafted archive could cause PHP to crash or,
possibly, execute arbitrary code when opened. (CVE-2015-2301,
CVE-2015-2783, CVE-2015-3307, CVE-2015-3329, CVE-2015-4021)

A heap buffer overflow flaw was found in the enchant_broker_request_dict()
function of PHP's enchant extension. An attacker able to make a PHP
application enchant dictionaries could possibly cause it to crash.
(CVE-2014-9705)

A buffer over-read flaw was found in the GD library used by the PHP gd
extension. A specially crafted GIF file could cause a PHP application using
the imagecreatefromgif() function to crash. (CVE-2014-9709)

A double free flaw was found in zend_ts_hash_graceful_destroy() function in
the PHP ZTS module. This flaw could possibly cause a PHP application to
crash. (CVE-2014-9425)

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1218</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9425</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0232</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2301</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2783</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2787</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3329</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3412</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4021</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4022</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4024</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4026</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4147</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4148</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4598</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4599</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4602</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4603</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4643</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151218"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151221" severity="medium">
    <xccdf:title>RHSA-2015:1221: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A NULL pointer dereference flaw was found in the way the Linux kernel's
virtual console implementation handled reference counting when accessing
pseudo-terminal device files (/dev/pts/*). A local, unprivileged attacker
could use this flaw to crash the system. (CVE-2011-5321, Moderate)

* It was found that the Linux kernel's ping socket implementation did not
properly handle socket unhashing during spurious disconnects, which could
lead to a use-after-free flaw. On x86-64 architecture systems, a local user
able to create ping sockets could use this flaw to crash the system.
On non-x86-64 architecture systems, a local user able to create ping
sockets could use this flaw to escalate their privileges on the system.
(CVE-2015-3636, Moderate)

* An integer overflow flaw was found in the way the Linux kernel randomized
the stack for processes on certain 64-bit architecture systems, such as
x86-64, causing the stack entropy to be reduced by four. (CVE-2015-1593,
Low)

* A flaw was found in the way the Linux kernel's 32-bit emulation
implementation handled forking or closing of a task with an 'int80' entry.
A local user could potentially use this flaw to escalate their privileges
on the system. (CVE-2015-2830, Low)

* It was found that the Linux kernel's TCP/IP protocol suite implementation
for IPv6 allowed the Hop Limit value to be set to a smaller value than the
default one. An attacker on a local network could use this flaw to prevent
systems on that network from sending or receiving network packets.
(CVE-2015-2922, Low)

These updated kernel packages also include numerous bug fixes and one
enhancement. Space precludes documenting all of these changes in this
advisory. For information on the most significant of these changes, users
are directed to the following article on the Red Hat Customer Portal:

https://access.redhat.com/articles/1506133

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1221</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2011-5321</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1593</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2830</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2922</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151221"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151228" severity="high">
    <xccdf:title>RHSA-2015:1228: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

Multiple flaws were discovered in the 2D, CORBA, JMX, Libraries and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2015-4760,
CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733)

A flaw was found in the way the Libraries component of OpenJDK verified
Online Certificate Status Protocol (OCSP) responses. An OCSP response with
no nextUpdate date specified was incorrectly handled as having unlimited
validity, possibly causing a revoked X.509 certificate to be interpreted as
valid. (CVE-2015-4748)

It was discovered that the JCE component in OpenJDK failed to use constant
time comparisons in multiple cases. An attacker could possibly use these
flaws to disclose sensitive information by measuring the time used to
perform operations using these non-constant time comparisons.
(CVE-2015-2601)

It was discovered that the GCM (Galois Counter Mode) implementation in the
Security component of OpenJDK failed to properly perform a null check.
This could cause the Java Virtual Machine to crash when an application
performed encryption using a block cipher in the GCM mode. (CVE-2015-2659)

A flaw was found in the RC4 encryption algorithm. When using certain keys
for RC4 encryption, an attacker could obtain portions of the plain text
from the cipher text without the knowledge of the encryption key.
(CVE-2015-2808)

Note: With this update, OpenJDK now disables RC4 TLS/SSL cipher suites by
default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla bug
1207101, linked to in the References section, for additional details about
this change.

A flaw was found in the way the TLS protocol composed the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them do decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenJDK to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Refer to Red Hat Bugzilla bug 1223211,
linked to in the References section, for additional details about this
change.

It was discovered that the JNDI component in OpenJDK did not handle DNS
resolutions correctly. An attacker able to trigger such DNS errors could
cause a Java application using JNDI to consume memory and CPU time, and
possibly block further DNS resolution. (CVE-2015-4749)

Multiple information leak flaws were found in the JMX and 2D components in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass certain Java sandbox restrictions. (CVE-2015-2621, CVE-2015-2632)

A flaw was found in the way the JSSE component in OpenJDK performed X.509
certificate identity verification when establishing a TLS/SSL connection to
a host identified by an IP address. In certain cases, the certificate was
accepted as valid if it was issued for a host name to which the IP address
resolves rather than for the IP address. (CVE-2015-2625)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. Note: This issue was
originally fixed as CVE-2015-0383, but the fix was regressed in the
RHSA-2015:0809 advisory. (CVE-2015-3149)

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1228</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3149</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151228"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151229" severity="high">
    <xccdf:title>RHSA-2015:1229: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the 2D, CORBA, JMX, Libraries and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2015-4760,
CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733)

A flaw was found in the way the Libraries component of OpenJDK verified
Online Certificate Status Protocol (OCSP) responses. An OCSP response with
no nextUpdate date specified was incorrectly handled as having unlimited
validity, possibly causing a revoked X.509 certificate to be interpreted as
valid. (CVE-2015-4748)

It was discovered that the JCE component in OpenJDK failed to use constant
time comparisons in multiple cases. An attacker could possibly use these
flaws to disclose sensitive information by measuring the time used to
perform operations using these non-constant time comparisons.
(CVE-2015-2601)

A flaw was found in the RC4 encryption algorithm. When using certain keys
for RC4 encryption, an attacker could obtain portions of the plain text
from the cipher text without the knowledge of the encryption key.
(CVE-2015-2808)

Note: With this update, OpenJDK now disables RC4 TLS/SSL cipher suites by
default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla bug
1207101, linked to in the References section, for additional details about
this change.

A flaw was found in the way the TLS protocol composed the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them do decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenJDK to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Refer to Red Hat Bugzilla bug 1223211,
linked to in the References section, for additional details about this
change.

It was discovered that the JNDI component in OpenJDK did not handle DNS
resolutions correctly. An attacker able to trigger such DNS errors could
cause a Java application using JNDI to consume memory and CPU time, and
possibly block further DNS resolution. (CVE-2015-4749)

Multiple information leak flaws were found in the JMX and 2D components in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass certain Java sandbox restrictions. (CVE-2015-2621, CVE-2015-2632)

A flaw was found in the way the JSSE component in OpenJDK performed X.509
certificate identity verification when establishing a TLS/SSL connection to
a host identified by an IP address. In certain cases, the certificate was
accepted as valid if it was issued for a host name to which the IP address
resolves rather than for the IP address. (CVE-2015-2625)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1229</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151229"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151230" severity="high">
    <xccdf:title>RHSA-2015:1230: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the 2D, CORBA, JMX, Libraries and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4760,
CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733)

A flaw was found in the way the Libraries component of OpenJDK verified
Online Certificate Status Protocol (OCSP) responses. An OCSP response with
no nextUpdate date specified was incorrectly handled as having unlimited
validity, possibly causing a revoked X.509 certificate to be interpreted as
valid. (CVE-2015-4748)

It was discovered that the JCE component in OpenJDK failed to use constant
time comparisons in multiple cases. An attacker could possibly use these
flaws to disclose sensitive information by measuring the time used to
perform operations using these non-constant time comparisons.
(CVE-2015-2601)

A flaw was found in the RC4 encryption algorithm. When using certain keys
for RC4 encryption, an attacker could obtain portions of the plain text
from the cipher text without the knowledge of the encryption key.
(CVE-2015-2808)

Note: With this update, OpenJDK now disables RC4 SSL/TLS cipher suites by
default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla bug
1207101, linked to in the References section, for additional details about
this change.

A flaw was found in the way the TLS protocol composed the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them do decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenJDK to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Refer to Red Hat Bugzilla bug 1223211,
linked to in the References section, for additional details about this
change.

It was discovered that the JNDI component in OpenJDK did not handle DNS
resolutions correctly. An attacker able to trigger such DNS errors could
cause a Java application using JNDI to consume memory and CPU time, and
possibly block further DNS resolution. (CVE-2015-4749)

Multiple information leak flaws were found in the JMX and 2D components in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass certain Java sandbox restrictions. (CVE-2015-2621, CVE-2015-2632)

A flaw was found in the way the JSSE component in OpenJDK performed X.509
certificate identity verification when establishing a TLS/SSL connection to
a host identified by an IP address. In certain cases, the certificate was
accepted as valid if it was issued for a host name to which the IP address
resolves rather than for the IP address. (CVE-2015-2625)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1230</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151230"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151241" severity="high">
    <xccdf:title>RHSA-2015:1241: java-1.8.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 8 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-2590, CVE-2015-2601, CVE-2015-2613, CVE-2015-2619, CVE-2015-2621,
CVE-2015-2625, CVE-2015-2627, CVE-2015-2628, CVE-2015-2632, CVE-2015-2637,
CVE-2015-2638, CVE-2015-2659, CVE-2015-2664, CVE-2015-2808, CVE-2015-4000,
CVE-2015-4729, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733, CVE-2015-4736,
CVE-2015-4748, CVE-2015-4749, CVE-2015-4760)

Note: With this update, Oracle JDK now disables RC4 TLS/SSL cipher suites
by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla
bug 1207101, linked to in the References section, for additional details
about this change.

Note: This update forces the TLS/SSL client implementation in Oracle JDK to
reject DH key sizes below 768 bits to address the CVE-2015-4000 issue.
Refer to Red Hat Bugzilla bug 1223211, linked to in the References section,
for additional details about this change.

All users of java-1.8.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 8 Update 51 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2637</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2659</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151241"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151242" severity="high">
    <xccdf:title>RHSA-2015:1242: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-2590, CVE-2015-2596, CVE-2015-2601, CVE-2015-2613, CVE-2015-2619,
CVE-2015-2621, CVE-2015-2625, CVE-2015-2627, CVE-2015-2628, CVE-2015-2632,
CVE-2015-2637, CVE-2015-2638, CVE-2015-2664, CVE-2015-2808, CVE-2015-4000,
CVE-2015-4729, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733, CVE-2015-4736,
CVE-2015-4748, CVE-2015-4749, CVE-2015-4760)

Note: With this update, Oracle JDK now disables RC4 TLS/SSL cipher suites
by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla
bug 1207101, linked to in the References section, for additional details
about this change.

Note: This update forces the TLS/SSL client implementation in Oracle JDK to
reject DH key sizes below 768 bits to address the CVE-2015-4000 issue.
Refer to Red Hat Bugzilla bug 1223211, linked to in the References section,
for additional details about this change.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 85 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2637</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4729</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151242"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151243" severity="high">
    <xccdf:title>RHSA-2015:1243: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-2590, CVE-2015-2601, CVE-2015-2621, CVE-2015-2625, CVE-2015-2627,
CVE-2015-2628, CVE-2015-2632, CVE-2015-2637, CVE-2015-2638, CVE-2015-2664,
CVE-2015-2808, CVE-2015-4000, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733,
CVE-2015-4748, CVE-2015-4749, CVE-2015-4760)

Note: With this update, Oracle JDK now disables RC4 TLS/SSL cipher suites
by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla
bug 1207101, linked to in the References section, for additional details
about this change.

Note: This update forces the TLS/SSL client implementation in Oracle JDK to
reject DH key sizes below 768 bits to address the CVE-2015-4000 issue.
Refer to Red Hat Bugzilla bug 1223211, linked to in the References section,
for additional details about this change.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 101 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2637</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2638</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151243"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151249" severity="low">
    <xccdf:title>RHSA-2015:1249: httpd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

A flaw was found in the way httpd handled HTTP Trailer headers when
processing requests using chunked encoding. A malicious client could use
Trailer headers to set additional HTTP headers after header processing was
performed by other modules. This could, for example, lead to a bypass of
header restrictions defined with mod_headers. (CVE-2013-5704)

This update also fixes the following bugs:

* The order of mod_proxy workers was not checked when httpd configuration
was reloaded. When mod_proxy workers were removed, added, or their order
was changed, their parameters and scores could become mixed. The order of
mod_proxy workers has been made internally consistent during configuration
reload. (BZ#1149906)

* The local host certificate created during firstboot contained CA
extensions, which caused the httpd service to return warning messages.
This has been addressed by local host certificates being generated with the
"-extensions v3_req" option. (BZ#906476)

* The default mod_ssl configuration no longer enables support for SSL
cipher suites using the single DES, IDEA, or SEED encryption algorithms.
(BZ#1086771)

* The apachectl script did not take into account the HTTPD_LANG variable
set in the /etc/sysconfig/httpd file during graceful restarts.
Consequently, httpd did not use a changed value of HTTPD_LANG when the
daemon was restarted gracefully. The script has been fixed to handle the
HTTPD_LANG variable correctly. (BZ#963146)

* The mod_deflate module failed to check the original file size while
extracting files larger than 4 GB, making it impossible to extract large
files. Now, mod_deflate checks the original file size properly according to
RFC1952, and it is able to decompress files larger than 4 GB. (BZ#1057695)

* The httpd service did not check configuration before restart. When a
configuration contained an error, an attempt to restart httpd gracefully
failed. Now, httpd checks configuration before restart and if the
configuration is in an inconsistent state, an error message is printed,
httpd is not stopped and a restart is not performed. (BZ#1146194)

* The SSL_CLIENT_VERIFY environment variable was incorrectly handled when
the "SSLVerifyClient optional_no_ca" and "SSLSessionCache" options were
used. When an SSL session was resumed, the SSL_CLIENT_VERIFY value was set
to "SUCCESS" instead of the previously set "GENEROUS". SSL_CLIENT_VERIFY is
now correctly set to GENEROUS in this scenario. (BZ#1149703)

* The ab utility did not correctly handle situations when an SSL connection
was closed after some data had already been read. As a consequence, ab did
not work correctly with SSL servers and printed "SSL read failed" error
messages. With this update, ab works as expected with HTTPS servers.
(BZ#1045477)

* When a client presented a revoked certificate, log entries were created
only at the debug level. The log level of messages regarding a revoked
certificate has been increased to INFO, and administrators are now properly
informed of this situation. (BZ#1161328)

In addition, this update adds the following enhancement:

* A mod_proxy worker can now be set into drain mode (N) using the
balancer-manager web interface or using the httpd configuration file.
A worker in drain mode accepts only existing sticky sessions destined for
itself and ignores all other requests. The worker waits until all clients
currently connected to this worker complete their work before the worker is
stopped. As a result, drain mode enables to perform maintenance on a worker
without affecting clients. (BZ#767130)

Users of httpd are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. After installing the updated packages, the httpd service will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1249</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-5704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151249"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151254" severity="medium">
    <xccdf:title>RHSA-2015:1254: curl security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP.

It was found that the libcurl library did not correctly handle partial
literal IP addresses when parsing received HTTP cookies. An attacker able
to trick a user into connecting to a malicious server could use this flaw
to set the user's cookie to a crafted domain, making other cookie-related
issues easier to exploit. (CVE-2014-3613)

A flaw was found in the way the libcurl library performed the duplication
of connection handles. If an application set the CURLOPT_COPYPOSTFIELDS
option for a handle, using the handle's duplicate could cause the
application to crash or disclose a portion of its memory. (CVE-2014-3707)

It was discovered that the libcurl library failed to properly handle URLs
with embedded end-of-line characters. An attacker able to make an
application using libcurl to access a specially crafted URL via an HTTP
proxy could use this flaw to inject additional headers to the request or
construct additional requests. (CVE-2014-8150)

It was discovered that libcurl implemented aspects of the NTLM and
Negotatiate authentication incorrectly. If an application uses libcurl
and the affected mechanisms in a specifc way, certain requests to a
previously NTLM-authenticated server could appears as sent by the wrong
authenticated user. Additionally, the initial set of credentials for HTTP
Negotiate-authenticated requests could be reused in subsequent requests,
although a different set of credentials was specified. (CVE-2015-3143,
CVE-2015-3148)

Red Hat would like to thank the cURL project for reporting these issues.

Bug fixes:

* An out-of-protocol fallback to SSL version 3.0 (SSLv3.0) was available
with libcurl. Attackers could abuse the fallback to force downgrade of the
SSL version. The fallback has been removed from libcurl. Users requiring
this functionality can explicitly enable SSLv3.0 through the libcurl API.
(BZ#1154059)

* A single upload transfer through the FILE protocol opened the destination
file twice. If the inotify kernel subsystem monitored the file, two events
were produced unnecessarily. The file is now opened only once per upload.
(BZ#883002)

* Utilities using libcurl for SCP/SFTP transfers could terminate
unexpectedly when the system was running in FIPS mode. (BZ#1008178)

* Using the "--retry" option with the curl utility could cause curl to
terminate unexpectedly with a segmentation fault. Now, adding "--retry" no
longer causes curl to crash. (BZ#1009455)

* The "curl --trace-time" command did not use the correct local time when
printing timestamps. Now, "curl --trace-time" works as expected.
(BZ#1120196)

* The valgrind utility could report dynamically allocated memory leaks on
curl exit. Now, curl performs a global shutdown of the NetScape Portable
Runtime (NSPR) library on exit, and valgrind no longer reports the memory
leaks. (BZ#1146528)

* Previously, libcurl returned an incorrect value of the
CURLINFO_HEADER_SIZE field when a proxy server appended its own headers to
the HTTP response. Now, the returned value is valid. (BZ#1161163)

Enhancements:

* The "--tlsv1.0", "--tlsv1.1", and "--tlsv1.2" options are available for
specifying the minor version of the TLS protocol to be negotiated by NSS.
The "--tlsv1" option now negotiates the highest version of the TLS protocol
supported by both the client and the server. (BZ#1012136)

* It is now possible to explicitly enable or disable the ECC and the new
AES cipher suites to be used for TLS. (BZ#1058767, BZ#1156422)

All curl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1254</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3148</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151254"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151272" severity="medium">
    <xccdf:title>RHSA-2015:1272: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way Linux kernel's Transparent Huge Pages (THP)
implementation handled non-huge page migration. A local, unprivileged user
could use this flaw to crash the kernel by migrating transparent hugepages.
(CVE-2014-3940, Moderate)

* A buffer overflow flaw was found in the way the Linux kernel's eCryptfs
implementation decoded encrypted file names. A local, unprivileged user
could use this flaw to crash the system or, potentially, escalate their
privileges on the system. (CVE-2014-9683, Moderate)

* A race condition flaw was found between the chown and execve system
calls. When changing the owner of a setuid user binary to root, the race
condition could momentarily make the binary setuid root. A local,
unprivileged user could potentially use this flaw to escalate their
privileges on the system. (CVE-2015-3339, Moderate)

* Multiple out-of-bounds write flaws were found in the way the Cherry
Cymotion keyboard driver, KYE/Genius device drivers, Logitech device
drivers, Monterey Genius KB29E keyboard driver, Petalynx Maxter remote
control driver, and Sunplus wireless desktop driver handled HID reports
with an invalid report descriptor size. An attacker with physical access to
the system could use either of these flaws to write data past an allocated
memory buffer. (CVE-2014-3184, Low)

* An information leak flaw was found in the way the Linux kernel's Advanced
Linux Sound Architecture (ALSA) implementation handled access of the user
control's state. A local, privileged user could use this flaw to leak
kernel memory to user space. (CVE-2014-4652, Low)

* It was found that the espfix functionality could be bypassed by
installing a 16-bit RW data segment into GDT instead of LDT (which espfix
checks), and using that segment on the stack. A local, unprivileged user
could potentially use this flaw to leak kernel stack addresses.
(CVE-2014-8133, Low)

* An information leak flaw was found in the Linux kernel's IEEE 802.11
wireless networking implementation. When software encryption was used, a
remote attacker could use this flaw to leak up to 8 bytes of plaintext.
(CVE-2014-8709, Low)

* It was found that the Linux kernel KVM subsystem's sysenter instruction
emulation was not sufficient. An unprivileged guest user could use this
flaw to escalate their privileges by tricking the hypervisor to emulate a
SYSENTER instruction in 16-bit mode, if the guest OS did not initialize the
SYSENTER model-specific registers (MSRs). Note: Certified guest operating
systems for Red Hat Enterprise Linux with KVM do initialize the SYSENTER
MSRs and are thus not vulnerable to this issue when running on a KVM
hypervisor. (CVE-2015-0239, Low)

Red Hat would like to thank Andy Lutomirski for reporting the CVE-2014-8133
issue, and Nadav Amit for reporting the CVE-2015-0239 issue.

This update fixes several hundred bugs and adds numerous enhancements.
Refer to the Red Hat Enterprise Linux 6.7 Release Notes for information on
the most significant of these changes, and the following Knowledgebase
article for further information:

https://access.redhat.com/articles/1466073

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3940</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8133</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8709</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9683</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0239</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3339</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151272"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151287" severity="medium">
    <xccdf:title>RHSA-2015:1287: freeradius security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.

A stack-based buffer overflow was found in the way the FreeRADIUS rlm_pap
module handled long password hashes. An attacker able to make radiusd
process a malformed password hash could cause the daemon to crash.
(CVE-2014-2015)

The freeradius packages have been upgraded to upstream version 2.2.6, which
provides a number of bug fixes and enhancements over the previous version,
including:

* The number of dictionaries have been updated.

* This update implements several Extensible Authentication Protocol
(EAP) improvements.

* A number of new expansions have been added, including: %{randstr:...},
%{hex:...}, %{sha1:...}, %{base64:...}, %{tobase64:...}, and
%{base64tohex:...}.

* Hexadecimal numbers (0x...) are now supported in %{expr:...} expansions.

* This update adds operator support to the rlm_python module.

* The Dynamic Host Configuration Protocol (DHCP) and DHCP relay code have
been finalized.

* This update adds the rlm_cache module to cache arbitrary attributes.

For a complete list of bug fixes and enhancements provided by this rebase,
see the freeradius changelog linked to in the References section.

(BZ#1078736)

This update also fixes the following bugs:

* The /var/log/radius/radutmp file was configured to rotate at one-month
intervals, even though this was unnecessary. This update removes
/var/log/radius/radutmp from the installed logrotate utility configuration
in the /etc/logrotate.d/radiusd file, and /var/log/radius/radutmp is no
longer rotated. (BZ#904578)

* The radiusd service could not write the output file created by the
raddebug utility. The raddebug utility now sets appropriate ownership to
the output file, allowing radiusd to write the output. (BZ#921563)

* After starting raddebug using the "raddebug -t 0" command, raddebug
exited immediately. A typo in the special case comparison has been fixed,
and raddebug now runs for 11.5 days in this situation. (BZ#921567)

* MS-CHAP authentication failed when the User-Name and MS-CHAP-User-Name
attributes used different encodings, even when the user provided correct
credentials. Now, MS-CHAP authentication properly handles mismatching
character encodings. Authentication with correct credentials no longer
fails in this situation. (BZ#1060319)

* Automatically generated default certificates used the SHA-1 algorithm
message digest, which is considered insecure. The default certificates now
use the more secure SHA-256 algorithm message digest. (BZ#1135439)

* During the Online Certificate Status Protocol (OCSP) validation, radiusd
terminated unexpectedly with a segmentation fault after attempting to
access the next update field that was not provided by the OCSP responder.
Now, radiusd does not crash in this situation and instead continues to
complete the OCSP validation. (BZ#1142669)

* Prior to this update, radiusd failed to work with some of the more recent
MikroTIK attributes, because the installed directory.mikrotik file did not
include them. This update adds MikroTIK attributes with IDs up to 22 to
dictionary.mikrotik, and radiusd now works as expected with these
attributes. (BZ#1173388)

Users of freeradius are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. After installing this
update, the radiusd service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-2015</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151287"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151320" severity="medium">
    <xccdf:title>RHSA-2015:1320: ppc64-diag security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The ppc64-diag packages provide diagnostic tools for Linux on the 64-bit
PowerPC platforms. The platform diagnostics write events reported by the
firmware to the service log, provide automated responses to urgent events,
and notify system administrators or connected service frameworks about the
reported events.

Multiple insecure temporary file use flaws were found in the way the
ppc64-diag utility created certain temporary files. A local attacker could
possibly use either of these flaws to perform a symbolic link attack and
overwrite arbitrary files with the privileges of the user running
ppc64-diag, or obtain sensitive information from the temporary files.
(CVE-2014-4038, CVE-2014-4039)

The ppc64-diag packages have been upgraded to upstream version 2.6.7, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1148142)

This update also fixes the following bugs:

* Previously, the "explain_syslog" and "syslog_to_svclog" commands failed
with a "No such file or directory" error message. With this update, the
ppc64-diag package specifies the location of the message_catalog directory
correctly, which prevents the described error from occurring. (BZ#1139655)

* Prior to this update, the /var/lock/subsys/rtas_errd file was incorrectly
labeled for SELinux as "system_u:object_r:var_lock_t:s0". This update
corrects the SELinux label to "system_u:object_r:rtas_errd_var_lock_t:s0".
(BZ#1131501)

Users of ppc64-diag are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1320</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4038</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4039</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151320"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151330" severity="medium">
    <xccdf:title>RHSA-2015:1330: python security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming language
often compared to Tcl, Perl, Scheme, or Java. Python includes modules,
classes, exceptions, very high level dynamic data types and dynamic typing.
Python supports interfaces to many system calls and libraries, as well as
to various windowing systems (X11, Motif, Tk, Mac and MFC).

It was discovered that the socket.recvfrom_into() function failed to check
the size of the supplied buffer. This could lead to a buffer overflow when
the function was called with an insufficiently sized buffer.
(CVE-2014-1912)

It was discovered that multiple Python standard library modules
implementing network protocols (such as httplib or smtplib) failed to
restrict the sizes of server responses. A malicious server could cause a
client using one of the affected modules to consume an excessive amount of
memory. (CVE-2013-1752)

It was discovered that the CGIHTTPServer module incorrectly handled URL
encoded paths. A remote attacker could use this flaw to execute scripts
outside of the cgi-bin directory, or disclose the source code of the
scripts in the cgi-bin directory. (CVE-2014-4650)

An integer overflow flaw was found in the way the buffer() function handled
its offset and size arguments. An attacker able to control these arguments
could use this flaw to disclose portions of the application memory or cause
it to crash. (CVE-2014-7185)

These updated python packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. For information on the most significant of these changes, users
are directed to the following article on the Red Hat Customer Portal:

https://access.redhat.com/articles/1495363

All python users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-1912</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4650</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7185</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151330"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151344" severity="medium">
    <xccdf:title>RHSA-2015:1344: autofs security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon. The 
daemon automatically mounts file systems when in use and unmounts them when 
they are not busy.

It was found that program-based automounter maps that used interpreted
languages such as Python would use standard environment variables to locate
and load modules of those languages. A local attacker could potentially use
this flaw to escalate their privileges on the system. (CVE-2014-8169)

Note: This issue has been fixed by adding the "AUTOFS_" prefix to the
affected environment variables so that they are not used to subvert the
system. A configuration option ("force_standard_program_map_env") to
override this prefix and to use the environment variables without the
prefix has been added. In addition, warnings have been added to the manual
page and to the installed configuration file. Now, by default the standard
variables of the program map are provided only with the prefix added to
its name.

Red Hat would like to thank the Georgia Institute of Technology for
reporting this issue.

Bug fixes:

* If the "ls *" command was executed before a valid mount, the autofs
program failed on further mount attempts inside the mount point, whether
the mount point was valid or not. While attempting to mount, the "ls *"
command of the root directory of an indirect mount was executed, which
led to an attempt to mount "*", causing it to be added to the negative
map entry cache. This bug has been fixed by checking for and not adding
"*" while updating the negative map entry cache. (BZ#1163957)

* The autofs program by design did not mount host map entries that were
duplicate exports in an NFS server export list. The duplicate entries in a
multi-mount map entry were recognized as a syntax error and autofs refused
to perform mounts when the duplicate entries occurred. Now, autofs has been
changed to continue mounting the last seen instance of the duplicate entry
rather than fail, and to report the problem in the log files to alert the
system administrator. (BZ#1124083)

* The autofs program did not recognize the yp map type in the master map.
This was caused by another change in the master map parser to fix a problem
with detecting the map format associated with mapping the type in the
master map. The change led to an incorrect length for the type comparison
of yp maps that resulted in a match operation failure. This bug has been
fixed by correcting the length which is used for the comparison.
(BZ#1153130)

* The autofs program did not update the export list of the Sun-format maps
of the network shares exported from an NFS server. This happened due to a
change of the Sun-format map parser leading to the hosts map update to stop
working on the map re-read operation. The bug has been now fixed by
selectively preventing this type of update only for the Sun-formatted maps.
The updates of the export list on the Sun-format maps are now visible and
refreshing of the export list is no longer supported for the Sun-formatted
hosts map. (BZ#1156387)

* Within changes made for adding of the Sun-format maps, an incorrect check 
was added that caused a segmentation fault in the Sun-format map parser in 
certain circumstances. This has been now fixed by analyzing the intent of 
the incorrect check and changing it in order to properly identify the 
conditions without causing a fault. (BZ#1175671)

* A bug in the autofs program map lookup module caused an incorrect map
format type comparison. The incorrect comparison affected the Sun-format
program maps where it led to the unused macro definitions. The bug in the
comparison has been fixed so that the macro definitions are not present for
the Sun-format program maps. (BZ#1201195)

Users of autofs are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1344</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151344"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151347" severity="medium">
    <xccdf:title>RHSA-2015:1347: pki-core security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Red Hat Certificate System is an enterprise software system designed to
manage enterprise public key infrastructure (PKI) deployments. PKI Core
contains fundamental packages required by Red Hat Certificate System, which
comprise the Certificate Authority (CA) subsystem.

Multiple cross-site scripting flaws were discovered in the Red Hat
Certificate System Agent and End Entity pages. An attacker could use these
flaws to perform a cross-site scripting (XSS) attack against victims using
the Certificate System's web interface. (CVE-2012-2662)

This update also fixes the following bugs:

* Previously, pki-core required the SSL version 3 (SSLv3) protocol ranges
to communicate with the 389-ds-base packages. However, recent changes to
389-ds-base disabled the default use of SSLv3 and enforced using protocol
ranges supported by secure protocols, such as the TLS protocol. As a
consequence, the CA failed to install during an Identity Management (IdM)
server installation. This update adds TLS-related parameters to the
server.xml file of the CA to fix this problem, and running the
ipa-server-install command now installs the CA as expected. (BZ#1171848)

* Previously, the ipa-server-install script failed when attempting to
configure a stand-alone CA on systems with OpenJDK version 1.8.0 installed.
The pki-core build and runtime dependencies have been modified to use
OpenJDK version 1.7.0 during the stand-alone CA configuration. As a result,
ipa-server-install no longer fails in this situation. (BZ#1212557)

* Creating a Red Hat Enterprise Linux 7 replica from a Red Hat Enterprise
Linux 6 replica running the CA service sometimes failed in IdM deployments
where the initial Red Hat Enterprise Linux 6 CA master had been removed.
This could cause problems in some situations, such as when migrating from
Red Hat Enterprise Linux 6 to Red Hat Enterprise Linux 7. The bug occurred
due to a problem in a previous version of IdM where the subsystem user,
created during the initial CA server installation, was removed together
with the initial master. This update adds the restore-subsystem-user.py
script that restores the subsystem user in the described situation, thus
enabling administrators to create a Red Hat Enterprise Linux 7 replica in
this scenario. (BZ#1225589)

* Several Java import statements specify wildcard arguments. However, due
to the use of wildcard arguments in the import statements of the source
code contained in the Red Hat Enterprise Linux 6 maintenance branch, a name
space collision created the potential for an incorrect class to be
utilized. As a consequence, the Token Processing System (TPS) rebuild test
failed with an error message. This update addresses the bug by supplying
the fully named class in all of the affected areas, and the TPS rebuild
test no longer fails. (BZ#1144188)

* Previously, pki-core failed to build with the rebased version of the
CMake build system during the TPS rebuild test. The pki-core build files
have been updated to comply with the rebased version of CMake. As a result,
pki-core builds successfully in the described scenario. (BZ#1144608)

Users of pki-core are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1347</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2662</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151347"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151378" severity="medium">
    <xccdf:title>RHSA-2015:1378: hivex security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Hivex is a library that can read and write Hive files, undocumented binary
files that Windows uses to store the Windows Registry on disk.

It was found that hivex attempted to read, and possibly write, beyond its
allocated buffer when reading a hive file with a very small size or with a
truncated or improperly formatted content. An attacker able to supply a
specially crafted hive file to an application using the hivex library could
possibly use this flaw to execute arbitrary code with the privileges of the
user running that application. (CVE-2014-9273)

Red Hat would like to thank Mahmoud Al-Qudsi of NeoSmart Technologies for
reporting this issue.

This update also fixes the following bug:

* The hivex(3) man page previously contained a typographical error. This
update fixes the typo. (BZ#1164693)

All hivex users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9273</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151378"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151385" severity="medium">
    <xccdf:title>RHSA-2015:1385: net-snmp security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

A denial of service flaw was found in the way snmptrapd handled certain
SNMP traps when started with the "-OQ" option. If an attacker sent an SNMP
trap containing a variable with a NULL type where an integer variable type
was expected, it would cause snmptrapd to crash. (CVE-2014-3565)

This update also fixes the following bugs:

* The HOST-RESOURCES-MIB::hrSystemProcesses object was not implemented
because parts of the HOST-RESOURCES-MIB module were rewritten in an earlier
version of net-snmp. Consequently, HOST-RESOURCES-MIB::hrSystemProcesses
did not provide information on the number of currently loaded or running
processes. With this update, HOST-RESOURCES-MIB::hrSystemProcesses has been
implemented, and the net-snmp daemon reports as expected. (BZ#1134335)

* The Net-SNMP agent daemon, snmpd, reloaded the system ARP table every 60
seconds. As a consequence, snmpd could cause a short CPU usage spike on
busy systems with a large APR table. With this update, snmpd does not
reload the full ARP table periodically, but monitors the table changes
using a netlink socket. (BZ#789500)

* Previously, snmpd used an invalid pointer to the current time when
periodically checking certain conditions specified by the "monitor" option
in the /etc/snmpd/snmpd.conf file. Consequently, snmpd terminated
unexpectedly on start with a segmentation fault if a certain entry with the
"monitor" option was used. Now, snmpd initializes the correct pointer
to the current time, and snmpd no longer crashes on start. (BZ#1050970)

* Previously, snmpd expected 8-bit network interface indices when
processing HOST-RESOURCES-MIB::hrDeviceTable. If an interface index of a
local network interface was larger than 30,000 items, snmpd could terminate
unexpectedly due to accessing invalid memory. Now, processing of all
network sizes is enabled, and snmpd no longer crashes in the described
situation. (BZ#1195547)

* The snmpdtrapd service incorrectly checked for errors when forwarding a
trap with a RequestID value of 0, and logged "Forward failed" even though
the trap was successfully forwarded. This update fixes snmptrapd checks and
the aforementioned message is now logged only when appropriate.
(BZ#1146948)

* Previously, snmpd ignored the value of the "storageUseNFS" option in the
/etc/snmpd/snmpd.conf file. As a consequence, NFS drivers were shown as
"Network Disks", even though "storageUseNFS" was set to "2" to report them
as "Fixed Disks" in HOST-RESOURCES-MIB::hrStorageTable. With this update,
snmpd takes the "storageUseNFS" option value into account, and "Fixed Disks"
NFS drives are reported correctly. (BZ#1125793)

* Previously, the Net-SNMP python binding used an incorrect size (8 bytes
instead of 4) for variables of IPADDRESS type. Consequently, applications
that were using Net-SNMP Python bindings could send malformed SNMP
messages. With this update, the bindings now use 4 bytes for variables with
IPADRESS type, and only valid SNMP messages are sent. (BZ#1100099)

* Previously, the snmpd service did not cut values in
HOST-RESOURCES-MIB::hrStorageTable to signed 32-bit integers, as required
by SNMP standards, and provided the values as unsigned integers. As a
consequence, the HOST-RESOURCES-MIB::hrStorageTable implementation did not
conform to RFC 2790. The values are now cut to 32-bit signed integers, and
snmpd is therefore standard compliant. (BZ#1104293)

Users of net-snmp are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1385</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3565</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151385"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151409" severity="medium">
    <xccdf:title>RHSA-2015:1409: sudo security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sudo packages contain the sudo utility which allows system 
administrators to provide certain users with the permission to execute 
privileged commands, which are used for system management purposes, without 
having to log in as root.

It was discovered that sudo did not perform any checks of the TZ
environment variable value. If sudo was configured to preserve the TZ
environment variable, a local user with privileges to execute commands via
sudo could possibly use this flaw to achieve system state changes not
permitted by the configured commands. (CVE-2014-9680)

Note: The default sudoers configuration in Red Hat Enterprise Linux removes
the TZ variable from the environment in which commands run by sudo are
executed.

This update also fixes the following bugs:

* Previously, the sudo utility child processes could sometimes become
unresponsive because they ignored the SIGPIPE signal. With this update,
SIGPIPE handler is properly restored in the function that reads passwords
from the user, and the child processes no longer ignore SIGPIPE. As a
result, sudo child processes do not hang in this situation. (BZ#1094548)

* Prior to this update, the order in which sudo rules were processed did
not honor the user-defined sudoOrder attribute. Consequently, sudo rules
were processed in an undefined order even when the user defined the order
in sudoOrder. The implementation of SSSD support in sudo has been modified
to sort the rules according to the sudoOrder value, and sudo rules are now
sorted in the order defined by the user in sudoOrder. (BZ#1138581)

* Previously, sudo became unresponsive after the user issued a command when
a sudoers source was mentioned multiple times in the /etc/nsswitch.conf
file. The problem occurred when nsswitch.conf contained, for example, the
"sudoers: files sss sss" entry. The sudoers source processing code has been
fixed to correctly handle multiple instances of the same sudoers source.
As a result, sudo no longer hangs when a sudoers source is mentioned
multiple times in /etc/nsswitch.conf. (BZ#1147498)

In addition, this update adds the following enhancement:

* The sudo utility now supports I/O logs compressed using the zlib library.
With this update, sudo can generate zlib compressed I/O logs and also
process zlib compressed I/O logs generated by other versions of sudo with
zlib support. (BZ#1106433)

All sudo users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1409</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9680</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151409"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151417" severity="medium">
    <xccdf:title>RHSA-2015:1417: mailman security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mailman is a program used to help manage e-mail discussion lists.

It was found that mailman did not sanitize the list name before passing it
to certain MTAs. A local attacker could use this flaw to execute arbitrary
code as the user running mailman. (CVE-2015-2775)

It was found that mailman stored private email messages in a world-readable
directory. A local user could use this flaw to read private mailing list
archives. (CVE-2002-0389)

This update also fixes the following bugs:

* Previously, it was impossible to configure Mailman in a way that
Domain-based Message Authentication, Reporting &amp; Conformance (DMARC) would
recognize Sender alignment for Domain Key Identified Mail (DKIM)
signatures. Consequently, Mailman list subscribers that belonged to a mail
server with a "reject" policy for DMARC, such as yahoo.com or AOL.com, were
unable to receive Mailman forwarded messages from senders residing in any
domain that provided DKIM signatures. With this update, domains with a
"reject" DMARC policy are recognized correctly, and Mailman list
administrators are able to configure the way these messages are handled.
As a result, after a proper configuration, subscribers now correctly
receive Mailman forwarded messages in this scenario. (BZ#1095359)

* Mailman used a console encoding when generating a subject for a "welcome
email" when new mailing lists were created by the "newlist" command.
Consequently, when the console encoding did not match the encoding used by
Mailman for that particular language, characters in the "welcome email"
could be displayed incorrectly. Mailman has been fixed to use the correct
encoding, and characters in the "welcome email" are now displayed properly.
(BZ#1056366)

* The "rmlist" command used a hardcoded path to list data based on the
VAR_PREFIX configuration variable. As a consequence, when the list was
created outside of VAR_PREFIX, it was impossible to remove it using the
"rmlist" command. With this update, the "rmlist" command uses the correct
LIST_DATA_DIR value instead of VAR_PREFIX, and it is now possible to remove
the list in described situation. (BZ#1008139)

* Due to an incompatibility between Python and Mailman in Red Hat
Enterprise Linux 6, when moderators were approving a moderated message to a
mailing list and checked the "Preserve messages for the site administrator"
checkbox, Mailman failed to approve the message and returned an error.
This incompatibility has been fixed, and Mailman now approves messages as
expected in this scenario. (BZ#765807)

* When Mailman was set to not archive a list but the archive was not set to
private, attachments sent to that list were placed in a public archive.
Consequently, users of Mailman web interface could list private attachments
because httpd configuration of public archive directory allows listing all
files in the archive directory. The httpd configuration of Mailman has been
fixed to not allow listing of private archive directory, and users of
Mailman web interface are no longer able to list private attachments.
(BZ#745409)

Users of mailman are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2002-0389</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2775</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151417"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151419" severity="low">
    <xccdf:title>RHSA-2015:1419: libxml2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in the way the libxml2 library parsed
certain XML files. An attacker could provide a specially crafted XML file
that, when parsed by an application using libxml2, could cause that
application to use an excessive amount of memory. (CVE-2015-1819)

This issue was discovered by Florian Weimer of Red Hat Product Security.

This update also fixes the following bug:

This update fixes an error that occurred when running a test case for the
serialization of HTML documents. (BZ#1004513)

Users of libxml2 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1819</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151419"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151424" severity="medium">
    <xccdf:title>RHSA-2015:1424: pacemaker security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Pacemaker Resource Manager is a collection of technologies working
together to provide data integrity and the ability to maintain application
availability in the event of a failure.

A flaw was found in the way pacemaker, a cluster resource manager,
evaluated added nodes in certain situations. A user with read-only access
could potentially assign any other existing roles to themselves and then
add privileges to other users as well. (CVE-2015-1867)

This update also fixes the following bugs:

* Due to a race condition, nodes that gracefully shut down occasionally had
difficulty rejoining the cluster. As a consequence, nodes could come online
and be shut down again immediately by the cluster. This bug has been fixed,
and the "shutdown" attribute is now cleared properly. (BZ#1198638)

* Prior to this update, the pacemaker utility caused an unexpected
termination of the attrd daemon after a system update to Red Hat Enterprise
Linux 6.6. The bug has been fixed so that attrd no longer crashes when
pacemaker starts. (BZ#1205292)

* Previously, the access control list (ACL) of the pacemaker utility
allowed a role assignment to the Cluster Information Base (CIB) with a
read-only permission. With this update, ACL is enforced and can no longer
be bypassed by the user without the write permission, thus fixing this bug.
(BZ#1207621)

* Prior to this update, the ClusterMon (crm_mon) utility did not trigger an
external agent script with the "-E" parameter to monitor the Cluster
Information Base (CIB) when the pacemaker utility was used. A patch has
been provided to fix this bug, and crm_mon now calls the agent script when
the "-E" parameter is used. (BZ#1208896)

Users of pacemaker are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1424</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1867</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151424"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151439" severity="low">
    <xccdf:title>RHSA-2015:1439: wpa_supplicant security and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wpa_supplicant package contains an 802.1X Supplicant with support for
WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication
methods. It implements key negotiation with a WPA Authenticator for client
stations and controls the roaming and IEEE 802.11 authentication and
association of the WLAN driver.

An integer underflow flaw, leading to a buffer over-read, was found in the
way wpa_supplicant handled WMM Action frames. A specially crafted frame
could possibly allow an attacker within Wi-Fi radio range to cause
wpa_supplicant to crash. (CVE-2015-4142)

This update includes the following enhancement:

* Prior to this update, wpa_supplicant did not provide a way to require the
host name to be listed in an X.509 certificate's Common Name or Subject
Alternative Name, and only allowed host name suffix or subject substring
checks. This update introduces a new configuration directive,
'domain_match', which adds a full host name check. (BZ#1186806)

All wpa_supplicant users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue and adds this
enhancement. After installing this update, the wpa_supplicant service will
be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1439</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4142</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151439"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151443" severity="high">
    <xccdf:title>RHSA-2015:1443: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND performed DNSSEC validation. An attacker
able to make BIND (functioning as a DNS resolver with DNSSEC validation
enabled) resolve a name in an attacker-controlled domain could cause named
to exit unexpectedly with an assertion failure. (CVE-2015-4620)

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1443</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4620</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151443"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151447" severity="low">
    <xccdf:title>RHSA-2015:1447: grep security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The grep utility searches through textual input for lines that contain a
match to a specified pattern and then prints the matching lines. The GNU
grep utilities include grep, egrep, and fgrep.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way grep parsed large lines of data. An attacker able to trick
a user into running grep on a specially crafted data file could use this
flaw to crash grep or, potentially, execute arbitrary code with the
privileges of the user running grep. (CVE-2012-5667)

A heap-based buffer overflow flaw was found in the way grep processed
certain pattern and text combinations. An attacker able to trick a user
into running grep on specially crafted input could use this flaw to crash
grep or, potentially, read from uninitialized memory. (CVE-2015-1345)

The grep packages have been upgraded to upstream version 2.20, which
provides a number of bug fixes and enhancements over the previous version.
Notably, the speed of various operations has been improved significantly.
Now, the recursive grep utility uses the fts function of the gnulib library
for directory traversal, so that it can handle much larger directories
without reporting the "File name too long" error message, and it can
operate faster when dealing with large directory hierarchies. (BZ#982215,
BZ#1064668, BZ#1126757, BZ#1167766, BZ#1171806)

This update also fixes the following bugs:

* Prior to this update, the \w and \W symbols were inconsistently matched
to the [:alnum:] character class. Consequently, regular expressions that used \w and \W in some cases had incorrect results. An upstream patch which fixes the matching problem has been applied, and \w is now matched to the [_[:alnum:]] character and \W to the [^_[:alnum:]] character consistently. (BZ#799863)

* Previously, the "--fixed-regexp" command-line option was not included in
the grep(1) manual page. Consequently, the manual page was inconsistent
with the built-in help of the grep utility. To fix this bug, grep(1) has
been updated to include a note informing the user that "--fixed-regexp" is
an obsolete option. Now, the built-in help and manual page are consistent
regarding the "--fixed-regexp" option. (BZ#1103270)

* Previously, the Perl Compatible Regular Expression (PCRE) library did not
work correctly when matching non-UTF-8 text in UTF-8 mode. Consequently, an
error message about invalid UTF-8 byte sequence characters was returned.
To fix this bug, patches from upstream have been applied to the PCRE
library and the grep utility. As a result, PCRE now skips non-UTF-8
characters as non-matching text without returning any error message.
(BZ#1193030)

All grep users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1447</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-5667</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1345</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151447"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151455" severity="high">
    <xccdf:title>RHSA-2015:1455: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-2724, CVE-2015-2725, CVE-2015-2731, CVE-2015-2734,
CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739,
CVE-2015-2740)

It was found that Thunderbird skipped key-pinning checks when handling an
error that could be overridden by the user (for example an expired
certificate error). This flaw allowed a user to override a pinned
certificate, which is an action the user should not be able to perform.
(CVE-2015-2741)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bob Clary, Christian Holler, Bobby Holley, Andrew
McCreight, Herre, Ronald Crane, and David Keeler as the original reporters
of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.8. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.8, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2724</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2725</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2735</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2736</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2738</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2739</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2740</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2741</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151457" severity="medium">
    <xccdf:title>RHSA-2015:1457: gnutls security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

It was found that GnuTLS did not check activation and expiration dates of
CA certificates. This could cause an application using GnuTLS to
incorrectly accept a certificate as valid when its issuing CA is already
expired. (CVE-2014-8155)

It was found that GnuTLS did not verify whether a hashing algorithm listed
in a signature matched the hashing algorithm listed in the certificate.
An attacker could create a certificate that used a different hashing
algorithm than it claimed, possibly causing GnuTLS to use an insecure,
disallowed hashing algorithm during certificate verification.
(CVE-2015-0282)

It was discovered that GnuTLS did not check if all sections of X.509
certificates indicate the same signature algorithm. This flaw, in
combination with a different flaw, could possibly lead to a bypass of the
certificate signature check. (CVE-2015-0294)

The CVE-2014-8155 issue was discovered by Marcel Kolaja of Red Hat.
The CVE-2015-0282 and CVE-2015-0294 issues were discovered by Nikos
Mavrogiannopoulos of the Red Hat Security Technologies Team.

This update also fixes the following bug:

* Previously, under certain circumstances, the certtool utility could
generate X.509 certificates which contained a negative modulus.
Consequently, such certificates could have interoperation problems with the
software using them. The bug has been fixed, and certtool no longer
generates X.509 certificates containing a negative modulus. (BZ#1036385)

Users of gnutls are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1457</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0282</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0294</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151457"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151458" severity="medium">
    <xccdf:title>RHSA-2015:1458: libreoffice security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibreOffice is an open source, community-developed office productivity
suite. It includes key desktop applications, such as a word processor, a
spreadsheet, a presentation manager, a formula editor, and a drawing
program. LibreOffice replaces OpenOffice and provides a similar but
enhanced and extended office suite.

A flaw was found in the way the LibreOffice HWP (Hangul Word Processor)
file filter processed certain HWP documents. An attacker able to trick a
user into opening a specially crafted HWP document could possibly use this
flaw to execute arbitrary code with the privileges of the user opening that
document. (CVE-2015-1774)

The libreoffice packages have been upgraded to upstream version 4.2.8.2,
which provides a number of bug fixes and enhancements over the previous
version, including:

* OpenXML interoperability has been improved.

* This update adds additional statistics functions to the Calc application,
thus improving interoperability with Microsoft Excel and its "Analysis
ToolPak" add-in.

* Various performance improvements have been implemented in Calc.

* This update adds new import filters for importing files from the Appple
Keynote and Abiword applications.

* The export filter for the MathML markup language has been improved.

* This update adds a new start screen that includes thumbnails of recently
opened documents.

* A visual clue is now displayed in the Slide Sorter window for slides with
transitions or animations.

* This update improves trend lines in charts.

* LibreOffice now supports BCP 47 language tags.

For a complete list of bug fixes and enhancements provided by this rebase,
see the libreoffice change log linked from the References section.
(BZ#1150048)

Users of libreoffice are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1458</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1774</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151458"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151459" severity="medium">
    <xccdf:title>RHSA-2015:1459: ntp security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with another referenced time source.

It was found that because NTP's access control was based on a source IP
address, an attacker could bypass source IP restrictions and send malicious
control and configuration packets by spoofing ::1 addresses.
(CVE-2014-9298)

A denial of service flaw was found in the way NTP hosts that were peering
with each other authenticated themselves before updating their internal
state variables. An attacker could send packets to one peer host, which
could cascade to other peers, and stop the synchronization process among
the reached peers. (CVE-2015-1799)

A flaw was found in the way the ntp-keygen utility generated MD5 symmetric
keys on big-endian systems. An attacker could possibly use this flaw to
guess generated MD5 keys, which could then be used to spoof an NTP client
or server. (CVE-2015-3405)

A stack-based buffer overflow was found in the way the NTP autokey protocol
was implemented. When an NTP client decrypted a secret received from an NTP
server, it could cause that client to crash. (CVE-2014-9297)

It was found that ntpd did not check whether a Message Authentication Code
(MAC) was present in a received packet when ntpd was configured to use
symmetric cryptographic keys. A man-in-the-middle attacker could use this
flaw to send crafted packets that would be accepted by a client or a peer
without the attacker knowing the symmetric key. (CVE-2015-1798)

The CVE-2015-1798 and CVE-2015-1799 issues were discovered by Miroslav
Lichvár of Red Hat.

Bug fixes:

* The ntpd daemon truncated symmetric keys specified in the key file to 20
bytes. As a consequence, it was impossible to configure NTP authentication
to work with peers that use longer keys. The maximum length of keys has now
been changed to 32 bytes. (BZ#1053551)

* The ntp-keygen utility used the exponent of 3 when generating RSA keys,
and generating RSA keys failed when FIPS mode was enabled. ntp-keygen has
been modified to use the exponent of 65537, and generating keys in FIPS
mode now works as expected. (BZ#1184421)

* The ntpd daemon included a root delay when calculating its root
dispersion. Consequently, the NTP server reported larger root dispersion
than it should have and clients could reject the source when its distance
reached the maximum synchronization distance (1.5 seconds by default).
Calculation of root dispersion has been fixed, the root dispersion is now
reported correctly, and clients no longer reject the server due to a large
synchronization distance. (BZ#1045376)

* The ntpd daemon dropped incoming NTP packets if their source port was
lower than 123 (the NTP port). Clients behind Network Address Translation
(NAT) were unable to synchronize with the server if their source port was
translated to ports below 123. With this update, ntpd no longer checks the
source port number. (BZ#1171630)

Enhancements:

* This update introduces configurable access of memory segments used for
Shared Memory Driver (SHM) reference clocks. Previously, only the first two
memory segments were created with owner-only access, allowing just two SHM
reference clocks to be used securely on a system. Now, the owner-only
access to SHM is configurable with the "mode" option, and it is therefore
possible to use more SHM reference clocks securely. (BZ#1122015)

* Support for nanosecond resolution has been added to the SHM reference
clock. Prior to this update, when a Precision Time Protocol (PTP) hardware
clock was used as a time source to synchronize the system clock (for
example, with the timemaster service from the linuxptp package), the
accuracy of the synchronization was limited due to the microsecond
resolution of the SHM protocol. The nanosecond extension in the SHM
protocol now enables sub-microsecond synchronization of the system clock.
(BZ#1117704)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1459</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9297</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3405</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151459"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151460" severity="medium">
    <xccdf:title>RHSA-2015:1460: wireshark security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Wireshark, previously known as Ethereal, is a network protocol analyzer,
which is used to capture and browse the traffic running on a computer
network.

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2014-8714, CVE-2014-8712, CVE-2014-8713,
CVE-2014-8711, CVE-2014-8710, CVE-2015-0562, CVE-2015-0564, CVE-2015-2189,
CVE-2015-2191)

This update also fixes the following bugs:

* Previously, the Wireshark tool did not support Advanced Encryption
Standard Galois/Counter Mode (AES-GCM) cryptographic algorithm. As a
consequence, AES-GCM was not decrypted. Support for AES-GCM has been added
to Wireshark, and AES-GCM is now correctly decrypted. (BZ#1095065)

* Previously, when installing the system using the kickstart method, a
dependency on the shadow-utils packages was missing from the wireshark
packages, which could cause the installation to fail with a "bad scriptlet"
error message. With this update, shadow-utils are listed as required in the
wireshark packages spec file, and kickstart installation no longer fails.
(BZ#1121275)

* Prior to this update, the Wireshark tool could not decode types of
elliptic curves in Datagram Transport Layer Security (DTLS) Client Hello.
Consequently, Wireshark incorrectly displayed elliptic curves types as
data. A patch has been applied to address this bug, and Wireshark now
decodes elliptic curves types properly. (BZ#1131203)

* Previously, a dependency on the gtk2 packages was missing from the
wireshark packages. As a consequence, the Wireshark tool failed to start
under certain circumstances due to an unresolved symbol,
"gtk_combo_box_text_new_with_entry", which was added in gtk version 2.24.
With this update, a dependency on gtk2 has been added, and Wireshark now
always starts as expected. (BZ#1160388)

In addition, this update adds the following enhancements:

* With this update, the Wireshark tool supports process substitution, which
feeds the output of a process (or processes) into the standard input of
another process using the "&lt;(command_list)" syntax. When using process
substitution with large files as input, Wireshark failed to decode such
input. (BZ#1104210)

* Wireshark has been enhanced to enable capturing packets with nanosecond
time stamp precision, which allows better analysis of recorded network
traffic. (BZ#1146578)

All wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. All running instances of Wireshark must be restarted for the
update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1460</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2191</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151460"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151462" severity="medium">
    <xccdf:title>RHSA-2015:1462: ipa security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Two cross-site scripting (XSS) flaws were found in jQuery, which impacted
the Identity Management web administrative interface, and could allow an
authenticated user to inject arbitrary HTML or web script into the
interface. (CVE-2010-5312, CVE-2012-6662)

Note: The IdM version provided by this update no longer uses jQuery.

Bug fixes:

* The ipa-server-install, ipa-replica-install, and ipa-client-install
utilities are not supported on machines running in FIPS-140 mode.
Previously, IdM did not warn users about this. Now, IdM does not allow
running the utilities in FIPS-140 mode, and displays an explanatory
message. (BZ#1131571)

* If an Active Directory (AD) server was specified or discovered
automatically when running the ipa-client-install utility, the utility
produced a traceback instead of informing the user that an IdM server is
expected in this situation. Now, ipa-client-install detects the AD server
and fails with an explanatory message. (BZ#1132261)

* When IdM servers were configured to require the TLS protocol version 1.1
(TLSv1.1) or later in the httpd server, the ipa utility failed. With this
update, running ipa works as expected with TLSv1.1 or later. (BZ#1154687)

* In certain high-load environments, the Kerberos authentication step of
the IdM client installer can fail. Previously, the entire client
installation failed in this situation. This update modifies
ipa-client-install to prefer the TCP protocol over the UDP protocol and to
retry the authentication attempt in case of failure. (BZ#1161722)

* If ipa-client-install updated or created the /etc/nsswitch.conf file, the
sudo utility could terminate unexpectedly with a segmentation fault. Now,
ipa-client-install puts a new line character at the end of nsswitch.conf if
it modifies the last line of the file, fixing this bug. (BZ#1185207)

* The ipa-client-automount utility failed with the "UNWILLING_TO_PERFORM"
LDAP error when the nsslapd-minssf Red Hat Directory Server configuration
parameter was set to "1". This update modifies ipa-client-automount to use
encrypted connection for LDAP searches by default, and the utility now
finishes successfully even with nsslapd-minssf specified. (BZ#1191040)

* If installing an IdM server failed after the Certificate Authority (CA)
installation, the "ipa-server-install --uninstall" command did not perform
a proper cleanup. After the user issued "ipa-server-install --uninstall"
and then attempted to install the server again, the installation failed.
Now, "ipa-server-install --uninstall" removes the CA-related files in the
described situation, and ipa-server-install no longer fails with the
mentioned error message. (BZ#1198160)

* Running ipa-client-install added the "sss" entry to the sudoers line in
nsswitch.conf even if "sss" was already configured and the entry was
present in the file. Duplicate "sss" then caused sudo to become
unresponsive. Now, ipa-client-install no longer adds "sss" if it is already
present in nsswitch.conf. (BZ#1198339)

* After running ipa-client-install, it was not possible to log in using SSH
under certain circumstances. Now, ipa-client-install no longer corrupts the
sshd_config file, and the sshd service can start as expected, and logging
in using SSH works in the described situation. (BZ#1201454)

* An incorrect definition of the dc attribute in the
/usr/share/ipa/05rfc2247.ldif file caused bogus error messages to be
returned during migration. The attribute has been fixed, but the bug
persists if the copy-schema-to-ca.py script was run on Red Hat Enterprise
Linux 6.6 prior to running it on Red Hat Enterprise Linux 6.7. To work
around this problem, manually copy /usr/share/ipa/schema/05rfc2247.ldif to
/etc/dirsrv/slapd-PKI-IPA/schema/ and restart IdM. (BZ#1220788)

All ipa users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1462</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-6662</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151462"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151471" severity="high">
    <xccdf:title>RHSA-2015:1471: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND performed DNSSEC validation. An attacker
able to make BIND (functioning as a DNS resolver with DNSSEC validation
enabled) resolve a name in an attacker-controlled domain could cause named
to exit unexpectedly with an assertion failure. (CVE-2015-4620)

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1471</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4620</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151471"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151482" severity="high">
    <xccdf:title>RHSA-2015:1482: libuser security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libuser library implements a standardized interface for manipulating
and administering user and group accounts. Sample applications that are
modeled after applications from the shadow password suite (shadow-utils)
are included in these packages.

Two flaws were found in the way the libuser library handled the /etc/passwd
file. A local attacker could use an application compiled against libuser
(for example, userhelper) to manipulate the /etc/passwd file, which could
result in a denial of service or possibly allow the attacker to escalate
their privileges to root. (CVE-2015-3245, CVE-2015-3246)

Red Hat would like to thank Qualys for reporting these issues.

All libuser users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1482</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3246</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151482"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151483" severity="high">
    <xccdf:title>RHSA-2015:1483: libuser security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libuser library implements a standardized interface for manipulating
and administering user and group accounts. Sample applications that are
modeled after applications from the shadow password suite (shadow-utils)
are included in these packages.

Two flaws were found in the way the libuser library handled the /etc/passwd
file. A local attacker could use an application compiled against libuser
(for example, userhelper) to manipulate the /etc/passwd file, which could
result in a denial of service or possibly allow the attacker to escalate
their privileges to root. (CVE-2015-3245, CVE-2015-3246)

Red Hat would like to thank Qualys for reporting these issues.

All libuser users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3246</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151483"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151507" severity="high">
    <xccdf:title>RHSA-2015:1507: qemu-kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

A heap buffer overflow flaw was found in the way QEMU's IDE subsystem
handled I/O buffer access while processing certain ATAPI commands.
A privileged guest user in a guest with the CDROM drive enabled could
potentially use this flaw to execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-5154)

An out-of-bounds memory access flaw, leading to memory corruption or
possibly an information leak, was found in QEMU's pit_ioport_read()
function. A privileged guest user in a QEMU guest, which had QEMU PIT
emulation enabled, could potentially, in rare cases, use this flaw to
execute arbitrary code on the host with the privileges of the hosting QEMU
process. (CVE-2015-3214)

Red Hat would like to thank Matt Tait of Google's Project Zero security
team for reporting the CVE-2015-3214 issue. The CVE-2015-5154 issue was
discovered by Kevin Wolf of Red Hat.

This update also fixes the following bug:

* Due to an incorrect implementation of portable memory barriers, the QEMU
emulator in some cases terminated unexpectedly when a virtual disk was
under heavy I/O load. This update fixes the implementation in order to
achieve correct synchronization between QEMU's threads. As a result, the
described crash no longer occurs. (BZ#1233643)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1507</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5154</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151507"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151510" severity="medium">
    <xccdf:title>RHSA-2015:1510: clutter security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Clutter is a library for creating fast, visually rich, graphical user
interfaces. Clutter is used for rendering the GNOME desktop environment.

A flaw was found in the way clutter processed certain mouse and touch
gestures. An attacker could use this flaw to bypass the screen lock.
(CVE-2015-3213)

All clutter users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using clutter must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1510</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3213</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151510"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151513" severity="high">
    <xccdf:title>RHSA-2015:1513: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled requests for TKEY DNS resource
records. A remote attacker could use this flaw to make named (functioning
as an authoritative DNS server or a DNS resolver) exit unexpectedly with an
assertion failure via a specially crafted DNS request packet.
(CVE-2015-5477)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Jonathan Foote as the original reporter.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5477</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151513"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151514" severity="high">
    <xccdf:title>RHSA-2015:1514: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled requests for TKEY DNS resource
records. A remote attacker could use this flaw to make named (functioning
as an authoritative DNS server or a DNS resolver) exit unexpectedly with an
assertion failure via a specially crafted DNS request packet.
(CVE-2015-5477)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Jonathan Foote as the original reporter.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1514</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5477</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151514"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151515" severity="high">
    <xccdf:title>RHSA-2015:1515: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handled requests for TKEY DNS resource
records. A remote attacker could use this flaw to make named (functioning
as an authoritative DNS server or a DNS resolver) exit unexpectedly with an
assertion failure via a specially crafted DNS request packet.
(CVE-2015-5477)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Jonathan Foote as the original reporter.

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1515</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5477</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151515"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151526" severity="high">
    <xccdf:title>RHSA-2015:1526: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple flaws were discovered in the 2D, CORBA, JMX, Libraries and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2015-4760,
CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733)

A flaw was found in the way the Libraries component of OpenJDK verified
Online Certificate Status Protocol (OCSP) responses. An OCSP response with
no nextUpdate date specified was incorrectly handled as having unlimited
validity, possibly causing a revoked X.509 certificate to be interpreted as
valid. (CVE-2015-4748)

It was discovered that the JCE component in OpenJDK failed to use constant
time comparisons in multiple cases. An attacker could possibly use these
flaws to disclose sensitive information by measuring the time used to
perform operations using these non-constant time comparisons.
(CVE-2015-2601)

A flaw was found in the RC4 encryption algorithm. When using certain keys
for RC4 encryption, an attacker could obtain portions of the plain text
from the cipher text without the knowledge of the encryption key.
(CVE-2015-2808)

Note: With this update, OpenJDK now disables RC4 TLS/SSL cipher suites by
default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla bug
1207101, linked to in the References section, for additional details about
this change.

A flaw was found in the way the TLS protocol composed the Diffie-Hellman
(DH) key exchange. A man-in-the-middle attacker could use this flaw to
force the use of weak 512 bit export-grade keys during the key exchange,
allowing them to decrypt all traffic. (CVE-2015-4000)

Note: This update forces the TLS/SSL client implementation in OpenJDK to
reject DH key sizes below 768 bits, which prevents sessions to be
downgraded to export-grade keys. Refer to Red Hat Bugzilla bug 1223211,
linked to in the References section, for additional details about this
change.

It was discovered that the JNDI component in OpenJDK did not handle DNS
resolutions correctly. An attacker able to trigger such DNS errors could
cause a Java application using JNDI to consume memory and CPU time, and
possibly block further DNS resolution. (CVE-2015-4749)

Multiple information leak flaws were found in the JMX and 2D components in
OpenJDK. An untrusted Java application or applet could use this flaw to
bypass certain Java sandbox restrictions. (CVE-2015-2621, CVE-2015-2632)

A flaw was found in the way the JSSE component in OpenJDK performed X.509
certificate identity verification when establishing a TLS/SSL connection to
a host identified by an IP address. In certain cases, the certificate was
accepted as valid if it was issued for a host name to which the IP address
resolves rather than for the IP address. (CVE-2015-2625)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2590</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2601</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2625</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2632</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2808</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4000</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4731</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4732</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4733</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4748</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4749</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4760</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151526"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151534" severity="medium">
    <xccdf:title>RHSA-2015:1534: kernel security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An integer overflow flaw was found in the way the Linux kernel's
netfilter connection tracking implementation loaded extensions. An attacker
on a local network could potentially send a sequence of specially crafted
packets that would initiate the loading of a large number of extensions,
causing the targeted system in that network to crash. (CVE-2014-9715,
Moderate)

* A stack-based buffer overflow flaw was found in the Linux kernel's early
load microcode functionality. On a system with UEFI Secure Boot enabled, a
local, privileged user could use this flaw to increase their privileges to
the kernel (ring0) level, bypassing intended restrictions in place.
(CVE-2015-2666, Moderate)

* It was found that the Linux kernel's ping socket implementation did not
properly handle socket unhashing during spurious disconnects, which could
lead to a use-after-free flaw. On x86-64 architecture systems, a local user
able to create ping sockets could use this flaw to crash the system.
On non-x86-64 architecture systems, a local user able to create ping
sockets could use this flaw to escalate their privileges on the system.
(CVE-2015-3636, Moderate)

* It was found that the Linux kernel's TCP/IP protocol suite implementation
for IPv6 allowed the Hop Limit value to be set to a smaller value than the
default one. An attacker on a local network could use this flaw to prevent
systems on that network from sending or receiving network packets.
(CVE-2015-2922, Low)

Red Hat would like to thank Nathan Hoad for reporting the CVE-2014-9715
issue.

This update also fixes several bugs. Refer to the following Knowledgebase
article for further information:

https://access.redhat.com/articles/1474193

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1534</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2666</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2922</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151534"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151565" severity="medium">
    <xccdf:title>RHSA-2015:1565: kernel-rt security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* An integer overflow flaw was found in the way the Linux kernel's
netfilter connection tracking implementation loaded extensions. An attacker
on a local network could potentially send a sequence of specially crafted
packets that would initiate the loading of a large number of extensions,
causing the targeted system in that network to crash. (CVE-2014-9715,
Moderate)

* A stack-based buffer overflow flaw was found in the Linux kernel's early
load microcode functionality. On a system with UEFI Secure Boot enabled, a
local, privileged user could use this flaw to increase their privileges to
the kernel (ring0) level, bypassing intended restrictions in place.
(CVE-2015-2666, Moderate)

* It was found that the Linux kernel's ping socket implementation did not
properly handle socket unhashing during spurious disconnects, which could
lead to a use-after-free flaw. On x86-64 architecture systems, a local user
able to create ping sockets could use this flaw to crash the system.
On non-x86-64 architecture systems, a local user able to create ping
sockets could use this flaw to escalate their privileges on the system.
(CVE-2015-3636, Moderate)

* It was found that the Linux kernel's TCP/IP protocol suite implementation
for IPv6 allowed the Hop Limit value to be set to a smaller value than the
default one. An attacker on a local network could use this flaw to prevent
systems on that network from sending or receiving network packets.
(CVE-2015-2922, Low)

Red Hat would like to thank Nathan Hoad for reporting the CVE-2014-9715
issue.

The kernel-rt packages have been upgraded to version 3.10.0-229.11.1, which
provides a number of bug fixes and enhancements over the previous version,
including:

* drbg: Add stdrng alias and increase priority
* seqiv / eseqiv / chainiv: Move IV seeding into init function
* ipv4: kABI fix for 0bbf87d backport
* ipv4: Convert ipv4.ip_local_port_range to be per netns
* libceph: tcp_nodelay support
* ipr: Increase default adapter init stage change timeout
* fix use-after-free bug in usb_hcd_unlink_urb()
* libceph: fix double __remove_osd() problem
* ext4: fix data corruption caused by unwritten and delayed extents
* sunrpc: Add missing support for RPC_CLNT_CREATE_NO_RETRANS_TIMEOUT
* nfs: Fixing lease renewal (Benjamin Coddington)
* control hard lockup detection default
* Fix print-once on enable
* watchdog: update watchdog_thresh properly and watchdog attributes
  atomically
* module: Call module notifier on failure after complete_formation()

(BZ#1234470)

This update also fixes the following bugs:

* The megasas driver used the smp_processor_id() function within a
preemptible context, which caused warning messages to be returned to the
console. The function has been changed to raw_smp_processor_id() so that a
lock is held while getting the processor ID. As a result, correct
operations are now allowed without any console warnings being produced.
(BZ#1235304)

* In the NFSv4 file system, non-standard usage of the
write_seqcount_{begin,end}() functions were used, which caused the realtime
code to try to sleep while locks were held. As a consequence, the
"scheduling while atomic" error messages were returned. The underlying
source code has been modified to use the __write_seqcount_{begin,end}()
functions that do not hold any locks, allowing correct execution of
realtime. (BZ#1235301)

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1565</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2666</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2922</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3636</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151565"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151581" severity="high">
    <xccdf:title>RHSA-2015:1581: firefox security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was discovered in Mozilla Firefox that could be used to violate the
same-origin policy and inject web script into a non-privileged part of the
built-in PDF file viewer (PDF.js). An attacker could create a malicious web
page that, when viewed by a victim, could steal arbitrary files (including
private SSH keys, the /etc/passwd file, and other potentially sensitive
files) from the system running Firefox. (CVE-2015-4495)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Cody Crews as the original reporter.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.1.1 ESR, which corrects this issue. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1581</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4495</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151581"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151586" severity="high">
    <xccdf:title>RHSA-2015:1586: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-4473, CVE-2015-4475, CVE-2015-4478, CVE-2015-4479,
CVE-2015-4480, CVE-2015-4493, CVE-2015-4484, CVE-2015-4491, CVE-2015-4485,
CVE-2015-4486, CVE-2015-4487, CVE-2015-4488, CVE-2015-4489, CVE-2015-4492)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christian Holler, Byron Campen, Aki
Helin, André Bargull, Massimiliano Tomassoli, laf.intel, Massimiliano
Tomassoli, Tyson Smith, Jukka Jylänki, Gustavo Grieco, Abhishek Arya,
Ronald Crane, and Looben Yang as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.2 ESR, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1586</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4486</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4487</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4489</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4491</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4492</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4493</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151586"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151623" severity="high">
    <xccdf:title>RHSA-2015:1623: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Two flaws were found in the way the Linux kernel's networking
implementation handled UDP packets with incorrect checksum values. A remote
attacker could potentially use these flaws to trigger an infinite loop in
the kernel, resulting in a denial of service on the system, or cause a
denial of service in applications using the edge triggered epoll
functionality. (CVE-2015-5364, CVE-2015-5366, Important)

This update also fixes the following bugs:

* When removing a directory, and a reference was held to that directory by
a reference to a negative child dentry, the directory dentry was previously
not killed. In addition, once the negative child dentry was killed, an
unlinked and unused dentry was present in the cache. As a consequence,
deadlock could be caused by forcing the dentry eviction while the file
system in question was frozen. With this update, all unused dentries are
unhashed and evicted just after a successful directory removal, which
avoids the deadlock, and the system no longer hangs in the aforementioned
scenario. (BZ#1243400)

* Due to the broken s_umount lock ordering, a race condition occurred when
an unlinked file was closed and the sync (or syncfs) utility was run at the
same time. As a consequence, deadlock occurred on a frozen file system
between sync and a process trying to unfreeze the file system. With this
update, sync (or syncfs) is skipped on a frozen file system, and deadlock
no longer occurs in the aforementioned situation. (BZ#1243404)

* Previously, in the scenario when a file was opened by file handle
(fhandle) with its dentry not present in dcache ("cold dcache") and then
making use of the unlink() and close() functions, the inode was not freed
upon the close() system call. As a consequence, the iput() final was
delayed indefinitely. A patch has been provided to fix this bug, and the
inode is now freed as expected. (BZ#1243406)

* Due to a corrupted Executable and Linkable Format (ELF) header in the
/proc/vmcore file, the kdump utility failed to provide any information.
The underlying source code has been patched, and kdump now provides
debuging information for kernel crashes as intended. (BZ#1245195)

* Previously, running the multipath request queue caused regressions in
cases where paths failed regularly under I/O load. This regression
manifested as I/O stalls that exceeded 300 seconds. This update reverts the
changes aimed to reduce running the multipath request queue resulting in
I/O completing in a timely manner. (BZ#1246095)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5366</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151623"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151627" severity="medium">
    <xccdf:title>RHSA-2015:1627: glibc security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

An invalid free flaw was found in glibc's getaddrinfo() function when used
with the AI_IDN flag. A remote attacker able to make an application call
this function could use this flaw to execute arbitrary code with the
permissions of the user running the application. Note that this flaw only
affected applications using glibc compiled with libidn support.
(CVE-2013-7424)

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1627</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7424</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151627"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151628" severity="medium">
    <xccdf:title>RHSA-2015:1628: mysql55-mysql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory pages, listed in the References section. (CVE-2014-6568,
CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0391, CVE-2015-0411,
CVE-2015-0432, CVE-2015-0433, CVE-2015-0441, CVE-2015-0499, CVE-2015-0501,
CVE-2015-0505, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573, CVE-2015-2582,
CVE-2015-2620, CVE-2015-2643, CVE-2015-2648, CVE-2015-4737, CVE-2015-4752,
CVE-2015-4757)

These updated packages upgrade MySQL to version 5.5.45. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1628</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-6568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0374</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0381</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0382</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0391</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0432</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4757</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4816</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4819</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4864</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4879</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151628"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151633" severity="medium">
    <xccdf:title>RHSA-2015:1633: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.
The mod_dav_svn module is used with the Apache HTTP Server to allow access
to Subversion repositories via HTTP.

An assertion failure flaw was found in the way the SVN server processed
certain requests with dynamically evaluated revision numbers. A remote
attacker could use this flaw to cause the SVN server (both svnserve and
httpd with the mod_dav_svn module) to crash. (CVE-2015-0248)

It was found that the mod_dav_svn module did not properly validate the
svn:author property of certain requests. An attacker able to create new
revisions could use this flaw to spoof the svn:author property.
(CVE-2015-0251)

It was found that when an SVN server (both svnserve and httpd with the
mod_dav_svn module) searched the history of a file or a directory, it would
disclose its location in the repository if that file or directory was not
readable (for example, if it had been moved). (CVE-2015-3187)

Red Hat would like to thank the Apache Software Foundation for reporting
these issues. Upstream acknowledges Evgeny Kotkov of VisualSVN as the
original reporter of CVE-2015-0248 and CVE-2015-0251, and C. Michael Pilato
of CollabNet as the original reporter of CVE-2015-3187.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1633</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0251</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3187</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151633"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151634" severity="medium">
    <xccdf:title>RHSA-2015:1634: sqlite security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SQLite is a C library that implements an SQL database engine. A large
subset of SQL92 is supported. A complete database is stored in a single
disk file. The API is designed for convenience and ease of use.
Applications that link against SQLite can enjoy the power and flexibility
of an SQL database without the administrative hassles of supporting a
separate database server.

It was found that SQLite's sqlite3VXPrintf() function did not properly
handle precision and width values during floating-point conversions.
A local attacker could submit a specially crafted SELECT statement that
would crash the SQLite process, or have other unspecified impacts.
(CVE-2015-3416)

All sqlite users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1634</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3416</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151634"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151635" severity="medium">
    <xccdf:title>RHSA-2015:1635: sqlite security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>SQLite is a C library that implements an SQL database engine. A large
subset of SQL92 is supported. A complete database is stored in a single
disk file. The API is designed for convenience and ease of use.
Applications that link against SQLite can enjoy the power and flexibility
of an SQL database without the administrative hassles of supporting a
separate database server.

A flaw was found in the way SQLite handled dequoting of collation-sequence
names. A local attacker could submit a specially crafted COLLATE statement
that would crash the SQLite process, or have other unspecified impacts.
(CVE-2015-3414)

It was found that SQLite's sqlite3VdbeExec() function did not properly
implement comparison operators. A local attacker could submit a specially
crafted CHECK statement that would crash the SQLite process, or have other
unspecified impacts. (CVE-2015-3415)

It was found that SQLite's sqlite3VXPrintf() function did not properly
handle precision and width values during floating-point conversions.
A local attacker could submit a specially crafted SELECT statement that
would crash the SQLite process, or have other unspecified impacts.
(CVE-2015-3416)

All sqlite users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1635</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3414</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3415</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3416</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151635"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151636" severity="medium">
    <xccdf:title>RHSA-2015:1636: net-snmp security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

It was discovered that the snmp_pdu_parse() function could leave
incompletely parsed varBind variables in the list of variables. A remote,
unauthenticated attacker could use this flaw to crash snmpd or,
potentially, execute arbitrary code on the system with the privileges of
the user running snmpd. (CVE-2015-5621)

Red Hat would like to thank Qinghao Tang of QIHU 360 company, China for
reporting this issue.

All net-snmp users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1636</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5621</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2018-1000116</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151636"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151640" severity="medium">
    <xccdf:title>RHSA-2015:1640: pam security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs to handle authentication.

It was discovered that the _unix_run_helper_binary() function of PAM's
unix_pam module could write to a blocking pipe, possibly causing the
function to become unresponsive. An attacker able to supply large passwords
to the unix_pam module could use this flaw to enumerate valid user
accounts, or cause a denial of service on the system. (CVE-2015-3238)

Red Hat would like to thank Sebastien Macke of Trustwave SpiderLabs for
reporting this issue.

All pam users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1640</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3238</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151640"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151664" severity="medium">
    <xccdf:title>RHSA-2015:1664: nss security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
cross-platform development of security-enabled client and server
applications.

It was found that NSS permitted skipping of the ServerKeyExchange packet
during a handshake involving ECDHE (Elliptic Curve Diffie-Hellman key
Exchange). A remote attacker could use this flaw to bypass the
forward-secrecy of a TLS/SSL connection. (CVE-2015-2721)

A flaw was found in the way NSS verified certain ECDSA (Elliptic Curve
Digital Signature Algorithm) signatures. Under certain conditions, an
attacker could use this flaw to conduct signature forgery attacks.
(CVE-2015-2730)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Karthikeyan Bhargavan as the original reporter of
CVE-2015-2721, and Watson Ladd as the original reporter of CVE-2015-2730.

The nss packages have been upgraded to upstream version 3.19.1, which
provides a number of bug fixes and enhancements over the previous version.

All nss users are advised to upgrade to these updated packages, which
correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1664</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2721</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2730</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151664"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151665" severity="medium">
    <xccdf:title>RHSA-2015:1665: mariadb security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>MariaDB is a multi-user, multi-threaded SQL database server that is binary
compatible with MySQL.

It was found that the MySQL client library permitted but did not require a
client to use SSL/TLS when establishing a secure connection to a MySQL
server using the "--ssl" option. A man-in-the-middle attacker could use
this flaw to strip the SSL/TLS protection from a connection between a
client and a server. (CVE-2015-3152)

This update fixes several vulnerabilities in the MariaDB database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2015-0501,
CVE-2015-2568, CVE-2015-0499, CVE-2015-2571, CVE-2015-0433, CVE-2015-0441,
CVE-2015-0505, CVE-2015-2573, CVE-2015-2582, CVE-2015-2620, CVE-2015-2643,
CVE-2015-2648, CVE-2015-4737, CVE-2015-4752, CVE-2015-4757)

These updated packages upgrade MariaDB to version 5.5.44. Refer to the
MariaDB Release Notes listed in the References section for a complete list
of changes.

All MariaDB users should upgrade to these updated packages, which correct
these issues. After installing this update, the MariaDB server daemon
(mysqld) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1665</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0433</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0441</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2568</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2571</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2573</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2582</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2620</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2643</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2648</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4757</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4864</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151665"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151667" severity="medium">
    <xccdf:title>RHSA-2015:1667: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

Multiple flaws were found in the way httpd parsed HTTP requests and
responses using chunked transfer encoding. A remote attacker could use
these flaws to create a specially crafted request, which httpd would decode
differently from an HTTP proxy software in front of it, possibly leading to
HTTP request smuggling attacks. (CVE-2015-3183)

It was discovered that in httpd 2.4, the internal API function
ap_some_auth_required() could incorrectly indicate that a request was
authenticated even when no authentication was used. An httpd module using
this API function could consequently allow access that should have been
denied. (CVE-2015-3185)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1667</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3183</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3185</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151667"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151668" severity="medium">
    <xccdf:title>RHSA-2015:1668: httpd security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

Multiple flaws were found in the way httpd parsed HTTP requests and
responses using chunked transfer encoding. A remote attacker could use
these flaws to create a specially crafted request, which httpd would decode
differently from an HTTP proxy software in front of it, possibly leading to
HTTP request smuggling attacks. (CVE-2015-3183)

All httpd users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the httpd service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1668</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151668"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151682" severity="high">
    <xccdf:title>RHSA-2015:1682: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-4473, CVE-2015-4491, CVE-2015-4487, CVE-2015-4488, 
CVE-2015-4489)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message because JavaScript is disabled by default for mail
messages. However, they could be exploited in other ways in Thunderbird
(for example, by viewing the full remote content of an RSS feed).

Red Hat would like to thank the Mozilla project for reporting these
issues. Upstream acknowledges Gary Kwong, Christian Holler, Byron Campen, 
Gustavo Grieco, and Ronald Crane as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 38.2. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 38.2, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1682</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4487</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4488</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4489</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4491</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151682"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151693" severity="high">
    <xccdf:title>RHSA-2015:1693: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the processing of malformed web content. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2015-4497)

A flaw was found in the way Firefox handled installation of add-ons.
An attacker could use this flaw to bypass the add-on installation prompt,
and trick the user inso installing an add-on from a malicious source.
(CVE-2015-4498)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jean-Max Reymond, Ucha Gobejishvili, and Bas Venis as
the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.2.1 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1693</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4498</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151693"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151694" severity="medium">
    <xccdf:title>RHSA-2015:1694: gdk-pixbuf2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>gdk-pixbuf is an image loading library that can be extended by loadable
modules for new image formats. It is used by toolkits such as GTK+ or
clutter.

An integer overflow, leading to a heap-based buffer overflow, was found in
the way gdk-pixbuf, an image loading library for GNOME, scaled certain
bitmap format images. An attacker could use a specially crafted BMP image
file that, when processed by an application compiled against the gdk-pixbuf
library, would cause that application to crash or execute arbitrary code
with the permissions of the user running the application. (CVE-2015-4491)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Gustavo Grieco as the original reporter.

All gdk-pixbuf2 users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4491</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151694"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151695" severity="high">
    <xccdf:title>RHSA-2015:1695: jakarta-taglibs-standard security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>jakarta-taglibs-standard is the Java Standard Tag Library (JSTL).
This library is used in conjunction with Tomcat and Java Server Pages
(JSP).

It was found that the Java Standard Tag Library (JSTL) allowed the
processing of untrusted XML documents to utilize external entity
references, which could access resources on the host system and,
potentially, allowing arbitrary code execution. (CVE-2015-0254)

Note: jakarta-taglibs-standard users may need to take additional steps
after applying this update. Detailed instructions on the additional steps
can be found here:

https://access.redhat.com/solutions/1584363

All jakarta-taglibs-standard users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0254</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151695"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151699" severity="medium">
    <xccdf:title>RHSA-2015:1699: nss-softokn security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support 
cross-platform development of security-enabled client and server
applications.

A flaw was found in the way NSS verified certain ECDSA (Elliptic Curve
Digital Signature Algorithm) signatures. Under certain conditions, an
attacker could use this flaw to conduct signature forgery attacks.
(CVE-2015-2730)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Watson Ladd as the original reporter of this issue.

All nss-softokn users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1699</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2730</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151699"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151700" severity="high">
    <xccdf:title>RHSA-2015:1700: pcs security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pcs packages provide a command-line configuration system for the
Pacemaker and Corosync utilities.

A command injection flaw was found in the pcsd web UI. An attacker able to
trick a victim that was logged in to the pcsd web UI into visiting a
specially crafted URL could use this flaw to execute arbitrary code with
root privileges on the server hosting the web UI. (CVE-2015-5190)

A race condition was found in the way the pcsd web UI backend performed
authorization of user requests. An attacker could use this flaw to send a
request that would be evaluated as originating from a different user,
potentially allowing the attacker to perform actions with permissions of a
more privileged user. (CVE-2015-5189)

These issues were discovered by Tomáš Jelínek of Red Hat.

All pcs users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5190</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151700"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151705" severity="high">
    <xccdf:title>RHSA-2015:1705: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND parsed certain malformed
DNSSEC keys. A remote attacker could use this flaw to send a specially
crafted DNS query (for example, a query requiring a response from a zone
containing a deliberately malformed key) that would cause named functioning
as a validating resolver to crash. (CVE-2015-5722)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Hanno Böck as the original reporter.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1705</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5722</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151705"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151706" severity="high">
    <xccdf:title>RHSA-2015:1706: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND parsed certain malformed
DNSSEC keys. A remote attacker could use this flaw to send a specially
crafted DNS query (for example, a query requiring a response from a zone
containing a deliberately malformed key) that would cause named functioning
as a validating resolver to crash. (CVE-2015-5722)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Hanno Böck as the original reporter.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1706</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5722</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151706"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151707" severity="high">
    <xccdf:title>RHSA-2015:1707: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND parsed certain malformed
DNSSEC keys. A remote attacker could use this flaw to send a specially
crafted DNS query (for example, a query requiring a response from a zone
containing a deliberately malformed key) that would cause named functioning
as a validating resolver to crash. (CVE-2015-5722)

Red Hat would like to thank ISC for reporting this issue. Upstream
acknowledges Hanno Böck as the original reporter.

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5722</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151707"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151708" severity="high">
    <xccdf:title>RHSA-2015:1708: libXfont security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libXfont package provides the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

An integer overflow flaw was found in the way libXfont processed certain
Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could
use this flaw to crash the X.Org server or, potentially, execute arbitrary
code with the privileges of the X.Org server. (CVE-2015-1802)

An integer truncation flaw was discovered in the way libXfont processed
certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local
user could use this flaw to crash the X.Org server or, potentially, execute
arbitrary code with the privileges of the X.Org server. (CVE-2015-1804)

A NULL pointer dereference flaw was discovered in the way libXfont
processed certain Glyph Bitmap Distribution Format (BDF) fonts.
A malicious, local user could use this flaw to crash the X.Org server.
(CVE-2015-1803)

All libXfont users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1708</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1802</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1804</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151708"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151714" severity="high">
    <xccdf:title>RHSA-2015:1714: spice security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A race condition flaw, leading to a heap-based memory corruption, was found
in spice's worker_update_monitors_config() function, which runs under the
QEMU-KVM context on the host. A user in a guest could leverage this flaw to
crash the host QEMU-KVM process or, possibly, execute arbitrary code with
the privileges of the host QEMU-KVM process. (CVE-2015-3247)

This issue was discovered by Frediano Ziglio of Red Hat.

All spice users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3247</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151714"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151715" severity="high">
    <xccdf:title>RHSA-2015:1715: spice-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A race condition flaw, leading to a heap-based memory corruption, was found
in spice's worker_update_monitors_config() function, which runs under the
QEMU-KVM context on the host. A user in a guest could leverage this flaw to
crash the host QEMU-KVM process or, possibly, execute arbitrary code with
the privileges of the host QEMU-KVM process. (CVE-2015-3247)

This issue was discovered by Frediano Ziglio of Red Hat.

All spice-server users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1715</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3247</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151715"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151741" severity="high">
    <xccdf:title>RHSA-2015:1741: haproxy security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>HAProxy provides high availability, load balancing, and proxying for TCP
and HTTP-based applications.

An implementation error related to the memory management of request and
responses was found within HAProxy's buffer_slow_realign() function.
An unauthenticated remote attacker could possibly use this flaw to leak
certain memory buffer contents from a past request or session.
(CVE-2015-3281)

All haproxy users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1741</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3281</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151741"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151742" severity="medium">
    <xccdf:title>RHSA-2015:1742: subversion security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access
to Subversion repositories via HTTP.

An assertion failure flaw was found in the way the SVN server processed
certain requests with dynamically evaluated revision numbers. A remote
attacker could use this flaw to cause the SVN server (both svnserve and
httpd with the mod_dav_svn module) to crash. (CVE-2015-0248)

It was found that the mod_authz_svn module did not properly restrict
anonymous access to Subversion repositories under certain configurations
when used with Apache httpd 2.4.x. This could allow a user to anonymously
access files in a Subversion repository, which should only be accessible to
authenticated users. (CVE-2015-3184)

It was found that the mod_dav_svn module did not properly validate the
svn:author property of certain requests. An attacker able to create new
revisions could use this flaw to spoof the svn:author property.
(CVE-2015-0251)

It was found that when an SVN server (both svnserve and httpd with the
mod_dav_svn module) searched the history of a file or a directory, it would
disclose its location in the repository if that file or directory was not
readable (for example, if it had been moved). (CVE-2015-3187)

Red Hat would like to thank the Apache Software Foundation for reporting
these issues. Upstream acknowledges Evgeny Kotkov of VisualSVN as the
original reporter of CVE-2015-0248 and CVE-2015-0251, and C. Michael
Pilato of CollabNet as the original reporter of CVE-2015-3184 and
CVE-2015-3187 flaws.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1742</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0251</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3187</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151742"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151778" severity="high">
    <xccdf:title>RHSA-2015:1778: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the kernel's implementation of the Berkeley Packet
Filter (BPF). A local attacker could craft BPF code to crash the system by
creating a situation in which the JIT compiler would fail to correctly
optimize the JIT image on the last pass. This would lead to the CPU
executing instructions that were not part of the JIT code. (CVE-2015-4700,
Important)

* Two flaws were found in the way the Linux kernel's networking
implementation handled UDP packets with incorrect checksum values. A remote
attacker could potentially use these flaws to trigger an infinite loop in
the kernel, resulting in a denial of service on the system, or cause a
denial of service in applications using the edge triggered epoll
functionality. (CVE-2015-5364, CVE-2015-5366, Important)

* A flaw was found in the way the Linux kernel's ext4 file system handled
the "page size &gt; block size" condition when the fallocate zero range
functionality was used. A local attacker could use this flaw to crash the
system. (CVE-2015-0275, Moderate)

* It was found that the Linux kernel's keyring implementation would leak
memory when adding a key to a keyring via the add_key() function. A local
attacker could use this flaw to exhaust all available memory on the system.
(CVE-2015-1333, Moderate)

* A race condition flaw was found in the way the Linux kernel's SCTP
implementation handled Address Configuration lists when performing Address
Configuration Change (ASCONF). A local attacker could use this flaw to
crash the system via a race condition triggered by setting certain ASCONF
options on a socket. (CVE-2015-3212, Moderate)

* An information leak flaw was found in the way the Linux kernel's Virtual
Dynamic Shared Object (vDSO) implementation performed address
randomization. A local, unprivileged user could use this flaw to leak
kernel memory addresses to user-space. (CVE-2014-9585, Low)

Red Hat would like to thank Daniel Borkmann for reporting CVE-2015-4700,
and Canonical for reporting the CVE-2015-1333 issue. The CVE-2015-0275
issue was discovered by Xiong Zhou of Red Hat, and the CVE-2015-3212 issue
was discovered by Ji Jianwen of Red Hat Engineering.

This update also fixes several bugs. Refer to the following Knowledgebase
article for further information:

https://access.redhat.com/articles/1614563

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1778</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1333</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5366</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151778"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151788" severity="high">
    <xccdf:title>RHSA-2015:1788: kernel-rt security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the kernel's implementation of the Berkeley Packet
Filter (BPF). A local attacker could craft BPF code to crash the system by
creating a situation in which the JIT compiler would fail to correctly
optimize the JIT image on the last pass. This would lead to the CPU
executing instructions that were not part of the JIT code. (CVE-2015-4700,
Important)

* Two flaws were found in the way the Linux kernel's networking
implementation handled UDP packets with incorrect checksum values. A remote
attacker could potentially use these flaws to trigger an infinite loop in
the kernel, resulting in a denial of service on the system, or cause a
denial of service in applications using the edge triggered epoll
functionality. (CVE-2015-5364, CVE-2015-5366, Important)

* A flaw was found in the way the Linux kernel's ext4 file system handled
the "page size &gt; block size" condition when the fallocate zero range
functionality was used. A local attacker could use this flaw to crash the
system. (CVE-2015-0275, Moderate)

* It was found that the Linux kernel's keyring implementation would leak
memory when adding a key to a keyring via the add_key() function. A local
attacker could use this flaw to exhaust all available memory on the system.
(CVE-2015-1333, Moderate)

* A race condition flaw was found in the way the Linux kernel's SCTP
implementation handled Address Configuration lists when performing Address
Configuration Change (ASCONF). A local attacker could use this flaw to
crash the system via a race condition triggered by setting certain ASCONF
options on a socket. (CVE-2015-3212, Moderate)

* An information leak flaw was found in the way the Linux kernel's Virtual
Dynamic Shared Object (vDSO) implementation performed address
randomization. A local, unprivileged user could use this flaw to leak
kernel memory addresses to user-space. (CVE-2014-9585, Low)

Red Hat would like to thank Daniel Borkmann for reporting CVE-2015-4700,
and Canonical for reporting the CVE-2015-1333 issue. The CVE-2015-0275
issue was discovered by Xiong Zhou of Red Hat, and the CVE-2015-3212 issue
was discovered by Ji Jianwen of Red Hat Engineering.

The kernel-rt packages have been upgraded to version 3.10.0-229.13.1, which
provides a number of bug fixes and enhancements over the previous version,
including:

* Fix regression in scsi_send_eh_cmnd()

* boot hangs at "Console: switching to colour dummy device 80x25"

* Update tcp stack to 3.17 kernel

* Missing some code from patch "(...) Fix VGA switcheroo problem related to
hotplug"

* ksoftirqd high CPU usage due to stray tasklet from ioatdma driver

* During Live Partition Mobility (LPM) testing, RHEL 7.1 LPARs will crash
in kmem_cache_alloc

(BZ#1253809)

This update also fixes the following bug:

* The hwlat_detector.ko module samples the clock and records any intervals
between reads that exceed a specified threshold. However, the module
previously tracked the maximum interval seen for the "inner" interval but
did not record when the "outer" interval was greater. A patch has been
applied to fix this bug, and hwlat_detector.ko now correctly records if the
outer interval is the maximal interval encountered during the run.
(BZ#1252365)

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1788</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9585</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0275</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1333</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4700</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5366</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151788"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151793" severity="medium">
    <xccdf:title>RHSA-2015:1793: qemu-kvm security fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An information leak flaw was found in the way QEMU's RTL8139 emulation
implementation processed network packets under RTL8139 controller's C+ mode
of operation. An unprivileged guest user could use this flaw to read up to
65 KB of uninitialized QEMU heap memory. (CVE-2015-5165)

Red Hat would like to thank the Xen project for reporting this issue.
Upstream acknowledges Donghai Zhu of Alibaba as the original reporter.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1793</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5165</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151793"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151833" severity="medium">
    <xccdf:title>RHSA-2015:1833: qemu-kvm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An information leak flaw was found in the way QEMU's RTL8139 emulation
implementation processed network packets under RTL8139 controller's C+ mode
of operation. An unprivileged guest user could use this flaw to read up to
65 KB of uninitialized QEMU heap memory. (CVE-2015-5165)

Red Hat would like to thank the Xen project for reporting this issue.
Upstream acknowledges Donghai Zhu of Alibaba as the original reporter.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1833</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5165</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151833"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151834" severity="high">
    <xccdf:title>RHSA-2015:1834: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-4500, CVE-2015-4506, CVE-2015-4509, CVE-2015-4511,
CVE-2015-4517, CVE-2015-4521, CVE-2015-4522, CVE-2015-7174, CVE-2015-7175,
CVE-2015-7176, CVE-2015-7177, CVE-2015-7180)

Two information leak flaws were found in the processing of malformed web
content. A web page containing malicious content could cause Firefox to
disclose sensitive information or, in certain cases, crash. (CVE-2015-4519,
CVE-2015-4520)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Andrew Osmond, Olli Pettay, Andrew Sutherland,
Christian Holler, David Major, Andrew McCreight, Cameron McCormack, Khalil
Zhani, Atte Kettunen, Ronald Crane, Mario Gomes, and Ehsan Akhgari as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.3.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1834</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4506</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4511</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7180</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151834"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151840" severity="high">
    <xccdf:title>RHSA-2015:1840: openldap security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols used
to access and maintain distributed directory information services over an
IP network. The openldap package contains configuration files, libraries,
and documentation for OpenLDAP.

A flaw was found in the way the OpenLDAP server daemon (slapd) parsed
certain Basic Encoding Rules (BER) data. A remote attacker could use this
flaw to crash slapd via a specially crafted packet. (CVE-2015-6908)

All openldap users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6908</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151840"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151852" severity="high">
    <xccdf:title>RHSA-2015:1852: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-4500, CVE-2015-4509, CVE-2015-4517, CVE-2015-4521,
CVE-2015-4522, CVE-2015-7174, CVE-2015-7175, CVE-2015-7176, CVE-2015-7177,
CVE-2015-7180)

Two information leak flaws were found in the processing of malformed web
content. A web page containing malicious content could cause Thunderbird to
disclose sensitive information or, in certain cases, crash. (CVE-2015-4519,
CVE-2015-4520)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message because JavaScript is disabled by default for mail
messages. However, they could be exploited in other ways in Thunderbird
(for example, by viewing the full remote content of an RSS feed).

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Andrew Osmond, Olli Pettay, Andrew Sutherland,
Christian Holler, David Major, Andrew McCreight, Cameron McCormack, Ronald
Crane, Mario Gomes, and Ehsan Akhgari as the original reporters of these
issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 38.3.0 You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 38.3.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1852</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4509</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4517</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4520</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7174</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7177</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7180</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151852"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151889" severity="high">
    <xccdf:title>RHSA-2015:1889: spice-server security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A heap-based buffer overflow flaw was found in the way SPICE handled
certain guest QXL commands related to surface creation. A user in a guest
could use this flaw to read and write arbitrary memory locations on the
host. (CVE-2015-5261)

A heap-based buffer overflow flaw was found in the way spice handled
certain QXL commands related to the "surface_id" parameter. A user in a
guest could use this flaw to crash the host QEMU-KVM process or, possibly,
execute arbitrary code with the privileges of the host QEMU-KVM process.
(CVE-2015-5260)

These issues were discovered by Frediano Ziglio of Red Hat.

All spice-server users are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1889</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5261</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151889"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151890" severity="high">
    <xccdf:title>RHSA-2015:1890: spice security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol for virtual environments. SPICE users can access a
virtualized desktop or server from the local system or any system with
network access to the server. SPICE is used in Red Hat Enterprise Linux for
viewing virtualized guests running on the Kernel-based Virtual Machine
(KVM) hypervisor or on Red Hat Enterprise Virtualization Hypervisors.

A heap-based buffer overflow flaw was found in the way SPICE handled
certain guest QXL commands related to surface creation. A user in a guest
could use this flaw to read and write arbitrary memory locations on the
host. (CVE-2015-5261)

A heap-based buffer overflow flaw was found in the way spice handled
certain QXL commands related to the "surface_id" parameter. A user in a
guest could use this flaw to crash the host QEMU-KVM process or, possibly,
execute arbitrary code with the privileges of the host QEMU-KVM process.
(CVE-2015-5260)

These issues were discovered by Frediano Ziglio of Red Hat.

All spice users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1890</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5260</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5261</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151890"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151917" severity="high">
    <xccdf:title>RHSA-2015:1917: libwmf security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.

It was discovered that libwmf did not correctly process certain WMF
(Windows Metafiles) with embedded BMP images. By tricking a victim into
opening a specially crafted WMF file in an application using libwmf, a
remote attacker could possibly use this flaw to execute arbitrary code with
the privileges of the user running the application. (CVE-2015-0848,
CVE-2015-4588)

It was discovered that libwmf did not properly process certain WMF files.
By tricking a victim into opening a specially crafted WMF file in an
application using libwmf, a remote attacker could possibly exploit this
flaw to cause a crash or execute arbitrary code with the privileges of the
user running the application. (CVE-2015-4696)

It was discovered that libwmf did not properly process certain WMF files.
By tricking a victim into opening a specially crafted WMF file in an
application using libwmf, a remote attacker could possibly exploit this
flaw to cause a crash. (CVE-2015-4695)

All users of libwmf are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, all applications using libwmf must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1917</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0848</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4588</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4695</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4696</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151917"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151919" severity="high">
    <xccdf:title>RHSA-2015:1919: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

Multiple flaws were discovered in the CORBA, Libraries, RMI, Serialization,
and 2D components in OpenJDK. An untrusted Java application or applet could
use these flaws to completely bypass Java sandbox restrictions.
(CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860,
CVE-2015-4805, CVE-2015-4844)

Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2015-4803, CVE-2015-4893, CVE-2015-4911)

A flaw was found in the way the Libraries component in OpenJDK handled
certificate revocation lists (CRL). In certain cases, CRL checking code
could fail to report a revoked certificate, causing the application to
accept it as trusted. (CVE-2015-4868)

It was discovered that the Security component in OpenJDK failed to properly
check if a certificate satisfied all defined constraints. In certain cases,
this could cause a Java application to accept an X.509 certificate which
does not meet requirements of the defined policy. (CVE-2015-4872)

Multiple flaws were found in the Libraries, 2D, CORBA, JAXP, JGSS, and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4806,
CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1919</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151919"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151920" severity="high">
    <xccdf:title>RHSA-2015:1920: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the CORBA, Libraries, RMI, Serialization,
and 2D components in OpenJDK. An untrusted Java application or applet could
use these flaws to completely bypass Java sandbox restrictions.
(CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860,
CVE-2015-4805, CVE-2015-4844)

Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2015-4803, CVE-2015-4893, CVE-2015-4911)

It was discovered that the Security component in OpenJDK failed to properly
check if a certificate satisfied all defined constraints. In certain cases,
this could cause a Java application to accept an X.509 certificate which
does not meet requirements of the defined policy. (CVE-2015-4872)

Multiple flaws were found in the Libraries, 2D, CORBA, JAXP, JGSS, and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4806,
CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1920</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151920"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151921" severity="high">
    <xccdf:title>RHSA-2015:1921: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the CORBA, Libraries, RMI, Serialization,
and 2D components in OpenJDK. An untrusted Java application or applet could
use these flaws to completely bypass Java sandbox restrictions.
(CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860,
CVE-2015-4805, CVE-2015-4844)

Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2015-4803, CVE-2015-4893, CVE-2015-4911)

It was discovered that the Security component in OpenJDK failed to properly
check if a certificate satisfied all defined constraints. In certain cases,
this could cause a Java application to accept an X.509 certificate which
does not meet requirements of the defined policy. (CVE-2015-4872)

Multiple flaws were found in the Libraries, 2D, CORBA, JAXP, JGSS, and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4806,
CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1921</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151921"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151924" severity="high">
    <xccdf:title>RHSA-2015:1924: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

A heap buffer overflow flaw was found in the way QEMU's NE2000 NIC
emulation implementation handled certain packets received over the network.
A privileged user inside a guest could use this flaw to crash the QEMU
instance (denial of service) or potentially execute arbitrary code on
the host. (CVE-2015-5279)

Red Hat would like to thank Qinghao Tang of QIHU 360 Inc. for reporting
this issue.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1924</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5279</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151924"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151925" severity="high">
    <xccdf:title>RHSA-2015:1925: kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems.

A heap buffer overflow flaw was found in the way QEMU's NE2000 NIC
emulation implementation handled certain packets received over the network.
A privileged user inside a guest could use this flaw to crash the QEMU
instance (denial of service) or potentially execute arbitrary code on
the host. (CVE-2015-5279)

Red Hat would like to thank Qinghao Tang of QIHU 360 Inc. for reporting
this issue.

All kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Note: The procedure in
the Solution section must be performed before this update will take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5279</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151925"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151926" severity="high">
    <xccdf:title>RHSA-2015:1926: java-1.8.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 8 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806, CVE-2015-4810,
CVE-2015-4835, CVE-2015-4840, CVE-2015-4842, CVE-2015-4843, CVE-2015-4844,
CVE-2015-4860, CVE-2015-4868, CVE-2015-4872, CVE-2015-4881, CVE-2015-4882,
CVE-2015-4883, CVE-2015-4893, CVE-2015-4901, CVE-2015-4902, CVE-2015-4903,
CVE-2015-4906, CVE-2015-4908, CVE-2015-4911, CVE-2015-4916)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.8.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 8 Update 65 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1926</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4868</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4901</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4906</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4908</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4916</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151926"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151927" severity="high">
    <xccdf:title>RHSA-2015:1927: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806, CVE-2015-4810,
CVE-2015-4835, CVE-2015-4840, CVE-2015-4842, CVE-2015-4843, CVE-2015-4844,
CVE-2015-4860, CVE-2015-4871, CVE-2015-4872, CVE-2015-4881, CVE-2015-4882,
CVE-2015-4883, CVE-2015-4893, CVE-2015-4902, CVE-2015-4903, CVE-2015-4911)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 91 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1927</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4840</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151927"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151928" severity="high">
    <xccdf:title>RHSA-2015:1928: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806, CVE-2015-4835,
CVE-2015-4842, CVE-2015-4843, CVE-2015-4844, CVE-2015-4860, CVE-2015-4872,
CVE-2015-4881, CVE-2015-4882, CVE-2015-4883, CVE-2015-4893, CVE-2015-4902,
CVE-2015-4903, CVE-2015-4911)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 105 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1928</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4902</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151928"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151930" severity="high">
    <xccdf:title>RHSA-2015:1930: ntp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

It was discovered that ntpd as a client did not correctly check timestamps
in Kiss-of-Death packets. A remote attacker could use this flaw to send a
crafted Kiss-of-Death packet to an ntpd client that would increase the
client's polling interval value, and effectively disable synchronization
with the server. (CVE-2015-7704)

It was found that ntpd did not correctly implement the threshold limitation
for the '-g' option, which is used to set the time without any
restrictions. A man-in-the-middle attacker able to intercept NTP traffic
between a connecting client and an NTP server could use this flaw to force
that client to make multiple steps larger than the panic threshold,
effectively changing the time to an arbitrary value. (CVE-2015-5300)

Red Hat would like to thank Aanchal Malhotra, Isaac E. Cohen, and Sharon
Goldberg of Boston University for reporting these issues.

All ntp users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1930</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5300</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151930"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151943" severity="medium">
    <xccdf:title>RHSA-2015:1943: qemu-kvm security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

It was found that the QEMU's websocket frame decoder processed incoming
frames without limiting resources used to process the header and the
payload. An attacker able to access a guest's VNC console could use this
flaw to trigger a denial of service on the host by exhausting all available
memory and CPU. (CVE-2015-1779)

This issue was discovered by Daniel P. Berrange of Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1943</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1779</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151943"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151977" severity="medium">
    <xccdf:title>RHSA-2015:1977: kernel-rt security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's VFS subsystem handled file
system locks. A local, unprivileged user could use this flaw to trigger a
deadlock in the kernel, causing a denial of service on the system.
(CVE-2014-8559, Moderate)

* A buffer overflow flaw was found in the way the Linux kernel's virtio-net
subsystem handled certain fraglists when the GRO (Generic Receive Offload)
functionality was enabled in a bridged network configuration. An attacker
on the local network could potentially use this flaw to crash the system,
or, although unlikely, elevate their privileges on the system.
(CVE-2015-5156, Moderate)

The CVE-2015-5156 issue was discovered by Jason Wang of Red Hat.

The kernel-rt packages have been upgraded to version 3.10.0-229.20.1, which
provides a number of bug fixes and enhancements over the previous version,
including:

* Unexpected completion is detected on Intel Ethernet x540

* Divide by zero error in intel_pstate_timer_func() [ inline s64
div_s64_rem() ]

* NFS Recover from stateid-type error on SETATTR

* pNFS RHEL 7.1 Data Server connection remains after umount due to lseg
refcount leak

* Race during NFS v4.0 recovery and standard IO.

* Fix ip6t_SYNPROXY for namespaces and connection delay

* synproxy window size and sequence number behaviour causes long connection
delay

* Crash in kmem_cache_alloc() during disk stress testing (using ipr)

* xfs: sync/backport to upstream v4.1

* iscsi_session recovery_tmo revert back to default when a path becomes
active

* read from MD raid1 can fail if read from resync target fails

* backport scsi-mq

* unable to handle kernel paging request at 0000000000237037 [zswap]

(BZ#1266915) 

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add this enhancement. The system must be rebooted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1977</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8559</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5156</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151977"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151978" severity="medium">
    <xccdf:title>RHSA-2015:1978: kernel security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's VFS subsystem handled file
system locks. A local, unprivileged user could use this flaw to trigger a
deadlock in the kernel, causing a denial of service on the system.
(CVE-2014-8559, Moderate)

* A buffer overflow flaw was found in the way the Linux kernel's virtio-net
subsystem handled certain fraglists when the GRO (Generic Receive Offload)
functionality was enabled in a bridged network configuration. An attacker
on the local network could potentially use this flaw to crash the system,
or, although unlikely, elevate their privileges on the system.
(CVE-2015-5156, Moderate)

The CVE-2015-5156 issue was discovered by Jason Wang of Red Hat.

This update also fixes several bugs and adds one enhancement. Refer to the
following Knowledgebase article for further information:

https://access.redhat.com/articles/2039563

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1978</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8559</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5156</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151978"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151979" severity="medium">
    <xccdf:title>RHSA-2015:1979: libreswan security and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Libreswan is an implementation of IPsec &amp; IKE for Linux. IPsec is the
Internet Protocol Security and uses strong cryptography to provide both
authentication and encryption services. These services allow you to build
secure tunnels through untrusted networks such as virtual private network
(VPN).

A flaw was discovered in the way Libreswan's IKE daemon processed IKE KE
payloads. A remote attacker could send specially crafted IKE payload with a
KE payload of g^x=0 that, when processed, would lead to a denial of service
(daemon crash). (CVE-2015-3240)

This issue was discovered by Paul Wouters of Red Hat.

Note: Please note that when upgrading from an earlier version of Libreswan,
the existing CA certificates in the /etc/ipsec.d/cacerts/ directory and the
existing certificate revocation list (CRL) files from the
/etc/ipsec.d/crls/ directory are automatically imported into the NSS
database. Once completed, these directories are no longer used by
Libreswan. To install new CA certificates or new CRLS, the certutil and
crlutil commands must be used to import these directly into the Network
Security Services (NSS) database.

This update also adds the following enhancements:

* This update adds support for RFC 7383 IKEv2 Fragmentation, RFC 7619 Auth
Null and ID Null, INVALID_KE renegotiation, CRL and OCSP support via NSS,
AES_CTR and AES_GCM support for IKEv2, CAVS testing for FIPS compliance.

In addition, this update enforces FIPS algorithms restrictions in FIPS
mode, and runs Composite Application Validation System (CAVS) testing for
FIPS compliance during package build. A new Cryptographic Algorithm
Validation Program (CAVP) binary can be used to re-run the CAVS tests at
any time. Regardless of FIPS mode, the pluto daemon runs RFC test vectors
for various algorithms.

Furthermore, compiling on all architectures now enables the "-Werror" GCC
option, which enhances the security by making all warnings into errors.
(BZ#1263346)

* This update also fixes several memory leaks and introduces a sub-second
packet retransmit option. (BZ#1268773)

* This update improves migration support from Openswan to Libreswan.
Specifically, all Openswan options that can take a time value without a
suffix are now supported, and several new keywords for use in the
/etc/ipsec.conf file have been introduced. See the relevant man pages for
details. (BZ#1268775)

* With this update, loopback support via the "loopback=" option has been
deprecated. (BZ#1270673)

All Libreswan users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1979</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3240</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151979"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151980" severity="high">
    <xccdf:title>RHSA-2015:1980: nss and nspr security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A use-after-poison flaw and a heap-based buffer overflow flaw were found in
the way NSS parsed certain ASN.1 structures. An attacker could use these
flaws to cause NSS to crash or execute arbitrary code with the permissions
of the user running an application compiled against the NSS library.
(CVE-2015-7181, CVE-2015-7182)

A heap-based buffer overflow was found in NSPR. An attacker could use this
flaw to cause NSPR to crash or execute arbitrary code with the permissions
of the user running an application compiled against the NSPR library.
(CVE-2015-7183)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Tyson Smith, David Keeler and Ryan Sleevi as the
original reporter.

All nss and nspr users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1980</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151980"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151981" severity="high">
    <xccdf:title>RHSA-2015:1981: nss, nss-util, and nspr security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support 
cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities. 

A use-after-poison flaw and a heap-based buffer overflow flaw were found in
the way NSS parsed certain ASN.1 structures. An attacker could use these
flaws to cause NSS to crash or execute arbitrary code with the permissions
of the user running an application compiled against the NSS library.
(CVE-2015-7181, CVE-2015-7182)

A heap-based buffer overflow was found in NSPR. An attacker could use this
flaw to cause NSPR to crash or execute arbitrary code with the permissions
of the user running an application compiled against the NSPR library.
(CVE-2015-7183)

Note: Applications using NSPR's PL_ARENA_ALLOCATE, PR_ARENA_ALLOCATE,
PL_ARENA_GROW, or PR_ARENA_GROW macros need to be rebuild against the fixed
nspr packages to completely resolve the CVE-2015-7183 issue. This erratum
includes nss and nss-utils packages rebuilt against the fixed nspr version.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Tyson Smith, David Keeler and Ryan Sleevi as the
original reporter.

All nss, nss-util and nspr users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7181</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7183</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151981"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20151982" severity="high">
    <xccdf:title>RHSA-2015:1982: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-4513, CVE-2015-7189, CVE-2015-7194, CVE-2015-7196,
CVE-2015-7198, CVE-2015-7197)

A same-origin policy bypass flaw was found in the way Firefox handled
certain cross-origin resource sharing (CORS) requests. A web page
containing malicious content could cause Firefox to disclose sensitive
information. (CVE-2015-7193)

A same-origin policy bypass flaw was found in the way Firefox handled URLs
containing IP addresses with white-space characters. This could lead to
cross-site scripting attacks. (CVE-2015-7188)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Major, Jesse Ruderman, Tyson
Smith, Boris Zbarsky, Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff
Walden, and Gary Kwong, Michał Bentkowski, Looben Yang, Shinto K Anto,
Gustavo Grieco, Vytautas Staraitis, Ronald Crane, and Ehsan Akhgari as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:1982</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7196</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20151982"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152019" severity="low">
    <xccdf:title>RHSA-2015:2019: sssd security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) service provides a set of
daemons to manage access to remote directories and authentication
mechanisms. It also provides the Name Service Switch (NSS) and the
Pluggable Authentication Modules (PAM) interfaces toward the system, and a
pluggable back-end system to connect to multiple different account sources.

It was found that SSSD's Privilege Attribute Certificate (PAC) responder
plug-in would leak a small amount of memory on each authentication request.
A remote attacker could potentially use this flaw to exhaust all available
memory on the system by making repeated requests to a Kerberized daemon
application configured to authenticate using the PAC responder plug-in.
(CVE-2015-5292)

This update also fixes the following bugs:

* Previously, SSSD did not correctly handle sudo rules that applied to
groups with names containing special characters, such as the "(" opening
parenthesis sign. Consequently, SSSD skipped such sudo rules. The internal
sysdb search has been modified to escape special characters when searching
for objects to which sudo rules apply. As a result, SSSD applies the
described sudo rules as expected. (BZ#1258398)

* Prior to this update, SSSD did not correctly handle group names
containing special Lightweight Directory Access Protocol (LDAP) characters,
such as the "(" or ")" parenthesis signs. When a group name contained one
or more such characters, the internal cache cleanup operation failed with
an I/O error. With this update, LDAP special characters in the
Distinguished Name (DN) of a cache entry are escaped before the cleanup
operation starts. As a result, the cleanup operation completes successfully
in the described situation. (BZ#1264098)

* Applications performing Kerberos authentication previously increased the
memory footprint of the Kerberos plug-in that parses the Privilege
Attribute Certificate (PAC) information. The plug-in has been updated to
free the memory it allocates, thus fixing this bug. (BZ#1268783)

* Previously, when malformed POSIX attributes were defined in an Active
Directory (AD) LDAP server, SSSD unexpectedly switched to offline mode.
This update relaxes certain checks for AD POSIX attribute validity. As a
result, SSSD now works as expected even when malformed POSIX attributes are
present in AD and no longer enters offline mode in the described situation.
(BZ#1268784)

All sssd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the sssd service will be restarted automatically. Additionally, all
running applications using the PAC responder plug-in must be restarted for
the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2019</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5292</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152019"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152065" severity="high">
    <xccdf:title>RHSA-2015:2065: xen security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A heap buffer overflow flaw was found in the way QEMU's NE2000 NIC
emulation implementation handled certain packets received over the network.
A privileged user inside a guest could use this flaw to crash the QEMU
instance (denial of service) or potentially execute arbitrary code on the
host. (CVE-2015-5279)

Red Hat would like to thank Qinghao Tang of QIHU 360 Inc. for reporting
this issue.

All xen users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, all running fully-virtualized guests must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5279</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152065"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152078" severity="medium">
    <xccdf:title>RHSA-2015:2078: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A memory leak error was discovered in the crypt() function of the pgCrypto
extension. An authenticated attacker could possibly use this flaw to
disclose a limited amount of the server memory. (CVE-2015-5288)

A stack overflow flaw was discovered in the way the PostgreSQL core server
processed certain JSON or JSONB input. An authenticated attacker could
possibly use this flaw to crash the server backend by sending specially
crafted JSON or JSONB input. (CVE-2015-5289)

Please note that SSL renegotiation is now disabled by default. For more
information, please refer to PostgreSQL's 2015-10-08 Security Update
Release notes, linked to in the References section.

All PostgreSQL users are advised to upgrade to these updated packages,
which correct these issues. If the postgresql service is running, it will
be automatically restarted after installing this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2078</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5289</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152078"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152079" severity="medium">
    <xccdf:title>RHSA-2015:2079: binutils security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The binutils packages provide a set of binary utilities.

Multiple buffer overflow flaws were found in the libbdf library used by
various binutils utilities. If a user were tricked into processing a
specially crafted file with an application using the libbdf library, it
could cause the application to crash or, potentially, execute arbitrary
code. (CVE-2014-8485, CVE-2014-8501, CVE-2014-8502, CVE-2014-8503,
CVE-2014-8504, CVE-2014-8738)

An integer overflow flaw was found in the libbdf library used by various
binutils utilities. If a user were tricked into processing a specially
crafted file with an application using the libbdf library, it could cause
the application to crash. (CVE-2014-8484)

A directory traversal flaw was found in the strip and objcopy utilities.
A specially crafted file could cause strip or objdump to overwrite an
arbitrary file writable by the user running either of these utilities.
(CVE-2014-8737)

This update fixes the following bugs:

* Binary files started by the system loader could lack the Relocation
Read-Only (RELRO) protection even though it was explicitly requested when
the application was built. This bug has been fixed on multiple
architectures. Applications and all dependent object files, archives, and
libraries built with an alpha or beta version of binutils should be rebuilt
to correct this defect. (BZ#1200138, BZ#1175624)

* The ld linker on 64-bit PowerPC now correctly checks the output format
when asked to produce a binary in another format than PowerPC. (BZ#1226864)

* An important variable that holds the symbol table for the binary being
debugged has been made persistent, and the objdump utility on 64-bit
PowerPC is now able to access the needed information without reading an
invalid memory region. (BZ#1172766)

* Undesirable runtime relocations described in RHBA-2015:0974. (BZ#872148)

The update adds these enhancements:

* New hardware instructions of the IBM z Systems z13 are now supported by
assembler, disassembler, and linker, as well as Single Instruction,
Multiple Data (SIMD) instructions. (BZ#1182153)

* Expressions of the form: "FUNC@localentry" to refer to the local entry
point for the FUNC function (if defined) are now supported by the PowerPC
assembler. These are required by the ELFv2 ABI on the little-endian variant
of IBM Power Systems. (BZ#1194164)

All binutils users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2079</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8484</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8485</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8501</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8502</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8503</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8737</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8738</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152079"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152081" severity="medium">
    <xccdf:title>RHSA-2015:2081: postgresql security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PostgreSQL is an advanced object-relational database management system
(DBMS).

A memory leak error was discovered in the crypt() function of the pgCrypto
extension. An authenticated attacker could possibly use this flaw to
disclose a limited amount of the server memory. (CVE-2015-5288)

All PostgreSQL users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. If the postgresql
service is running, it will be automatically restarted after installing
this update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2081</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5288</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152081"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152086" severity="high">
    <xccdf:title>RHSA-2015:2086: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple flaws were discovered in the CORBA, Libraries, RMI, Serialization,
and 2D components in OpenJDK. An untrusted Java application or applet could
use these flaws to completely bypass Java sandbox restrictions.
(CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860,
CVE-2015-4805, CVE-2015-4844)

Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2015-4803, CVE-2015-4893, CVE-2015-4911)

It was discovered that the Security component in OpenJDK failed to properly
check if a certificate satisfied all defined constraints. In certain cases,
this could cause a Java application to accept an X.509 certificate which
does not meet requirements of the defined policy. (CVE-2015-4872)

Multiple flaws were found in the Libraries, CORBA, JAXP, JGSS, and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4806,
CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903)

Red Hat would like to thank Andrea Palazzo of Truel IT for reporting the
CVE-2015-4806 issue.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2086</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4734</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4803</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4805</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4806</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4835</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4843</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4844</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4860</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4881</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4882</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4883</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4893</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4903</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4911</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152086"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152088" severity="medium">
    <xccdf:title>RHSA-2015:2088: openssh security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the way OpenSSH handled PAM authentication when using
privilege separation. An attacker with valid credentials on the system and
able to fully compromise a non-privileged pre-authentication process using
a different flaw could use this flaw to authenticate as other users.
(CVE-2015-6563)

A use-after-free flaw was found in OpenSSH. An attacker able to fully
compromise a non-privileged pre-authentication process using a different
flaw could possibly cause sshd to crash or execute arbitrary code with
root privileges. (CVE-2015-6564)

It was discovered that the OpenSSH sshd daemon did not check the list of
keyboard-interactive authentication methods for duplicates. A remote
attacker could use this flaw to bypass the MaxAuthTries limit, making it
easier to perform password guessing attacks. (CVE-2015-5600)

It was found that the OpenSSH ssh-agent, a program to hold private keys
used for public key authentication, was vulnerable to password guessing
attacks. An attacker able to connect to the agent could use this flaw to
conduct a brute-force attack to unlock keys in the ssh-agent. (BZ#1238238)

This update fixes the following bugs:

* Previously, the sshd_config(5) man page was misleading and could thus
confuse the user. This update improves the man page text to clearly
describe the AllowGroups feature. (BZ#1150007)

* The limit for the function for restricting the number of files listed using the wildcard character (*) that prevents the Denial of Service (DoS) for both server and client was previously set too low. Consequently, the user reaching the limit was prevented from listing a directory with a large number of files over Secure File Transfer Protocol (SFTP). This update increases the aforementioned limit, thus fixing this bug. (BZ#1160377)

* When the ForceCommand option with a pseudoterminal was used and the
MaxSession option was set to "2", multiplexed SSH connections did not work
as expected. After the user attempted to open a second multiplexed
connection, the attempt failed if the first connection was still open. This
update modifies OpenSSH to issue only one audit message per session, and
the user is thus able to open two multiplexed connections in this
situation. (BZ#1199112)

* The ssh-copy-id utility failed if the account on the remote server did
not use an sh-like shell. Remote commands have been modified to run in an
sh-like shell, and ssh-copy-id now works also with non-sh-like shells.
(BZ#1201758)

* Due to a race condition between auditing messages and answers when using
ControlMaster multiplexing, one session in the shared connection randomly
and unexpectedly exited the connection. This update fixes the race
condition in the auditing code, and multiplexing connections now work as
expected even with a number of sessions created at once. (BZ#1240613)

In addition, this update adds the following enhancements:

* As not all Lightweight Directory Access Protocol (LDAP) servers possess
a default schema, as expected by the ssh-ldap-helper program, this update
provides the user with an ability to adjust the LDAP query to get public
keys from servers with a different schema, while the default functionality
stays untouched. (BZ#1201753)

* With this enhancement update, the administrator is able to set
permissions for files uploaded using Secure File Transfer Protocol (SFTP).
(BZ#1197989)

* This update provides the LDAP schema in LDAP Data Interchange Format (LDIF) format as a complement to the old schema previously accepted
by OpenLDAP. (BZ#1184938)

* With this update, the user can selectively disable the Generic Security
Services API (GSSAPI) key exchange algorithms as any normal key exchange.
(BZ#1253062)

Users of openssh are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2088</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5600</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6564</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152088"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152101" severity="medium">
    <xccdf:title>RHSA-2015:2101: python security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Python is an interpreted, interactive, object-oriented programming language
often compared to Tcl, Perl, Scheme, or Java. Python includes modules,
classes, exceptions, very high level dynamic data types and dynamic typing.
Python supports interfaces to many system calls and libraries, as well as
to various windowing systems (X11, Motif, Tk, Mac and MFC).

It was discovered that the Python xmlrpclib module did not restrict the
size of gzip-compressed HTTP responses. A malicious XMLRPC server could
cause an XMLRPC client using xmlrpclib to consume an excessive amount of
memory. (CVE-2013-1753)

It was discovered that multiple Python standard library modules
implementing network protocols (such as httplib or smtplib) failed to
restrict the sizes of server responses. A malicious server could cause a
client using one of the affected modules to consume an excessive amount of
memory. (CVE-2013-1752)

It was discovered that the CGIHTTPServer module incorrectly handled URL
encoded paths. A remote attacker could use this flaw to execute scripts
outside of the cgi-bin directory, or disclose the source code of the
scripts in the cgi-bin directory. (CVE-2014-4650)

An integer overflow flaw was found in the way the buffer() function handled
its offset and size arguments. An attacker able to control these arguments
could use this flaw to disclose portions of the application memory or cause
it to crash. (CVE-2014-7185)

A flaw was found in the way the json module handled negative index
arguments passed to certain functions (such as raw_decode()). An attacker
able to control the index value passed to one of the affected functions
could possibly use this flaw to disclose portions of the application
memory. (CVE-2014-4616)

The Python standard library HTTP client modules (such as httplib or urllib)
did not perform verification of TLS/SSL certificates when connecting to
HTTPS servers. A man-in-the-middle attacker could use this flaw to hijack
connections and eavesdrop or modify transferred data. (CVE-2014-9365)

Note: The Python standard library was updated to make it possible to enable
certificate verification by default. However, for backwards compatibility,
verification remains disabled by default. Future updates may change this
default. Refer to the Knowledgebase article 2039753 linked to in the
References section for further details about this change. (BZ#1219108)

This update also fixes the following bugs:

* Subprocesses used with the Eventlet library or regular threads previously
tried to close epoll file descriptors twice, which led to an "Invalid
argument" error. Subprocesses have been fixed to close the file descriptors
only once. (BZ#1103452)

* When importing the readline module from a Python script, Python no longer
produces erroneous random characters on stdout. (BZ#1189301)

* The cProfile utility has been fixed to print all values that the "-s"
option supports when this option is used without a correct value.
(BZ#1237107)

* The load_cert_chain() function now accepts "None" as a keyfile argument.
(BZ#1250611)

In addition, this update adds the following enhancements:

* Security enhancements as described in PEP 466 have been backported to the
Python standard library, for example, new features of the ssl module:
Server Name Indication (SNI) support, support for new TLSv1.x protocols,
new hash algorithms in the hashlib module, and many more. (BZ#1111461)

* Support for the ssl.PROTOCOL_TLSv1_2 protocol has been added to the ssl
library. (BZ#1192015)

* The ssl.SSLSocket.version() method is now available to access information
about the version of the SSL protocol used in a connection. (BZ#1259421)

All python users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2101</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1752</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-1753</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-4650</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7185</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152101"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152108" severity="medium">
    <xccdf:title>RHSA-2015:2108: cpio security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cpio packages provide the GNU cpio utility for creating and extracting
archives, or copying files from one place to another.

A heap-based buffer overflow flaw was found in cpio's list_file() function.
An attacker could provide a specially crafted archive that, when processed
by cpio, would crash cpio, or potentially lead to arbitrary code execution.
(CVE-2014-9112)

This update fixes the following bugs:

* Previously, during archive creation, cpio internals did not detect a
read() system call failure. Based on the premise that the call succeeded,
cpio terminated unexpectedly with a segmentation fault without processing
further files. The underlying source code has been patched, and an archive
is now created successfully. (BZ#1138148)

* Previously, running the cpio command without parameters on Red Hat
Enterprise Linux 7 with Russian as the default language resulted in an
error message that was not accurate in Russian due to an error in spelling.
This has been corrected and the Russian error message is spelled correctly.
(BZ#1075513)

All cpio users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2108</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9112</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152108"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152111" severity="low">
    <xccdf:title>RHSA-2015:2111: grep security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The grep utility searches through textual input for lines that contain a
match to a specified pattern and then prints the matching lines. The GNU
grep utilities include grep, egrep, and fgrep.

A heap-based buffer overflow flaw was found in the way grep processed
certain pattern and text combinations. An attacker able to trick a user
into running grep on specially crafted input could use this flaw to crash
grep or, potentially, read from uninitialized memory. (CVE-2015-1345)

This update also fixes the following bugs:

* Prior to this update, the \w and \W symbols were inconsistently matched
to the [:alnum:] character class. Consequently, using regular expressions
with "\w" and "\W" could lead to incorrect results. With this update, "\w"
is consistently matched to the [_[:alnum:]] character, and "\W" is
consistently matched to the [^_[:alnum:]] character. (BZ#1159012)

* Previously, the Perl Compatible Regular Expression (PCRE) matcher
(selected by the "-P" parameter in grep) did not work correctly when
matching non-UTF-8 text in UTF-8 locales. Consequently, an error message
about invalid UTF-8 byte sequence characters was returned. To fix this bug,
patches from upstream have been applied to the grep utility. As a result,
PCRE now skips non-UTF-8 characters as non-matching text without returning
any error message. (BZ#1217080)

All grep users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2111</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1345</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152111"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152131" severity="medium">
    <xccdf:title>RHSA-2015:2131: openldap security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenLDAP is an open-source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols used
to access and maintain distributed directory information services over an
IP network. The openldap packages contain configuration files, libraries,
and documentation for OpenLDAP.

A flaw was found in the way OpenLDAP parsed OpenSSL-style cipher strings.
As a result, OpenLDAP could potentially use ciphers that were not intended
to be enabled. (CVE-2015-3276)

This issue was discovered by Martin Poole of the Red Hat Software
Maintenance Engineering group.

The openldap packages have been upgraded to upstream version 2.4.40, which
provides a number of bug fixes and one enhancement over the previous
version:

* The ORDERING matching rules have been added to the ppolicy attribute type
descriptions.
* The server no longer terminates unexpectedly when processing SRV records.
* Missing objectClass information has been added, which enables the user to
modify the front-end configuration by standard means.

(BZ#1147982)

This update also fixes the following bugs:

* Previously, OpenLDAP did not properly handle a number of simultaneous
updates. As a consequence, sending a number of parallel update requests to
the server could cause a deadlock. With this update, a superfluous locking
mechanism causing the deadlock has been removed, thus fixing the bug.
(BZ#1125152)

* The httpd service sometimes terminated unexpectedly with a segmentation
fault on the libldap library unload. The underlying source code has been
modified to prevent a bad memory access error that caused the bug to occur.
As a result, httpd no longer crashes in this situation. (BZ#1158005)

* After upgrading the system from Red Hat Enterprise Linux 6 to Red Hat
Enterprise Linux 7, symbolic links to certain libraries unexpectedly
pointed to locations belonging to the openldap-devel package. If the user
uninstalled openldap-devel, the symbolic links were broken and the "rpm -V
openldap" command sometimes produced errors. With this update, the symbolic
links no longer get broken in the described situation. If the user
downgrades openldap to version 2.4.39-6 or earlier, the symbolic links
might break. After such downgrade, it is recommended to verify that the
symbolic links did not break. To do this, make sure the yum-plugin-verify
package is installed and obtain the target libraries by running the "rpm -V
openldap" or "yum verify openldap" command. (BZ#1230263)

In addition, this update adds the following enhancement:

* OpenLDAP clients now automatically choose the Network Security Services
(NSS) default cipher suites for communication with the server. It is no
longer necessary to maintain the default cipher suites manually in the
OpenLDAP source code. (BZ#1245279)

All openldap users are advised to upgrade to these updated packages, which
correct these issues and add this enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2131</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3276</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152131"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152140" severity="low">
    <xccdf:title>RHSA-2015:2140: libssh2 security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libssh2 packages provide a library that implements the SSH2 protocol.

A flaw was found in the way the kex_agree_methods() function of libssh2
performed a key exchange when negotiating a new SSH session. A
man-in-the-middle attacker could use a crafted SSH_MSG_KEXINIT packet to
crash a connecting libssh2 client. (CVE-2015-1782)

This update also fixes the following bugs:

* Previously, libssh2 did not correctly adjust the size of the receive
window while reading from an SSH channel. This caused downloads over
the secure copy (SCP) protocol to consume an excessive amount of memory.
A series of upstream patches has been applied on the libssh2 source code to
improve handling of the receive window size. Now, SCP downloads work as
expected. (BZ#1080459)

* Prior to this update, libssh2 did not properly initialize an internal
variable holding the SSH agent file descriptor, which caused the agent
destructor to close the standard input file descriptor by mistake.
An upstream patch has been applied on libssh2 sources to properly
initialize the internal variable. Now, libssh2 closes only the file
descriptors it owns. (BZ#1147717)

All libssh2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing these
updated packages, all running applications using libssh2 must be restarted
for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2140</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1782</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152140"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152151" severity="low">
    <xccdf:title>RHSA-2015:2151: xfsprogs security, bug fix and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The xfsprogs packages contain a set of commands to use the XFS file system,
including the mkfs.xfs command to construct an XFS system.

It was discovered that the xfs_metadump tool of the xfsprogs suite did not
fully adhere to the standards of obfuscation described in its man page. In
case a user with the necessary privileges used xfs_metadump and relied on
the advertised obfuscation, the generated data could contain unexpected
traces of potentially sensitive information. (CVE-2012-2150)

The xfsprogs packages have been upgraded to upstream version 3.2.2, which
provides a number of bug fixes and enhancements over the previous version.
This release also includes updates present in upstream version 3.2.3,
although it omits the mkfs.xfs default disk format change (for metadata
checksumming) which is present upstream. (BZ#1223991)

Users of xfsprogs are advised to upgrade to these updated packages, which
fix these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2151</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2012-2150</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152151"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152152" severity="high">
    <xccdf:title>RHSA-2015:2152: kernel security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's file system implementation
handled rename operations in which the source was inside and the
destination was outside of a bind mount. A privileged user inside a
container could use this flaw to escape the bind mount and, potentially,
escalate their privileges on the system. (CVE-2015-2925, Important)

* A race condition flaw was found in the way the Linux kernel's IPC
subsystem initialized certain fields in an IPC object structure that were
later used for permission checking before inserting the object into a
globally visible list. A local, unprivileged user could potentially use
this flaw to elevate their privileges on the system. (CVE-2015-7613,
Important)

* It was found that reporting emulation failures to user space could lead
to either a local (CVE-2014-7842) or a L2-&gt;L1 (CVE-2010-5313) denial of
service. In the case of a local denial of service, an attacker must have
access to the MMIO area or be able to access an I/O port. (CVE-2010-5313,
CVE-2014-7842, Moderate)

* A flaw was found in the way the Linux kernel's KVM subsystem handled
non-canonical addresses when emulating instructions that change the RIP
(for example, branches or calls). A guest user with access to an I/O or
MMIO region could use this flaw to crash the guest. (CVE-2014-3647,
Moderate)

* It was found that the Linux kernel memory resource controller's (memcg)
handling of OOM (out of memory) conditions could lead to deadlocks.
An attacker could use this flaw to lock up the system. (CVE-2014-8171,
Moderate)

* A race condition flaw was found between the chown and execve system
calls. A local, unprivileged user could potentially use this flaw to
escalate their privileges on the system. (CVE-2015-3339, Moderate)

* A flaw was discovered in the way the Linux kernel's TTY subsystem handled
the tty shutdown phase. A local, unprivileged user could use this flaw to
cause a denial of service on the system. (CVE-2015-4170, Moderate)

* A NULL pointer dereference flaw was found in the SCTP implementation.
A local user could use this flaw to cause a denial of service on the system
by triggering a kernel panic when creating multiple sockets in parallel
while the system did not have the SCTP module loaded. (CVE-2015-5283,
Moderate)

* A flaw was found in the way the Linux kernel's perf subsystem retrieved
userlevel stack traces on PowerPC systems. A local, unprivileged user could
use this flaw to cause a denial of service on the system. (CVE-2015-6526,
Moderate)

* A flaw was found in the way the Linux kernel's Crypto subsystem handled
automatic loading of kernel modules. A local user could use this flaw to
load any installed kernel module, and thus increase the attack surface of
the running kernel. (CVE-2013-7421, CVE-2014-9644, Low)

* An information leak flaw was found in the way the Linux kernel changed
certain segment registers and thread-local storage (TLS) during a context
switch. A local, unprivileged user could use this flaw to leak the user
space TLS base address of an arbitrary process. (CVE-2014-9419, Low)

* It was found that the Linux kernel KVM subsystem's sysenter instruction
emulation was not sufficient. An unprivileged guest user could use this
flaw to escalate their privileges by tricking the hypervisor to emulate a
SYSENTER instruction in 16-bit mode, if the guest OS did not initialize the
SYSENTER model-specific registers (MSRs). Note: Certified guest operating
systems for Red Hat Enterprise Linux with KVM do initialize the SYSENTER
MSRs and are thus not vulnerable to this issue when running on a KVM
hypervisor. (CVE-2015-0239, Low)

* A flaw was found in the way the Linux kernel handled the securelevel
functionality after performing a kexec operation. A local attacker could
use this flaw to bypass the security mechanism of the
securelevel/secureboot combination. (CVE-2015-7837, Low)</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2010-5313</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3647</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-7842</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9644</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0239</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3288</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6526</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7553</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7837</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8215</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0774</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152152"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152154" severity="medium">
    <xccdf:title>RHSA-2015:2154: krb5 security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Kerberos is a network authentication system, which can improve the security
of your network by eliminating the insecure practice of sending passwords
over the network in unencrypted form. It allows clients and servers to
authenticate to each other with the help of a trusted third party, the
Kerberos key distribution center (KDC).

It was found that the krb5_read_message() function of MIT Kerberos did not
correctly sanitize input, and could create invalid krb5_data objects.
A remote, unauthenticated attacker could use this flaw to crash a Kerberos
child process via a specially crafted request. (CVE-2014-5355)

A flaw was found in the OTP kdcpreauth module of MIT kerberos.
An unauthenticated remote attacker could use this flaw to bypass the
requires_preauth flag on a client principal and obtain a ciphertext
encrypted in the principal's long-term key. This ciphertext could be used
to conduct an off-line dictionary attack against the user's password.
(CVE-2015-2694)

The krb5 packages have been upgraded to upstream version 1.13.2, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1203889)

Notably, this update fixes the following bugs:

* Previously, the RADIUS support (libkrad) in krb5 was sending krb5
authentication for Transmission Control Protocol (TCP) transports multiple
times, accidentally using a code path intended to be used only for
unreliable transport types, for example User Datagram Protocol (UDP)
transports. A patch that fixes the problem by disabling manual retries for
reliable transports, such as TCP, has been applied, and the correct code
path is now used in this situation. (BZ#1251586)

* Attempts to use Kerberos single sign-on (SSO) to access SAP NetWeaver
systems sometimes failed. The SAP NetWeaver developer trace displayed the
following error message:

    No credentials were supplied, or the credentials were
    unavailable or inaccessible
    Unable to establish the security context

Querying SSO credential lifetime has been modified to trigger credential
acquisition, thus preventing the error from occurring. Now, the user can
successfully use Kerberos SSO for accessing SAP NetWeaver systems.
(BZ#1252454)

All krb5 users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2154</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-5355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2694</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152154"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152155" severity="medium">
    <xccdf:title>RHSA-2015:2155: file security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The file command is used to identify a particular file according to the 
type of data the file contains. It can identify many different file 
types, including Executable and Linkable Format (ELF) binary files, 
system libraries, RPM packages, and different graphics formats.

Multiple denial of service flaws were found in the way file parsed certain
Composite Document Format (CDF) files. A remote attacker could use either
of these flaws to crash file, or an application using file, via a specially
crafted CDF file. (CVE-2014-0207, CVE-2014-0237, CVE-2014-0238,
CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3587)

Two flaws were found in the way file processed certain Pascal strings. A
remote attacker could cause file to crash if it was used to identify the
type of the attacker-supplied file. (CVE-2014-3478, CVE-2014-9652)

Multiple flaws were found in the file regular expression rules for
detecting various files. A remote attacker could use these flaws to cause
file to consume an excessive amount of CPU. (CVE-2014-3538)

Multiple flaws were found in the way file parsed Executable and Linkable
Format (ELF) files. A remote attacker could use these flaws to cause file
to crash, disclose portions of its memory, or consume an excessive amount
of system resources. (CVE-2014-3710, CVE-2014-8116, CVE-2014-8117,
CVE-2014-9653)

Red Hat would like to thank Thomas Jarosch of Intra2net AG for reporting
the CVE-2014-8116 and CVE-2014-8117 issues. The CVE-2014-0207,
CVE-2014-0237, CVE-2014-0238, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480,
CVE-2014-3487, CVE-2014-3710 issues were discovered by Francisco Alonso of
Red Hat Product Security; the CVE-2014-3538 issue was discovered by Jan
Kaluža of the Red Hat Web Stack Team

The file packages have been updated to ensure correct operation on Power
little endian and ARM 64-bit hardware architectures. (BZ#1224667,
BZ#1224668, BZ#1157850, BZ#1067688).

All file users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2155</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0207</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-0238</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3478</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3479</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3480</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3487</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3538</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3587</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8116</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8117</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9652</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9653</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152155"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152159" severity="medium">
    <xccdf:title>RHSA-2015:2159: curl security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP.

It was found that the libcurl library did not correctly handle partial
literal IP addresses when parsing received HTTP cookies. An attacker able
to trick a user into connecting to a malicious server could use this flaw
to set the user's cookie to a crafted domain, making other cookie-related
issues easier to exploit. (CVE-2014-3613)

A flaw was found in the way the libcurl library performed the duplication
of connection handles. If an application set the CURLOPT_COPYPOSTFIELDS
option for a handle, using the handle's duplicate could cause the
application to crash or disclose a portion of its memory. (CVE-2014-3707)

It was discovered that the libcurl library failed to properly handle URLs
with embedded end-of-line characters. An attacker able to make an
application using libcurl access a specially crafted URL via an HTTP proxy
could use this flaw to inject additional headers to the request or
construct additional requests. (CVE-2014-8150)

It was discovered that libcurl implemented aspects of the NTLM and
Negotatiate authentication incorrectly. If an application uses libcurl
and the affected mechanisms in a specifc way, certain requests to a
previously NTLM-authenticated server could appears as sent by the wrong
authenticated user. Additionally, the initial set of credentials for HTTP
Negotiate-authenticated requests could be reused in subsequent requests,
although a different set of credentials was specified. (CVE-2015-3143,
CVE-2015-3148)

Red Hat would like to thank the cURL project for reporting these issues.

Bug fixes:

* An out-of-protocol fallback to SSL 3.0 was available with libcurl.
Attackers could abuse the fallback to force downgrade of the SSL version.
The fallback has been removed from libcurl. Users requiring this
functionality can explicitly enable SSL 3.0 through the libcurl API.
(BZ#1154060)

* TLS 1.1 and TLS 1.2 are no longer disabled by default in libcurl. You can
explicitly disable them through the libcurl API. (BZ#1170339)

* FTP operations such as downloading files took a significantly long time
to complete. Now, the FTP implementation in libcurl correctly sets blocking
direction and estimated timeout for connections, resulting in faster FTP
transfers. (BZ#1218272)

Enhancements:

* With the updated packages, it is possible to explicitly enable or disable
new Advanced Encryption Standard (AES) cipher suites to be used for the TLS
protocol. (BZ#1066065)

* The libcurl library did not implement a non-blocking SSL handshake, which
negatively affected performance of applications based on the libcurl multi
API. The non-blocking SSL handshake has been implemented in libcurl, and
the libcurl multi API now immediately returns the control back to the
application whenever it cannot read or write data from or to the underlying
network socket. (BZ#1091429)

* The libcurl library used an unnecessarily long blocking delay for actions
with no active file descriptors, even for short operations. Some actions,
such as resolving a host name using /etc/hosts, took a long time to
complete. The blocking code in libcurl has been modified so that the
initial delay is short and gradually increases until an event occurs.
(BZ#1130239)

All curl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2159</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3707</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8150</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3143</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3148</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152159"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152172" severity="high">
    <xccdf:title>RHSA-2015:2172: glibc security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

It was discovered that the nss_files backend for the Name Service Switch in
glibc would return incorrect data to applications or corrupt the heap
(depending on adjacent heap contents) in certain cases. A local attacker
could potentially use this flaw to escalate their privileges.
(CVE-2015-5277)

This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2172</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5277</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152172"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152180" severity="medium">
    <xccdf:title>RHSA-2015:2180: rubygem-bundler and rubygem-thor security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Bundler manages an application's dependencies through its entire life,
across many machines, systematically and repeatably. Thor is a toolkit for
building powerful command-line interfaces.

A flaw was found in the way Bundler handled gems available from multiple
sources. An attacker with access to one of the sources could create a
malicious gem with the same name, which they could then use to trick a user
into installing, potentially resulting in execution of code from the
attacker-supplied malicious gem. (CVE-2013-0334)

Bundler has been upgraded to upstream version 1.7.8 and Thor has been
upgraded to upstream version 1.19.1, both of which provide a number of bug
fixes and enhancements over the previous versions. (BZ#1194243, BZ#1209921)

All rubygem-bundler and rubygem-thor users are advised to upgrade to these
updated packages, which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2180</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-0334</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152180"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152184" severity="medium">
    <xccdf:title>RHSA-2015:2184: realmd security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The realmd DBus system service manages discovery of and enrollment in
realms and domains, such as Active Directory or Identity Management (IdM).
The realmd service detects available domains, automatically configures the
system, and joins it as an account to a domain.

A flaw was found in the way realmd parsed certain input when writing
configuration into the sssd.conf or smb.conf file. A remote attacker could
use this flaw to inject arbitrary configurations into these files via a
newline character in an LDAP response. (CVE-2015-2704)

It was found that the realm client would try to automatically join an
active directory domain without authentication, which could potentially
lead to privilege escalation within a specified domain. (BZ#1205751)

The realmd packages have been upgraded to upstream version 0.16.1, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1174911)

This update also fixes the following bugs:

* Joining a Red Hat Enterprise Linux machine to a domain using the realm
utility creates /home/domainname/[username]/ directories for domain users.
Previously, SELinux labeled the domain users' directories incorrectly. As a
consequence, the domain users sometimes experienced problems with SELinux
policy. This update modifies the realmd service default behavior so that
the domain users' directories are compatible with the standard SELinux
policy. (BZ#1241832)

* Previously, the realm utility was unable to join or discover domains with
domain names containing underscore (_). The realmd service has been
modified to process underscores in domain names correctly, which fixes the
described bug. (BZ#1243771)

In addition, this update adds the following enhancement:

* The realmd utility now allows the user to disable automatic ID mapping
from the command line. To disable the mapping, pass the
"--automatic-id-mapping=no" option to the realmd utility. (BZ#1230941)

All realmd users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2184</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152184"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152199" severity="medium">
    <xccdf:title>RHSA-2015:2199: glibc security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

It was discovered that, under certain circumstances, glibc's getaddrinfo()
function would send DNS queries to random file descriptors. An attacker
could potentially use this flaw to send DNS queries to unintended
recipients, resulting in information disclosure or data loss due to the
application encountering corrupted data. (CVE-2013-7423)

A buffer overflow flaw was found in the way glibc's gethostbyname_r() and
other related functions computed the size of a buffer when passed a
misaligned buffer as input. An attacker able to make an application call
any of these functions with a misaligned buffer could use this flaw to
crash the application or, potentially, execute arbitrary code with the
permissions of the user running the application. (CVE-2015-1781)

A heap-based buffer overflow flaw and a stack overflow flaw were found in
glibc's swscanf() function. An attacker able to make an application call
the swscanf() function could use these flaws to crash that application or,
potentially, execute arbitrary code with the permissions of the user
running the application. (CVE-2015-1472, CVE-2015-1473)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in glibc's _IO_wstr_overflow() function. An attacker able to make an
application call this function could use this flaw to crash that
application or, potentially, execute arbitrary code with the permissions of
the user running the application. (BZ#1195762)

A flaw was found in the way glibc's fnmatch() function processed certain
malformed patterns. An attacker able to make an application call this
function could use this flaw to crash that application. (BZ#1197730)

The CVE-2015-1781 issue was discovered by Arjun Shankar of Red Hat.

These updated glibc packages also include numerous bug fixes and one
enhancement. Space precludes documenting all of these changes in this
advisory. For information on the most significant of these changes, users
are directed to the following article on the Red Hat Customer Portal:

https://access.redhat.com/articles/2050743

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7423</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1473</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1781</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152199"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152231" severity="medium">
    <xccdf:title>RHSA-2015:2231: ntp security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with another referenced time source. These packages include the ntpd
service which continuously adjusts system time and utilities used to query
and configure the ntpd service.

It was found that because NTP's access control was based on a source IP
address, an attacker could bypass source IP restrictions and send
malicious control and configuration packets by spoofing ::1 addresses.
(CVE-2014-9298, CVE-2014-9751)

A denial of service flaw was found in the way NTP hosts that were peering
with each other authenticated themselves before updating their internal
state variables. An attacker could send packets to one peer host, which
could cascade to other peers, and stop the synchronization process among
the reached peers. (CVE-2015-1799)

A flaw was found in the way the ntp-keygen utility generated MD5 symmetric
keys on big-endian systems. An attacker could possibly use this flaw to
guess generated MD5 keys, which could then be used to spoof an NTP client
or server. (CVE-2015-3405)

A stack-based buffer overflow was found in the way the NTP autokey protocol
was implemented. When an NTP client decrypted a secret received from an NTP
server, it could cause that client to crash. (CVE-2014-9297, CVE-2014-9750)

It was found that ntpd did not check whether a Message Authentication Code
(MAC) was present in a received packet when ntpd was configured to use
symmetric cryptographic keys. A man-in-the-middle attacker could use this
flaw to send crafted packets that would be accepted by a client or a peer
without the attacker knowing the symmetric key. (CVE-2015-1798)

The CVE-2015-1798 and CVE-2015-1799 issues were discovered by Miroslav
Lichvár of Red Hat.

Bug fixes:

* The ntpd service truncated symmetric keys specified in the key file to 20
bytes. As a consequence, it was impossible to configure NTP authentication
to work with peers that use longer keys. With this update, the maximum key
length has been changed to 32 bytes. (BZ#1191111)

* The ntpd service could previously join multicast groups only when
starting, which caused problems if ntpd was started during system boot
before network was configured. With this update, ntpd attempts to join
multicast groups every time network configuration is changed. (BZ#1207014)

* Previously, the ntp-keygen utility used the exponent of 3 when generating
RSA keys. Consequently, generating RSA keys failed when FIPS mode was
enabled. With this update, ntp-keygen has been modified to use the exponent
of 65537, and generating keys in FIPS mode now works as expected.
(BZ#1191116)

* The ntpd service dropped incoming NTP packets if their source port was
lower than 123 (the NTP port). With this update, ntpd no longer checks the
source port number, and clients behind NAT are now able to correctly
synchronize with the server. (BZ#1171640)

Enhancements:

* This update adds support for configurable Differentiated Services Code
Points (DSCP) in NTP packets, simplifying configuration in large networks
where different NTP implementations or versions are using different DSCP
values. (BZ#1202828)

* This update adds the ability to configure separate clock stepping
thresholds for each direction (backward and forward). Use the "stepback"
and "stepfwd" options to configure each threshold. (BZ#1193154)

* Support for nanosecond resolution has been added to the Structural
Health Monitoring (SHM) reference clock. Prior to this update, when a
Precision Time Protocol (PTP) hardware clock was used as a time source to
synchronize the system clock, the accuracy of the synchronization was
limited due to the microsecond resolution of the SHM protocol. The
nanosecond extension in the SHM protocol now allows sub-microsecond
synchronization of the system clock. (BZ#1117702)

All ntp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2231</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9297</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9298</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9750</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9751</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1798</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1799</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3405</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152231"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152233" severity="medium">
    <xccdf:title>RHSA-2015:2233: tigervnc security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Virtual Network Computing (VNC) is a remote display system which allows
users to view a computing desktop environment not only on the machine where
it is running, but from anywhere on the Internet and from a wide variety of
machine architectures. TigerVNC is a suite of VNC servers and clients.
The tigervnc packages contain a client which allows users to connect to
other desktops running a VNC server.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way TigerVNC handled screen sizes. A malicious VNC server
could use this flaw to cause a client to crash or, potentially, execute
arbitrary code on the client. (CVE-2014-8240)

A NULL pointer dereference flaw was found in TigerVNC's XRegion.
A malicious VNC server could use this flaw to cause a client to crash.
(CVE-2014-8241)

The tigervnc packages have been upgraded to upstream version 1.3.1, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1199453)

This update also fixes the following bug:

* The position of the mouse cursor in the VNC session was not correctly
communicated to the VNC viewer, resulting in cursor misplacement.
The method of displaying the remote cursor has been changed, and cursor
movements on the VNC server are now accurately reflected on the VNC client.
(BZ#1100661)

All tigervnc users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2233</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8240</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8241</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152233"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152237" severity="low">
    <xccdf:title>RHSA-2015:2237: rest security update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rest library was designed to make it easier to access web services that
claim to be RESTful. A RESTful service should have URLs that represent
remote objects, which methods can then be called on.

It was found that the OAuth implementation in librest, a helper library for
RESTful services, incorrectly truncated the pointer returned by the
rest_proxy_call_get_url call. An attacker could use this flaw to crash an
application using the librest library. (CVE-2015-2675)

All users of rest are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using librest must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2237</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2675</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152237"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152241" severity="medium">
    <xccdf:title>RHSA-2015:2241: chrony security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The chrony suite, chronyd and chronyc, is an advanced implementation of the
Network Time Protocol (NTP), specially designed to support systems with
intermittent connections. It can synchronize the system clock with NTP
servers, hardware reference clocks, and manual input. It can also operate
as an NTPv4 (RFC 5905) server or peer to provide a time service to other
computers in the network.

An out-of-bounds write flaw was found in the way chrony stored certain
addresses when configuring NTP or cmdmon access. An attacker that has the
command key and is allowed to access cmdmon (only localhost is allowed by
default) could use this flaw to crash chronyd or, possibly, execute
arbitrary code with the privileges of the chronyd process. (CVE-2015-1821)

An uninitialized pointer use flaw was found when allocating memory to save
unacknowledged replies to authenticated command requests. An attacker that
has the command key and is allowed to access cmdmon (only localhost is
allowed by default) could use this flaw to crash chronyd or, possibly,
execute arbitrary code with the privileges of the chronyd process.
(CVE-2015-1822)

A denial of service flaw was found in the way chrony hosts that were
peering with each other authenticated themselves before updating their
internal state variables. An attacker could send packets to one peer host,
which could cascade to other peers, and stop the synchronization process
among the reached peers. (CVE-2015-1853)

These issues were discovered by Miroslav Lichvár of Red Hat.

The chrony packages have been upgraded to upstream version 2.1.1, which
provides a number of bug fixes and enhancements over the previous version.
Notable enhancements include:

* Updated to NTP version 4 (RFC 5905)

* Added pool directive to specify pool of NTP servers

* Added leapsecmode directive to select how to correct clock for leap
second

* Added smoothtime directive to smooth served time and enable leap smear

* Added asynchronous name resolving with POSIX threads

* Ready for year 2036 (next NTP era)

* Improved clock control

* Networking code reworked to open separate client sockets for each NTP
server

(BZ#1117882)

This update also fixes the following bug:

* The chronyd service previously assumed that network interfaces specified
with the "bindaddress" directive were ready when the service was started.
This could cause chronyd to fail to bind an NTP server socket to the
interface if the interface was not ready. With this update, chronyd uses
the IP_FREEBIND socket option, enabling it to bind to an interface later,
not only when the service starts. (BZ#1169353)

In addition, this update adds the following enhancement:

* The chronyd service now supports four modes of handling leap seconds,
configured using the "leapsecmode" option. The clock can be either stepped
by the kernel (the default "system" mode), stepped by chronyd ("step"
mode), slowly adjusted by slewing ("slew" mode), or the leap second can be
ignored and corrected later in normal operation ("ignore" mode). If you
select slewing, the correction will always start at 00:00:00 UTC and will
be applied at a rate specified in the "maxslewrate" option. (BZ#1206504)

All chrony users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1821</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1822</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1853</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152241"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152248" severity="medium">
    <xccdf:title>RHSA-2015:2248: netcf security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The netcf packages contain a library for modifying the network
configuration of a system. Network configuration is expressed in a
platform-independent XML format, which netcf translates into changes to the
system's "native" network configuration files.

A denial of service flaw was found in netcf. A specially crafted interface
name could cause an application using netcf (such as the libvirt daemon) to
crash. (CVE-2014-8119)

This issue was discovered by Hao Liu of Red Hat.

The netcf packages have been upgraded to upstream version 0.2.8, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1206680)

Users of netcf are advised to upgrade to these updated packages, which fix
these bugs and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2248</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8119</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152248"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152290" severity="medium">
    <xccdf:title>RHSA-2015:2290: pcs security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The pcs package provides a configuration tool for Corosync and Pacemaker.
It permits users to easily view, modify and create Pacemaker based
clusters. The pcs package includes Rack, which provides a minimal interface
between webservers that support Ruby and Ruby frameworks.

A flaw was found in a way Rack processed parameters of incoming requests.
An attacker could use this flaw to send a crafted request that would cause
an application using Rack to crash. (CVE-2015-3225)

Red Hat would like to thank Ruby upstream developers for reporting this.
Upstream acknowledges Tomek Rabczak from the NCC Group as the original
reporter.

The pcs package has been upgraded to upstream version 0.9.143, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1198265)

The following enhancements are described in more detail in the Red Hat
Enterprise Linux 7.2 Release Notes, linked to from the References section:

* The pcs resource move and pcs resource ban commands now display a warning
message to clarify the commands' behavior (BZ#1201452)

* New command to move a Pacemaker resource to its preferred node
(BZ#1122818)

This update also fixes the following bugs:

* Before this update, a bug caused location, ordering, and colocation
constraints related to a resource group to be removed when removing any
resource from that group. This bug has been fixed, and the constraints are
now preserved until the group has no resources left, and is removed.
(BZ#1158537)

* Previously, when a user disabled a resource clone or multi-state
resource, and then later enabled a primitive resource within it, the clone
or multi-state resource remained disabled. With this update, enabling a
resource within a disabled clone or multi-state resource enables it.
(BZ#1218979)

* When the web UI displayed a list of resource attributes, a bug caused
the list to be truncated at the first "=" character. This update fixes the
bug and now the web UI displays lists of resource attributes correctly.
(BZ#1243579)

* The documentation for the "pcs stonith confirm" command was not clear.
This could lead to incorrect usage of the command, which could in turn
cause data corruption. With this update, the documentation has been
improved and the "pcs stonith confirm" command is now more clearly
explained. (BZ#1245264)

* Previously, if there were any unauthenticated nodes, creating a new
cluster, adding a node to an existing cluster, or adding a cluster to the
web UI failed with the message "Node is not authenticated". With this
update, when the web UI detects a problem with authentication, the web UI
displays a dialog to authenticate nodes as necessary. (BZ#1158569)

* Previously, the web UI displayed only primitive resources. Thus there was
no way to set attributes, constraints and other properties separately for a
parent resource and a child resource. This has now been fixed, and
resources are displayed in a tree structure, meaning all resource elements
can be viewed and edited independently. (BZ#1189857)

In addition, this update adds the following enhancements:

* A dashboard has been added which shows the status of clusters in the web
UI. Previously, it was not possible to view all important information about
clusters in one place. Now, a dashboard showing the status of clusters has
been added to the main page of the web UI. (BZ#1158566)

* With this update, the pcsd daemon automatically synchronizes pcsd
configuration across a cluster. This enables the web UI to be run from any
node, allowing management even if any particular node is down. (BZ#1158577)

* The web UI can now be used to set permissions for users and groups on a
cluster. This allows users and groups to have their access restricted to
certain operations on certain clusters. (BZ#1158571)

All pcs users are advised to upgrade to this updated package, which
corrects these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2290</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3225</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152290"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152315" severity="medium">
    <xccdf:title>RHSA-2015:2315: NetworkManager security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>NetworkManager is a system network service that manages network devices
and connections.

It was discovered that NetworkManager would set device MTUs based on MTU
values received in IPv6 RAs (Router Advertisements), without sanity
checking the MTU value first. A remote attacker could exploit this flaw to
create a denial of service attack, by sending a specially crafted IPv6 RA
packet to disturb IPv6 communication. (CVE-2015-0272)

A flaw was found in the way NetworkManager handled router advertisements.
An unprivileged user on a local network could use IPv6 Neighbor Discovery
ICMP to broadcast a non-route with a low hop limit, causing machines to
lower the hop limit on existing IPv6 routes. If this limit is small enough,
IPv6 packets would be dropped before reaching the final destination.
(CVE-2015-2924)

The network-manager-applet and NetworkManager-libreswan packages have been
upgraded to upstream versions 1.0.6, and provide a number of bug fixes and
enhancements over the previous versions. (BZ#1177582, BZ#1243057)

Bugs:

* It was not previously possible to set the Wi-Fi band to the "a" or "bg"
values to lock to a specific frequency band. NetworkManager has been fixed,
and it now sets the wpa_supplicant's "freq_list" option correctly, which
enables proper Wi-Fi band locking. (BZ#1254461)

* NetworkManager immediately failed activation of devices that did not have
a carrier early in the boot process. The legacy network.service then
reported activation failure. Now, NetworkManager has a grace period during
which it waits for the carrier to appear. Devices that have a carrier down
for a short time on system startup no longer cause the legacy
network.service to fail. (BZ#1079353)

* NetworkManager brought down a team device if the teamd service managing
it exited unexpectedly, and the team device was deactivated. Now,
NetworkManager respawns the teamd instances that disappear and is able to
recover from a teamd failure avoiding disruption of the team device
operation. (BZ#1145988)

* NetworkManager did not send the FQDN DHCP option even if host name was
set to FQDN. Consequently, Dynamic DNS (DDNS) setups failed to update the
DNS records for clients running NetworkManager. Now, NetworkManager sends
the FQDN option with DHCP requests, and the DHCP server is able to create
DNS records for such clients. (BZ#1212597)

* The command-line client was not validating the vlan.flags property
correctly, and a spurious warning message was displayed when the nmcli tool
worked with VLAN connections. The validation routine has been fixed, and
the warning message no longer appears. (BZ#1244048)

* NetworkManager did not propagate a media access control (MAC) address
change from a bonding interface to a VLAN interface on top of it.
Consequently, a VLAN interface on top of a bond used an incorrect MAC
address. Now, NetworkManager synchronizes the addresses correctly.
(BZ#1264322)

Enhancements:

* IPv6 Privacy extensions are now enabled by default. NetworkManager checks
the per-network configuration files, NetworkManager.conf, and then falls
back to "/proc/sys/net/ipv6/conf/default/use_tempaddr" to determine and set
IPv6 privacy settings at device activation. (BZ#1187525)

* The NetworkManager command-line tool, nmcli, now allows setting the
wake-on-lan property to 0 ("none", "disable", "disabled"). (BZ#1260584)

* NetworkManager now provides information about metered connections.
(BZ#1200452)

* NetworkManager daemon and the connection editor now support setting the
Maximum Transmission Unit (MTU) of a bond. It is now possible to change MTU
of a bond interface in a GUI. (BZ#1177582, BZ#1177860)

* NetworkManager daemon and the connection editor now support setting the
MTU of a team, allowing to change MTU of a teaming interface. (BZ#1255927)

NetworkManager users are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2315</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0272</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2924</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152315"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152345" severity="medium">
    <xccdf:title>RHSA-2015:2345: net-snmp security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

A denial of service flaw was found in the way snmptrapd handled certain
SNMP traps when started with the "-OQ" option. If an attacker sent an SNMP
trap containing a variable with a NULL type where an integer variable type
was expected, it would cause snmptrapd to crash. (CVE-2014-3565)

This update also fixes the following bugs:

* Previously, the clientaddr option in the snmp.conf file affected outgoing
messages sent only over IPv4. With this release, outgoing IPv6 messages are
correctly sent from the interface specified by clientaddr. (BZ#1190679)

* The Net-SNMP daemon, snmpd, did not properly clean memory when reloading
its configuration file with multiple "exec" entries. Consequently, the
daemon terminated unexpectedly. Now, the memory is properly cleaned, and
snmpd no longer crashes on reload. (BZ#1228893)

* Prior to this update, snmpd did not parse complete IPv4 traffic
statistics, but reported the number of received or sent bytes in the
IP-MIB::ipSystemStatsTable only for IPv6 packets and not for IPv4.
This affected objects ipSystemStatsInOctets, ipSystemStatsOutOctets,
ipSystemStatsInMcastOctets, and ipSystemStatsOutMcastOctets. Now, the
statistics reported by snmpd are collected for IPv4 as well. (BZ#1235697)

* The Net-SNMP daemon, snmpd, did not correctly detect the file system
change from read-only to read-write. Consequently, after remounting the
file system into the read-write mode, the daemon reported it to be still
in the read-only mode. A patch has been applied, and snmpd now detects the
mode changes as expected. (BZ#1241897)

All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2345</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-3565</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152345"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152355" severity="low">
    <xccdf:title>RHSA-2015:2355: sssd security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The System Security Services Daemon (SSSD) service provides a set of
daemons to manage access to remote directories and authentication
mechanisms.

It was found that SSSD's Privilege Attribute Certificate (PAC) responder
plug-in would leak a small amount of memory on each authentication request.
A remote attacker could potentially use this flaw to exhaust all available
memory on the system by making repeated requests to a Kerberized daemon
application configured to authenticate using the PAC responder plug-in.
(CVE-2015-5292)

The sssd packages have been upgraded to upstream version 1.13.0, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1205554)

Several enhancements are described in the Red Hat Enterprise Linux 7.2
Release Notes, linked to in the References section:

* SSSD smart card support (BZ#854396)
* Cache authentication in SSSD (BZ#910187)
* SSSD supports overriding automatically discovered AD site (BZ#1163806)
* SSSD can now deny SSH access to locked accounts (BZ#1175760)
* SSSD enables UID and GID mapping on individual clients (BZ#1183747)
* Background refresh of cached entries (BZ#1199533)
* Multi-step prompting for one-time and long-term passwords (BZ#1200873)
* Caching for initgroups operations (BZ#1206575)

Bugs fixed:

* When the SELinux user content on an IdM server was set to an empty
string, the SSSD SELinux evaluation utility returned an error. (BZ#1192314)

* If the ldap_child process failed to initialize credentials and exited
with an error multiple times, operations that create files in some cases
started failing due to an insufficient amount of i-nodes. (BZ#1198477)

* The SRV queries used a hard coded TTL timeout, and environments that
wanted the SRV queries to be valid for a certain time only were blocked.
Now, SSSD parses the TTL value out of the DNS packet. (BZ#1199541)

* Previously, initgroups operation took an excessive amount of time. Now,
logins and ID processing are faster for setups with AD back end and
disabled ID mapping. (BZ#1201840)

* When an IdM client with Red Hat Enterprise Linux 7.1 or later was
connecting to a server with Red Hat Enterprise Linux 7.0 or earlier,
authentication with an AD trusted domain caused the sssd_be process to
terminate unexpectedly. (BZ#1202170)

* If replication conflict entries appeared during HBAC processing, the user
was denied access. Now, the replication conflict entries are skipped and
users are permitted access. (BZ#1202245)

* The array of SIDs no longer contains an uninitialized value and SSSD no
longer crashes. (BZ#1204203)

* SSSD supports GPOs from different domain controllers and no longer
crashes when processing GPOs from different domain controllers.
(BZ#1205852)

* SSSD could not refresh sudo rules that contained groups with special
characters, such as parentheses, in their name. (BZ#1208507)

* The IPA names are not qualified on the client side if the server already
qualified them, and IdM group members resolve even if default_domain_suffix
is used on the server side. (BZ#1211830)

* The internal cache cleanup task has been disabled by default to improve
performance of the sssd_be process. (BZ#1212489)

* Now, default_domain_suffix is not considered anymore for autofs maps.
(BZ#1216285)

* The user can set subdomain_inherit=ignore_group-members to disable
fetching group members for trusted domains. (BZ#1217350)

* The group resolution failed with an error message: "Error: 14 (Bad
address)". The binary GUID handling has been fixed. (BZ#1226119)

Enhancements added:

* The description of default_domain_suffix has been improved in the manual
pages. (BZ#1185536)

* With the new "%0" template option, users on SSSD IdM clients can now use
home directories set on AD. (BZ#1187103)

All sssd users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2355</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5292</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152355"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152360" severity="medium">
    <xccdf:title>RHSA-2015:2360: cups-filters security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The cups-filters packages contain back ends, filters, and other software
that was once part of the core Common UNIX Printing System (CUPS)
distribution but is now maintained independently.

A heap-based buffer overflow flaw and an integer overflow flaw leading to a
heap-based buffer overflow were discovered in the way the texttopdf utility
of cups-filter processed print jobs with a specially crafted line size.
An attacker able to submit print jobs could use these flaws to crash
texttopdf or, possibly, execute arbitrary code with the privileges of the
"lp" user. (CVE-2015-3258, CVE-2015-3279)

The CVE-2015-3258 issue was discovered by Petr Sklenar of Red Hat.

Notably, this update also fixes the following bug:

* Previously, when polling CUPS printers from a CUPS server, when a printer
name contained an underscore (_), the client displayed the name containing
a hyphen (-) instead. This made the print queue unavailable. With this
update, CUPS allows the underscore character in printer names, and printers
appear as shown on the CUPS server as expected. (BZ#1167408)

In addition, this update adds the following enhancement:

* Now, the information from local and remote CUPS servers is cached during
each poll, and the CUPS server load is reduced. (BZ#1191691)

All cups-filters users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2360</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3258</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3279</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152360"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152369" severity="low">
    <xccdf:title>RHSA-2015:2369: openhpi security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenHPI is an open source project created with the intent of providing an
implementation of the SA Forum's Hardware Platform Interface (HPI).
HPI provides an abstracted interface to managing computer hardware,
typically for chassis and rack based servers. HPI includes resource
modeling, access to and control over sensor, control, watchdog, and
inventory data associated with resources, abstracted System Event Log
interfaces, hardware events and alerts, and a managed hotswap interface.

It was found that the "/var/lib/openhpi" directory provided by OpenHPI used
world-writeable and world-readable permissions. A local user could use this
flaw to view, modify, and delete OpenHPI-related data, or even fill up the
storage device hosting the /var/lib directory. (CVE-2015-3248)

This issue was discovered by Marko Myllynen of Red Hat.

The openhpi packages have been upgraded to upstream version 3.4.0, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1127908)

This update also fixes the following bug:

* Network timeouts were handled incorrectly in the openhpid daemon. As a
consequence, network connections could fail when external plug-ins were
used. With this update, handling of network socket timeouts has been
improved in openhpid, and the described problem no longer occurs.
(BZ#1208127)

All openhpi users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2369</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152369"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152378" severity="medium">
    <xccdf:title>RHSA-2015:2378: squid security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

It was found that Squid configured with client-first SSL-bump did not
correctly validate X.509 server certificate host name fields. A
man-in-the-middle attacker could use this flaw to spoof a Squid server
using a specially crafted X.509 certificate. (CVE-2015-3455)

This update fixes the following bugs:

* Previously, the squid process did not handle file descriptors correctly
when receiving Simple Network Management Protocol (SNMP) requests. As a
consequence, the process gradually accumulated open file descriptors. This
bug has been fixed and squid now handles SNMP requests correctly, closing
file descriptors when necessary. (BZ#1198778)

* Under high system load, the squid process sometimes terminated
unexpectedly with a segmentation fault during reboot. This update provides
better memory handling during reboot, thus fixing this bug. (BZ#1225640)

Users of squid are advised to upgrade to these updated packages, which fix
these bugs. After installing this update, the squid service will be
restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2378</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3455</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152378"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152383" severity="medium">
    <xccdf:title>RHSA-2015:2383: pacemaker security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Pacemaker Resource Manager is a collection of technologies working
together to provide data integrity and the ability to maintain
application availability in the event of a failure.

A flaw was found in the way pacemaker, a cluster resource manager,
evaluated added nodes in certain situations. A user with read-only access
could potentially assign any other existing roles to themselves and then
add privileges to other users as well. (CVE-2015-1867)

The pacemaker packages have been upgraded to upstream version 1.1.13, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1234680)

This update also fixes the following bugs:

* When a Pacemaker cluster included an Apache resource, and Apache's
mod_systemd module was enabled, systemd rejected notifications sent by
Apache. As a consequence, a large number of errors in the following format
appeared in the system log:

  Got notification message from PID XXXX, but reception only permitted
  for PID YYYY

With this update, the lrmd daemon now unsets the "NOTIFY_SOCKET" variable
in the described circumstances, and these error messages are no longer
logged. (BZ#1150184)

* Previously, specifying a remote guest node as a part of a group resource
in a Pacemaker cluster caused the node to stop working. This update adds
support for remote guests in Pacemaker group resources, and the described
problem no longer occurs. (BZ#1168637)

* When a resource in a Pacemaker cluster failed to start, Pacemaker updated
the resource's last failure time and incremented its fail count even if the
"on-fail=ignore" option was used. This in some cases caused unintended
resource migrations when a resource start failure occurred. Now, Pacemaker
does not update the fail count when "on-fail=ignore" is used. As a result,
the failure is displayed in the cluster status output, but is properly
ignored and thus does not cause resource migration. (BZ#1200849)

* Previously, Pacemaker supported semicolon characters (";") as delimiters
when parsing the pcmk_host_map string, but not when parsing the
pcmk_host_list string. To ensure consistent user experience, semicolons are
now supported as delimiters for parsing pcmk_host_list, as well.
(BZ#1206232)

In addition, this update adds the following enhancements:

* If a Pacemaker location constraint has the "resource-discovery=never"
option, Pacemaker now does not attempt to determine whether a specified
service is running on the specified node. In addition, if multiple location
constraints for a given resource specify "resource-discovery=exclusive",
then Pacemaker attempts resource discovery only on the nodes specified in
those constraints. This allows Pacemaker to skip resource discovery on
nodes where attempting the operation would lead to error or other
undesirable behavior. (BZ#1108853)

* The procedure of configuring fencing for redundant power supplies has
been simplified in order to prevent multiple nodes accessing cluster
resources at the same time and thus causing data corruption. For further
information, see the "Fencing: Configuring STONITH" chapter of the High
Availability Add-On Reference manual. (BZ#1206647)

* The output of the "crm_mon" and "pcs_status" commands has been modified
to be clearer and more concise, and thus easier to read when reporting
the status of a Pacemaker cluster with a large number of remote nodes and
cloned resources. (BZ#1115840)

All pacemaker users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2383</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1867</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152383"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152393" severity="medium">
    <xccdf:title>RHSA-2015:2393: wireshark security, bug fix, and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The wireshark packages contain a network protocol analyzer used to capture
and browse the traffic running on a computer network.

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2015-2188, CVE-2015-2189, CVE-2015-2191,
CVE-2015-3810, CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2014-8710,
CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2015-0562,
CVE-2015-0563, CVE-2015-0564, CVE-2015-3182, CVE-2015-6243, CVE-2015-6244,
CVE-2015-6245, CVE-2015-6246, CVE-2015-6248)

The CVE-2015-3182 issue was discovered by Martin Žember of Red Hat.

The wireshark packages have been upgraded to upstream version 1.10.14,
which provides a number of bug fixes and enhancements over the previous
version. (BZ#1238676)

This update also fixes the following bug:

* Prior to this update, when using the tshark utility to capture packets
over the interface, tshark failed to create output files in the .pcap
format even if it was specified using the "-F" option. This bug has been
fixed, the "-F" option is now honored, and the result saved in the .pcap
format as expected. (BZ#1227199)

In addition, this update adds the following enhancement:

* Previously, wireshark included only microseconds in the .pcapng format.
With this update, wireshark supports nanosecond time stamp precision to
allow for more accurate time stamps. (BZ#1213339)

All wireshark users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. All running instances of
Wireshark must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2393</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8710</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8711</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8712</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8713</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8714</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0562</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0563</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-0564</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2191</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3182</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3810</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3811</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3812</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3813</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6243</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6244</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6245</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6246</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-6248</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152393"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152401" severity="low">
    <xccdf:title>RHSA-2015:2401: grub2 security, bug fix, and enhancement update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The grub2 packages provide version 2 of the Grand Unified Bootloader
(GRUB), a highly configurable and customizable bootloader with modular
architecture. The packages support a variety of kernel formats, file
systems, computer architectures, and hardware devices.

It was discovered that grub2 builds for EFI systems contained modules that
were not suitable to be loaded in a Secure Boot environment. An attacker
could use this flaw to circumvent the Secure Boot mechanisms and load
non-verified code. Attacks could use the boot menu if no password was set,
or the grub2 configuration file if the attacker has root privileges on the
system. (CVE-2015-5281)

This update also fixes the following bugs:

* In one of the earlier updates, GRUB2 was modified to escape forward slash
(/) characters in several different places. In one of these places, the
escaping was unnecessary and prevented certain types of kernel command-line
arguments from being passed to the kernel correctly. With this update,
GRUB2 no longer escapes the forward slash characters in the mentioned
place, and the kernel command-line arguments work as expected. (BZ#1125404)

* Previously, GRUB2 relied on a timing mechanism provided by legacy
hardware, but not by the Hyper-V Gen2 hypervisor, to calibrate its timer
loop. This prevented GRUB2 from operating correctly on Hyper-V Gen2.
This update modifies GRUB2 to use a different mechanism on Hyper-V Gen2 to
calibrate the timing. As a result, Hyper-V Gen2 hypervisors now work as
expected. (BZ#1150698)

* Prior to this update, users who manually configured GRUB2 to use the
built-in GNU Privacy Guard (GPG) verification observed the following error
on boot:

    alloc magic is broken at [addr]: [value] Aborted.

Consequently, the boot failed. The GRUB2 built-in GPG verification has been
modified to no longer free the same memory twice. As a result, the
mentioned error no longer occurs. (BZ#1167977)

* Previously, the system sometimes did not recover after terminating
unexpectedly and failed to reboot. To fix this problem, the GRUB2 packages
now enforce file synchronization when creating the GRUB2 configuration
file, which ensures that the required configuration files are written to
disk. As a result, the system now reboots successfully after crashing.
(BZ#1212114)

* Previously, if an unconfigured network driver instance was selected and
configured when the GRUB2 bootloader was loaded on a different instance,
GRUB2 did not receive notifications of the Address Resolution Protocol
(ARP) replies. Consequently, GRUB2 failed with the following error message:

    error: timeout: could not resolve hardware address.

With this update, GRUB2 selects the network driver instance from which it
was loaded. As a result, ARP packets are processed correctly. (BZ#1257475)

In addition, this update adds the following enhancement:

* Sorting of GRUB2 boot menu has been improved. GRUB2 now uses the
rpmdevtools package to sort available kernels and the configuration file is
being generated correctly with the most recent kernel version listed at the
top. (BZ#1124074)

All grub2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2401</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5281</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152401"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152411" severity="high">
    <xccdf:title>RHSA-2015:2411: kernel-rt security, bug fix, and enhancement update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel-rt packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's file system implementation
handled rename operations in which the source was inside and the
destination was outside of a bind mount. A privileged user inside a
container could use this flaw to escape the bind mount and, potentially,
escalate their privileges on the system. (CVE-2015-2925, Important)

* A race condition flaw was found in the way the Linux kernel's IPC
subsystem initialized certain fields in an IPC object structure that were
later used for permission checking before inserting the object into a
globally visible list. A local, unprivileged user could potentially use
this flaw to elevate their privileges on the system. (CVE-2015-7613,
Important)

* It was found that the Linux kernel memory resource controller's (memcg)
handling of OOM (out of memory) conditions could lead to deadlocks.
An attacker able to continuously spawn new processes within a single
memory-constrained cgroup during an OOM event could use this flaw to lock
up the system. (CVE-2014-8171, Moderate)

* A race condition flaw was found between the chown and execve system
calls. When changing the owner of a setuid user binary to root, the race
condition could momentarily make the binary setuid root. A local,
unprivileged user could potentially use this flaw to escalate their
privileges on the system. (CVE-2015-3339, Moderate)

* A flaw was discovered in the way the Linux kernel's TTY subsystem handled
the tty shutdown phase. A local, unprivileged user could use this flaw to
cause a denial of service on the system by holding a reference to the ldisc
lock during tty shutdown, causing a deadlock. (CVE-2015-4170, Moderate)

* A NULL pointer dereference flaw was found in the SCTP implementation.
A local user could use this flaw to cause a denial of service on the system
by triggering a kernel panic when creating multiple sockets in parallel
while the system did not have the SCTP module loaded. (CVE-2015-5283,
Moderate)

* A flaw was found in the way the Linux kernel's Crypto subsystem handled
automatic loading of kernel modules. A local user could use this flaw to
load any installed kernel module, and thus increase the attack surface of
the running kernel. (CVE-2013-7421, CVE-2014-9644, Low)

* An information leak flaw was found in the way the Linux kernel changed
certain segment registers and thread-local storage (TLS) during a context
switch. A local, unprivileged user could use this flaw to leak the user
space TLS base address of an arbitrary process. (CVE-2014-9419, Low)

* A flaw was found in the way the Linux kernel handled the securelevel
functionality after performing a kexec operation. A local attacker could
use this flaw to bypass the security mechanism of the
securelevel/secureboot combination. (CVE-2015-7837, Low)

Red Hat would like to thank Linn Crosetto of HP for reporting the
CVE-2015-7837 issue. The CVE-2015-5283 issue was discovered by Ji Jianwen
from Red Hat engineering.

The kernel-rt packages have been upgraded to version 3.10.0-326.rt56.204,
which provides a number of bug fixes and enhancements. (BZ#1201915,
BZ#1211724)

This update also fixes several bugs and adds multiple enhancements.
Refer to the following Red Hat Knowledgebase article for information on the
most significant of these changes:

https://access.redhat.com/articles/2055783

All kernel-rt users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2411</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2013-7421</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8171</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9419</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-9644</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3339</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4170</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5283</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7837</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152411"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152417" severity="medium">
    <xccdf:title>RHSA-2015:2417: autofs security, bug fix and enhancement update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The autofs utility controls the operation of the automount daemon. The
daemon automatically mounts file systems when in use and unmounts them when
they are not busy.

It was found that program-based automounter maps that used interpreted
languages such as Python used standard environment variables to locate
and load modules of those languages. A local attacker could potentially use
this flaw to escalate their privileges on the system. (CVE-2014-8169)

Note: This issue has been fixed by adding the "AUTOFS_" prefix to the
affected environment variables so that they are not used to subvert the
system. A configuration option ("force_standard_program_map_env") to
override this prefix and to use the environment variables without the
prefix has been added. In addition, warnings have been added to the manual
page and to the installed configuration file. Now, by default the standard
variables of the program map are provided only with the prefix added to
its name.

Red Hat would like to thank the Georgia Institute of Technology for
reporting this issue.

Notably, this update fixes the following bugs:

* When the "ls *" command was run in the root of an indirect mount, autofs
attempted to literally mount the wildcard character (*) causing it to be
added to the negative cache. If done before a valid mount, autofs then
failed on further mount attempts inside the mount point, valid or not. This
has been fixed, and wildcard map entries now function in the described
situation. (BZ#1166457)

* When autofs encountered a syntax error consisting of a duplicate entry in
a multimap entry, it reported an error and did not mount the map entry.
With this update, autofs has been amended to report the problem in the log
to alert the system administrator and use the last seen instance of the
duplicate entry rather than fail. (BZ#1205600)

* In the ldap and sss lookup modules, the map reading functions did not
distinguish between the "no entry found" and "service not available"
errors. Consequently, when the "service not available" response was
returned from a master map read, autofs did not update the mounts.
An "entry not found" return does not prevent the map update, so the ldap
and sss lookup modules were updated to distinguish between these two
returns and now work as expected. (BZ#1233065)

In addition, this update adds the following enhancement:

* The description of the configuration parameter map_hash_table_size was
missing from the autofs.conf(5) man page and its description in the
configuration file comments was insufficient. A description of the
parameter has been added to autofs.conf(5), and the configuration file
comments have been updated. (BZ#1238573)

All autofs users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2417</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8169</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152417"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152455" severity="low">
    <xccdf:title>RHSA-2015:2455: unbound security and bug fix update (Low)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The unbound packages provide a validating, recursive, and caching DNS or
DNSSEC resolver.

A denial of service flaw was found in unbound that an attacker could use to
trick the unbound resolver into following an endless loop of delegations,
consuming an excessive amount of resources. (CVE-2014-8602)

This update also fixes the following bugs:

* Prior to this update, there was a mistake in the time configuration in
the cron job invoking unbound-anchor to update the root zone key.
Consequently, unbound-anchor was invoked once a month instead of every day,
thus not complying with RFC 5011. The cron job has been replaced with a
systemd timer unit that is invoked on a daily basis. Now, the root zone key
validity is checked daily at a random time within a 24-hour window, and
compliance with RFC 5011 is ensured. (BZ#1180267)

* Previously, the unbound packages were installing their configuration file
for the systemd-tmpfiles utility into the /etc/tmpfiles.d/ directory. As a 
consequence, changes to unbound made by the administrator in 
/etc/tmpfiles.d/ could be overwritten on package reinstallation or update. 
To fix this bug, unbound has been amended to install the configuration file
into the /usr/lib/tmpfiles.d/ directory. As a result, the system 
administrator's configuration in /etc/tmpfiles.d/ is preserved, including 
any changes, on package reinstallation or update. (BZ#1180995)

* The unbound server default configuration included validation of DNS
records using the DNSSEC Look-aside Validation (DLV) registry. The Internet
Systems Consortium (ISC) plans to deprecate the DLV registry service as no
longer needed, and unbound could execute unnecessary steps. Therefore, the 
use of the DLV registry has been removed from the unbound server default 
configuration. Now, unbound does not try to perform DNS records validation 
using the DLV registry. (BZ#1223339)

All unbound users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2455</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2014-8602</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152455"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152504" severity="medium">
    <xccdf:title>RHSA-2015:2504: libreport security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>libreport provides an API for reporting different problems in applications
to different bug targets, such as Bugzilla, FTP, and Trac. ABRT (Automatic
Bug Reporting Tool) uses libreport.

It was found that ABRT may have exposed unintended information to Red Hat
Bugzilla during crash reporting. A bug in the libreport library caused
changes made by a user in files included in a crash report to be discarded.
As a result, Red Hat Bugzilla attachments may contain data that was not
intended to be made public, including host names, IP addresses, or command
line options. (CVE-2015-5302)

This flaw did not affect default installations of ABRT on Red Hat
Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature
can however be enabled, potentially impacting modified ABRT instances.

As a precaution, Red Hat has identified bugs filed by such non-default Red
Hat Enterprise Linux users of ABRT and marked them private.

This issue was discovered by Bastien Nocera of Red Hat.

All users of libreport are advised to upgrade to these updated packages,
which corrects this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5302</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152504"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152505" severity="medium">
    <xccdf:title>RHSA-2015:2505: abrt and libreport security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. libreport provides an API for reporting different problems
in applications to different bug targets, such as Bugzilla, FTP, and Trac.

It was found that the ABRT debug information installer
(abrt-action-install-debuginfo-to-abrt-cache) did not use temporary
directories in a secure way. A local attacker could use the flaw to create
symbolic links and files at arbitrary locations as the abrt user.
(CVE-2015-5273)

It was discovered that the kernel-invoked coredump processor provided by
ABRT did not handle symbolic links correctly when writing core dumps of
ABRT programs to the ABRT dump directory (/var/spool/abrt). A local
attacker with write access to an ABRT problem directory could use this flaw
to escalate their privileges. (CVE-2015-5287)

It was found that ABRT may have exposed unintended information to Red Hat
Bugzilla during crash reporting. A bug in the libreport library caused
changes made by a user in files included in a crash report to be discarded.
As a result, Red Hat Bugzilla attachments may contain data that was not
intended to be made public, including host names, IP addresses, or command
line options. (CVE-2015-5302)

This flaw did not affect default installations of ABRT on Red Hat
Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature
can however be enabled, potentially impacting modified ABRT instances.

As a precaution, Red Hat has identified bugs filed by such non-default Red
Hat Enterprise Linux users of ABRT and marked them private.

Red Hat would like to thank Philip Pettersson of Samsung for reporting the
CVE-2015-5273 and CVE-2015-5287 issues. The CVE-2015-5302 issue was
discovered by Bastien Nocera of Red Hat.

All users of abrt and libreport are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2505</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5273</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5287</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5302</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152505"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152519" severity="high">
    <xccdf:title>RHSA-2015:2519: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-4513, CVE-2015-7189, CVE-2015-7197, CVE-2015-7198,
CVE-2015-7199, CVE-2015-7200)

A same-origin policy bypass flaw was found in the way Thunderbird handled
certain cross-origin resource sharing (CORS) requests. A web page
containing malicious content could cause Thunderbird to disclose sensitive
information. (CVE-2015-7193)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message because JavaScript is disabled by default for mail
messages. However, they could be exploited in other ways in Thunderbird
(for example, by viewing the full remote content of an RSS feed).

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Christian Holler, David Major, Jesse Ruderman, Tyson
Smith, Boris Zbarsky, Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff
Walden, Gary Kwong, Looben Yang, Shinto K Anto, Ronald Crane, and Ehsan
Akhgari as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 38.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 38.4.0, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2519</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4513</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7193</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7198</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7199</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7200</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152519"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152521" severity="high">
    <xccdf:title>RHSA-2015:2521: jakarta-commons-collections security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Jakarta/Apache Commons Collections library provides new interfaces,
implementations, and utilities to extend the features of the Java
Collections Framework.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

With this update, deserialization of certain classes in the
commons-collections library is no longer allowed. Applications that require
those classes to be deserialized can use the system property
"org.apache.commons.collections.enableUnsafeSerialization" to re-enable
their deserialization.

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of jakarta-commons-collections are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.
All running applications using the commons-collections library must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7501</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152521"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152522" severity="high">
    <xccdf:title>RHSA-2015:2522: apache-commons-collections security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Apache Commons Collections library provides new interfaces,
implementations, and utilities to extend the features of the Java
Collections Framework.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

With this update, deserialization of certain classes in the
commons-collections library is no longer allowed. Applications that require
those classes to be deserialized can use the system property
"org.apache.commons.collections.enableUnsafeSerialization" to re-enable
their deserialization.

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of apache-commons-collections are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.
All running applications using the commons-collections library must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7501</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152522"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152549" severity="medium">
    <xccdf:title>RHSA-2015:2549: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

Several denial of service flaws were found in libxml2, a library providing
support for reading, modifying, and writing XML and HTML files. A remote
attacker could provide a specially crafted XML or HTML file that, when
processed by an application using libxml2, would cause that application to
use an excessive amount of CPU, leak potentially sensitive information, or
in certain cases crash the application. (CVE-2015-5312, CVE-2015-7497,
CVE-2015-7498, CVE-2015-7499, CVE-2015-7500 CVE-2015-7941, CVE-2015-7942,
CVE-2015-8241, CVE-2015-8242, CVE-2015-8317, BZ#1213957, BZ#1281955)

Red Hat would like to thank the GNOME project for reporting CVE-2015-7497,
CVE-2015-7498, CVE-2015-7499, CVE-2015-7500, CVE-2015-8241, CVE-2015-8242,
and CVE-2015-8317. Upstream acknowledges Kostya Serebryany of Google as the
original reporter of CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, and
CVE-2015-7500; Hugh Davenport as the original reporter of CVE-2015-8241 and
CVE-2015-8242; and Hanno Boeck as the original reporter of CVE-2015-8317.

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2549</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7941</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8317</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8710</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152549"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152550" severity="medium">
    <xccdf:title>RHSA-2015:2550: libxml2 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

Several denial of service flaws were found in libxml2, a library providing
support for reading, modifying, and writing XML and HTML files. A remote
attacker could provide a specially crafted XML or HTML file that, when
processed by an application using libxml2, would cause that application to
use an excessive amount of CPU, leak potentially sensitive information, or
in certain cases crash the application. (CVE-2015-1819, CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, CVE-2015-7500 CVE-2015-7941,
CVE-2015-7942, CVE-2015-8241, CVE-2015-8242, CVE-2015-8317, BZ#1213957,
BZ#1281955)

Red Hat would like to thank the GNOME project for reporting CVE-2015-7497,
CVE-2015-7498, CVE-2015-7499, CVE-2015-7500, CVE-2015-8241, CVE-2015-8242,
and CVE-2015-8317. Upstream acknowledges Kostya Serebryany of Google as the
original reporter of CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, and
CVE-2015-7500; Hugh Davenport as the original reporter of CVE-2015-8241 and
CVE-2015-8242; and Hanno Boeck as the original reporter of CVE-2015-8317.
The CVE-2015-1819 issue was discovered by Florian Weimer of Red Hat
Product Security.

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2550</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-1819</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5312</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7497</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7498</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7499</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7500</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7941</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7942</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8241</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8242</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8317</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8710</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152550"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152552" severity="high">
    <xccdf:title>RHSA-2015:2552: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the x86 ISA (Instruction Set Architecture) is prone to
a denial of service attack inside a virtualized environment in the form of
an infinite loop in the microcode due to the way (sequential) delivering of
benign exceptions such as #AC (alignment check exception) and #DB (debug
exception) is handled. A privileged user inside a guest could use these
flaws to create denial of service conditions on the host kernel.
(CVE-2015-5307, CVE-2015-8104, Important)

Red Hat would like to thank Ben Serebrin of Google Inc. for reporting the
CVE-2015-5307 issue.

This update also fixes the following bugs:

* On Intel Xeon v5 platforms, the processor frequency was always tied to
the highest possible frequency. Switching p-states on these client
platforms failed. This update sets the idle frequency, busy frequency, and
processor frequency values by determining the range and adjusting the
minimal and maximal percent limit values. Now, switching p-states on the
aforementioned client platforms proceeds successfully. (BZ#1273926)

* Due to a validation error of in-kernel memory-mapped I/O (MMIO) tracing,
a VM became previously unresponsive when connected to Red Hat Enterprise
Virtualization Hypervisor. The provided patch fixes this bug by dropping
the check in MMIO handler, and a VM continues running as expected.
(BZ#1275150)

* Due to retry-able command errors, the NVMe driver previously leaked I/O
descriptors and DMA mappings. As a consequence, the kernel could become
unresponsive during the hot-unplug operation if a driver was removed.
This update fixes the driver memory leak bug on command retries, and the
kernel no longer hangs in this situation. (BZ#1279792)

* The hybrid_dma_data() function was not initialized before use, which
caused an invalid memory access when hot-plugging a PCI card. As a
consequence, a kernel oops occurred. The provided patch makes sure
hybrid_dma_data() is initialized before use, and the kernel oops no longer
occurs in this situation. (BZ#1279793)

* When running PowerPC (PPC) KVM guests and the host was experiencing a lot
of page faults, for example because it was running low on memory, the host
sometimes triggered an incorrect kind of interrupt in the guest: a data
storage exception instead of a data segment exception. This caused a kernel
panic of the PPC KVM guest. With this update, the host kernel synthesizes a
segment fault if the corresponding Segment Lookaside Buffer (SLB) lookup
fails, which prevents the kernel panic from occurring. (BZ#1281423)

* The kernel accessed an incorrect area of the khugepaged process causing
Logical Partitioning (LPAR) to become unresponsive, and an oops occurred in
medlp5. The backported upstream patch prevents an LPAR hang, and the oops
no longer occurs. (BZ#1281424)

* When the sctp module was loaded and a route to an association endpoint
was removed after receiving an Out-of-The-Blue (OOTB) chunk but before
incrementing the "dropped because of missing route" SNMP statistic, a Null
Pointer Dereference kernel panic previously occurred. This update fixes the
race condition between OOTB response and route removal. (BZ#1281426)

* The cpuscaling test of the certification test suite previously failed due
to a rounding bug in the intel-pstate driver. This bug has been fixed and
the cpuscaling test now passes. (BZ#1281491)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2552</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8104</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152552"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152561" severity="medium">
    <xccdf:title>RHSA-2015:2561: git security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Git is a distributed revision control system with a decentralized
architecture. As opposed to centralized version control systems with a
client-server model, Git ensures that each working copy of a Git repository
is an exact copy with complete revision history. This not only allows the
user to work on and contribute to projects without the need to have
permission to push the changes to their official repositories, but also
makes it possible for the user to work with no network connection.

A flaw was found in the way the git-remote-ext helper processed certain
URLs. If a user had Git configured to automatically clone submodules from
untrusted repositories, an attacker could inject commands into the URL of a
submodule, allowing them to execute arbitrary code on the user's system.
(BZ#1269794)

All git users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2561</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7545</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152561"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152594" severity="medium">
    <xccdf:title>RHSA-2015:2594: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

It was discovered that the png_get_PLTE() and png_set_PLTE() functions of
libpng did not correctly calculate the maximum palette sizes for bit depths
of less than 8. In case an application tried to use these functions in
combination with properly calculated palette sizes, this could lead to a
buffer overflow or out-of-bounds reads. An attacker could exploit this to
cause a crash or potentially execute arbitrary code by tricking an
unsuspecting user into processing a specially crafted PNG image. However,
the exact impact is dependent on the application using the library.
(CVE-2015-8126, CVE-2015-8472)

An array-indexing error was discovered in the png_convert_to_rfc1123()
function of libpng. An attacker could possibly use this flaw to cause an
out-of-bounds read by tricking an unsuspecting user into processing a
specially crafted PNG image. (CVE-2015-7981)

All libpng users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2594</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152594"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152595" severity="medium">
    <xccdf:title>RHSA-2015:2595: libpng12 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng12 packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

It was discovered that the png_get_PLTE() and png_set_PLTE() functions of
libpng did not correctly calculate the maximum palette sizes for bit depths
of less than 8. In case an application tried to use these functions in
combination with properly calculated palette sizes, this could lead to a
buffer overflow or out-of-bounds reads. An attacker could exploit this to
cause a crash or potentially execute arbitrary code by tricking an
unsuspecting user into processing a specially crafted PNG image. However,
the exact impact is dependent on the application using the library.
(CVE-2015-8126, CVE-2015-8472)

An array-indexing error was discovered in the png_convert_to_rfc1123()
function of libpng. An attacker could possibly use this flaw to cause an
out-of-bounds read by tricking an unsuspecting user into processing a
specially crafted PNG image. (CVE-2015-7981)

All libpng12 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2595</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7981</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152595"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152596" severity="medium">
    <xccdf:title>RHSA-2015:2596: libpng security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

It was discovered that the png_get_PLTE() and png_set_PLTE() functions of
libpng did not correctly calculate the maximum palette sizes for bit depths
of less than 8. In case an application tried to use these functions in
combination with properly calculated palette sizes, this could lead to a
buffer overflow or out-of-bounds reads. An attacker could exploit this to
cause a crash or potentially execute arbitrary code by tricking an
unsuspecting user into processing a specially crafted PNG image. However,
the exact impact is dependent on the application using the library.
(CVE-2015-8126, CVE-2015-8472)

All libpng users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2596</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152596"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152616" severity="medium">
    <xccdf:title>RHSA-2015:2616: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A memory leak vulnerability was found in the way OpenSSL parsed PKCS#7 and
CMS data. A remote attacker could use this flaw to cause an application
that parses PKCS#7 or CMS data from untrusted sources to use an excessive
amount of memory and possibly crash. (CVE-2015-3195)

All openssl users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2616</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3195</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152616"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152617" severity="medium">
    <xccdf:title>RHSA-2015:2617: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A NULL pointer derefernce flaw was found in the way OpenSSL verified
signatures using the RSA PSS algorithm. A remote attacked could possibly
use this flaw to crash a TLS/SSL client using OpenSSL, or a TLS/SSL server
using OpenSSL if it enabled client authentication. (CVE-2015-3194)

A memory leak vulnerability was found in the way OpenSSL parsed PKCS#7 and
CMS data. A remote attacker could use this flaw to cause an application
that parses PKCS#7 or CMS data from untrusted sources to use an excessive
amount of memory and possibly crash. (CVE-2015-3195)

A race condition flaw, leading to a double free, was found in the way
OpenSSL handled pre-shared key (PSK) identify hints. A remote attacker
could use this flaw to crash a multi-threaded SSL/TLS client using
OpenSSL. (CVE-2015-3196)

All openssl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2617</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3194</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3195</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3196</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152617"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152619" severity="medium">
    <xccdf:title>RHSA-2015:2619: libreoffice security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>LibreOffice is an open source, community-developed office productivity
suite. It includes key desktop applications, such as a word processor, a
spreadsheet, a presentation manager, a formula editor, and a drawing
program. LibreOffice replaces OpenOffice and provides a similar but
enhanced and extended office suite.

It was discovered that LibreOffice did not properly restrict automatic link
updates. By tricking a victim into opening specially crafted documents, an
attacker could possibly use this flaw to disclose contents of files
accessible by the victim. (CVE-2015-4551)

An integer underflow flaw leading to a heap-based buffer overflow when
parsing PrinterSetup data was discovered. By tricking a user into opening a
specially crafted document, an attacker could possibly exploit this flaw to
execute arbitrary code with the privileges of the user opening the file.
(CVE-2015-5212)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way LibreOffice processed certain Microsoft Word .doc files.
By tricking a user into opening a specially crafted Microsoft Word .doc
document, an attacker could possibly use this flaw to execute arbitrary
code with the privileges of the user opening the file. (CVE-2015-5213)

It was discovered that LibreOffice did not properly sanity check bookmark
indexes. By tricking a user into opening a specially crafted document, an
attacker could possibly use this flaw to execute arbitrary code with the
privileges of the user opening the file. (CVE-2015-5214)

All libreoffice users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2619</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4551</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5214</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152619"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152623" severity="medium">
    <xccdf:title>RHSA-2015:2623: grub2 security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The grub2 packages provide version 2 of the Grand Unified Bootloader
(GRUB), a highly configurable and customizable bootloader with modular
architecture. The packages support a variety of kernel formats, file
systems, computer architectures, and hardware devices.

A flaw was found in the way the grub2 handled backspace characters entered
in username and password prompts. An attacker with access to the system
console could use this flaw to bypass grub2 password protection and gain
administrative access to the system. (CVE-2015-8370)

This update also fixes the following bug:

* When upgrading from Red Hat Enterprise Linux 7.1 and earlier, a
configured boot password was not correctly migrated to the newly introduced
user.cfg configuration files. This could possibly prevent system
administrators from changing grub2 configuration during system boot even if
they provided the correct password. This update corrects the password
migration script and the incorrectly generated user.cfg file. (BZ#1290089)

All grub2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For this update to take
effect on BIOS-based machines, grub2 needs to be reinstalled as documented
in the "Reinstalling GRUB 2 on BIOS-Based Machines" section of the Red Hat
Enterprise Linux 7 System Administrator's Guide linked to in the References
section. No manual action is needed on UEFI-based machines.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2623</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8370</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152623"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152636" severity="high">
    <xccdf:title>RHSA-2015:2636: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's file system implementation
handled rename operations in which the source was inside and the
destination was outside of a bind mount. A privileged user inside a
container could use this flaw to escape the bind mount and, potentially,
escalate their privileges on the system. (CVE-2015-2925, Important)

* It was found that the x86 ISA (Instruction Set Architecture) is prone to
a denial of service attack inside a virtualized environment in the form of
an infinite loop in the microcode due to the way (sequential) delivering of
benign exceptions such as #AC (alignment check exception) and #DB (debug
exception) is handled. A privileged user inside a guest could use these
flaws to create denial of service conditions on the host kernel.
(CVE-2015-5307, CVE-2015-8104, Important)

* A race condition flaw was found in the way the Linux kernel's IPC
subsystem initialized certain fields in an IPC object structure that were
later used for permission checking before inserting the object into a
globally visible list. A local, unprivileged user could potentially use
this flaw to elevate their privileges on the system. (CVE-2015-7613,
Important)

* It was found that the Linux kernel's keys subsystem did not correctly
garbage collect uninstantiated keyrings. A local attacker could use this
flaw to crash the system or, potentially, escalate their privileges on
the system. (CVE-2015-7872, Important)

Red Hat would like to thank Ben Serebrin of Google Inc. for reporting the
CVE-2015-5307 issue.

This update also fixes the following bugs:

* Previously, Human Interface Device (HID) ran a report on an unaligned
buffer, which could cause a page fault interrupt and an oops when the end
of the report was read. This update fixes this bug by padding the end of
the report with extra bytes, so the reading of the report never crosses a
page boundary. As a result, a page fault and subsequent oops no longer
occur. (BZ#1268203)

* The NFS client was previously failing to detect a directory loop for some
NFS server directory structures. This failure could cause NFS inodes to
remain referenced after attempting to unmount the file system, leading to a
kernel crash. Loop checks have been added to VFS, which effectively
prevents this problem from occurring. (BZ#1272858)

* Due to a race whereby the nfs_wb_pages_cancel() and
nfs_commit_release_pages() calls both removed a request from the nfs_inode
struct type, the kernel panicked with negative nfs_inode.npages count.
The provided upstream patch performs the required serialization by holding
the inode i_lock over the check of PagePrivate and locking the request,
thus preventing the race and kernel panic from occurring. (BZ#1273721)

* Due to incorrect URB_ISO_ASAP semantics, playing an audio file using a
USB sound card could previously fail for some hardware configurations.
This update fixes the bug, and playing audio from a USB sound card now
works as expected. (BZ#1273916)

* Inside hugetlb, region data structures were protected by a combination of
a memory map semaphore and a single hugetlb instance mutex. However, a
page-fault scalability improvement backported to the kernel on previous
releases removed the single hugetlb instance mutex and introduced a new
mutex table, making the locking combination insufficient, leading to
possible race windows that could cause corruption and undefined behavior.
This update fixes the problem by introducing a required spinlock to the
region tracking functions for proper serialization. The problem only
affects software using huge pages through hugetlb interface. (BZ#1274599)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2636</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-2925</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5307</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7613</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7872</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8104</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152636"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152655" severity="high">
    <xccdf:title>RHSA-2015:2655: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND processed certain
records with malformed class attributes. A remote attacker could use this
flaw to send a query to request a cached record with a malformed class
attribute that would cause named functioning as an authoritative or
recursive server to crash. (CVE-2015-8000)

Note: This issue affects authoritative servers as well as recursive
servers, however authoritative servers are at limited risk if they perform
authentication when making recursive queries to resolve addresses for
servers listed in NS RRSETs.

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2655</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152655"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152656" severity="high">
    <xccdf:title>RHSA-2015:2656: bind security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND processed certain
records with malformed class attributes. A remote attacker could use this
flaw to send a query to request a cached record with a malformed class
attribute that would cause named functioning as an authoritative or
recursive server to crash. (CVE-2015-8000)

Note: This issue affects authoritative servers as well as recursive
servers, however authoritative servers are at limited risk if they perform
authentication when making recursive queries to resolve addresses for
servers listed in NS RRSETs.

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2656</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152656"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152657" severity="high">
    <xccdf:title>RHSA-2015:2657: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-7201, CVE-2015-7205, CVE-2015-7210, CVE-2015-7212,
CVE-2015-7213, CVE-2015-7222)

A flaw was found in the way Firefox handled content using the 'data:' and
'view-source:' URIs. An attacker could use this flaw to bypass the
same-origin policy and read data from cross-site URLs and local files.
(CVE-2015-7214)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Andrei Vaida, Jesse Ruderman, Bob Clary, Looben Yang,
Abhishek Arya, Ronald Crane, Gerald Squelart, and Tsubasa Iinuma as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2657</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7210</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7214</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7222</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152657"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152658" severity="high">
    <xccdf:title>RHSA-2015:2658: bind97 security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND processed certain
records with malformed class attributes. A remote attacker could use this
flaw to send a query to request a cached record with a malformed class
attribute that would cause named functioning as an authoritative or
recursive server to crash. (CVE-2015-8000)

Note: This issue affects authoritative servers as well as recursive
servers, however authoritative servers are at limited risk if they perform
authentication when making recursive queries to resolve addresses for
servers listed in NS RRSETs.

Red Hat would like to thank ISC for reporting this issue.

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2658</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8000</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152658"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152671" severity="high">
    <xccdf:title>RHSA-2015:2671: jakarta-commons-collections security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Jakarta/Apache Commons Collections library provides new interfaces,
implementations, and utilities to extend the features of the Java
Collections Framework.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

With this update, deserialization of certain classes in the
commons-collections library is no longer allowed. Applications that require
those classes to be deserialized can use the system property
"org.apache.commons.collections.enableUnsafeSerialization" to re-enable
their deserialization.

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of jakarta-commons-collections are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.
All running applications using the commons-collections library must be
restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2671</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7501</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152671"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20152694" severity="high">
    <xccdf:title>RHSA-2015:2694: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

A heap-based buffer overflow flaw was discovered in the way QEMU's AMD
PC-Net II Ethernet Controller emulation received certain packets in
loopback mode. A privileged user (with the CAP_SYS_RAWIO capability) inside
a guest could use this flaw to crash the host QEMU process (resulting in
denial of service) or, potentially, execute arbitrary code with privileges
of the host QEMU process. (CVE-2015-7504)

A buffer overflow flaw was found in the way QEMU's AMD PC-Net II emulation
validated certain received packets from a remote host in non-loopback mode.
A remote, unprivileged attacker could potentially use this flaw to execute
arbitrary code on the host with the privileges of the QEMU process.
Note that to exploit this flaw, the guest network interface must have a
large MTU limit. (CVE-2015-7512)

Red Hat would like to thank Qinghao Tang of QIHU 360 Marvel Team and Ling
Liu of Qihoo 360 Inc. for reporting the CVE-2015-7504 issue, and Ling Liu
of Qihoo 360 Inc. for reporting the CVE-2015-7512 issue. The CVE-2015-7512
issue was independently discovered by Jason Wang of Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2015:2694</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7504</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7512</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20152694"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160001" severity="high">
    <xccdf:title>RHSA-2016:0001: thunderbird security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2015-7201, CVE-2015-7205, CVE-2015-7212, CVE-2015-7213)

A flaw was found in the way Thunderbird handled content using the 'data:'
and 'view-source:' URIs. An attacker could use this flaw to bypass the
same-origin policy and read data from cross-site URLs and local files.
(CVE-2015-7214)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Andrei Vaida, Jesse Ruderman, Bob Clary, Abhishek
Arya, Ronald Crane, and Tsubasa Iinuma as the original reporters of these
issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 38.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 38.5.0, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0001</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7201</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7205</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7212</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7213</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7214</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160001"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160005" severity="medium">
    <xccdf:title>RHSA-2016:0005: rpcbind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The rpcbind utility is a server that converts RPC program numbers into
universal addresses. It must be running on the host to be able to make RPC
calls on a server on that machine.

A use-after-free flaw related to the PMAP_CALLIT operation and TCP/UDP
connections was discovered in rpcbind. A remote attacker could possibly
exploit this flaw to crash the rpcbind service by performing a series of
UDP and TCP calls. (CVE-2015-7236)

All rpcbind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. If the rpcbind service
is running, it will be automatically restarted after installing this
update.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0005</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7236</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160005"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160006" severity="medium">
    <xccdf:title>RHSA-2016:0006: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the LDAP server provided by the AD DC
in the Samba process daemon. A remote attacker could exploit this flaw by
sending a specially crafted packet, which could cause the server to consume
an excessive amount of memory and crash. (CVE-2015-7540)

Multiple buffer over-read flaws were found in the way Samba handled
malformed inputs in certain encodings. An authenticated, remote attacker
could possibly use these flaws to disclose portions of the server memory.
(CVE-2015-5330)

A man-in-the-middle vulnerability was found in the way "connection signing"
was implemented by Samba. A remote attacker could use this flaw to
downgrade an existing Samba client connection and force the use of plain
text. (CVE-2015-5296)

A missing access control flaw was found in Samba. A remote, authenticated
attacker could use this flaw to view the current snapshot on a Samba share,
despite not having DIRECTORY_LIST access rights. (CVE-2015-5299)

An access flaw was found in the way Samba verified symbolic links when
creating new files on a Samba share. A remote attacker could exploit this
flaw to gain access to files outside of Samba's share path. (CVE-2015-5252)

Red Hat would like to thank the Samba project for reporting these issues.
Upstream acknowledges Stefan Metzmacher of the Samba Team and Sernet.de as
the original reporters of CVE-2015-5296, partha@exablox.com as the original
reporter of CVE-2015-5299, Jan "Yenya" Kasprzak and the Computer Systems
Unit team at Faculty of Informatics, Masaryk University as the original
reporters of CVE-2015-5252 flaws, and Douglas Bagnall as the original
reporter of CVE-2015-5330.

All samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0006</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5299</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5330</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160006"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160007" severity="medium">
    <xccdf:title>RHSA-2016:0007: nss security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

All nss users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the NSS library must be restarted, or the
system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0007</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160007"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160008" severity="medium">
    <xccdf:title>RHSA-2016:0008: openssl security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

All openssl users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library must be restarted, or
the system rebooted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0008</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160008"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160009" severity="medium">
    <xccdf:title>RHSA-2016:0009: libldb security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The libldb packages provide an extensible library that implements an
LDAP-like API to access remote LDAP servers, or use local TDB databases.

A denial of service flaw was found in the ldb_wildcard_compare() function
of libldb. A remote attacker could send a specially crafted packet that,
when processed by an application using libldb (for example the AD LDAP
server in Samba), would cause that application to consume an excessive
amount of memory and crash. (CVE-2015-3223)

A memory-read flaw was found in the way the libldb library processed LDB DN
records with a null byte. An authenticated, remote attacker could use this
flaw to read heap-memory pages from the server. (CVE-2015-5330)

Red Hat would like to thank the Samba project for reporting these issues.
Upstream acknowledges Thilo Uttendorfer as the original reporter of
CVE-2015-3223, and Douglas Bagnall as the original reporter of
CVE-2015-5330.

All libldb users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0009</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3223</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5330</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160009"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160010" severity="medium">
    <xccdf:title>RHSA-2016:0010: samba4 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the LDAP server provided by the AD DC
in the Samba process daemon. A remote attacker could exploit this flaw by
sending a specially crafted packet, which could cause the server to consume
an excessive amount of memory and crash. (CVE-2015-7540)

Multiple buffer over-read flaws were found in the way Samba handled
malformed inputs in certain encodings. An authenticated, remote attacker
could possibly use these flaws to disclose portions of the server memory.
(CVE-2015-5330)

A man-in-the-middle vulnerability was found in the way "connection signing"
was implemented by Samba. A remote attacker could use this flaw to
downgrade an existing Samba client connection and force the use of plain
text. (CVE-2015-5296)

A missing access control flaw was found in Samba. A remote, authenticated
attacker could use this flaw to view the current snapshot on a Samba share,
despite not having DIRECTORY_LIST access rights. (CVE-2015-5299)

An access flaw was found in the way Samba verified symbolic links when
creating new files on a Samba share. A remote attacker could exploit this
flaw to gain access to files outside of Samba's share path. (CVE-2015-5252)

Red Hat would like to thank the Samba project for reporting these issues.
Upstream acknowledges Stefan Metzmacher of the Samba Team and Sernet.de as
the original reporters of CVE-2015-5296, partha@exablox.com as the original
reporter of CVE-2015-5299, Jan "Yenya" Kasprzak and the Computer Systems
Unit team at Faculty of Informatics, Masaryk University as the original
reporters of CVE-2015-5252 flaws, and Douglas Bagnall as the original
reporter of CVE-2015-5330.

All samba4 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0010</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5299</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5330</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7540</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160010"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160011" severity="medium">
    <xccdf:title>RHSA-2016:0011: samba security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A man-in-the-middle vulnerability was found in the way "connection signing"
was implemented by Samba. A remote attacker could use this flaw to
downgrade an existing Samba client connection and force the use of plain
text. (CVE-2015-5296)

A missing access control flaw was found in Samba. A remote, authenticated
attacker could use this flaw to view the current snapshot on a Samba share,
despite not having DIRECTORY_LIST access rights. (CVE-2015-5299)

An access flaw was found in the way Samba verified symbolic links when
creating new files on a Samba share. A remote attacker could exploit this
flaw to gain access to files outside of Samba's share path. (CVE-2015-5252)

Red Hat would like to thank the Samba project for reporting these issues.
Upstream acknowledges Stefan Metzmacher of the Samba Team and Sernet.de as
the original reporters of CVE-2015-5296, partha@exablox.com as the original
reporter of CVE-2015-5299, Jan "Yenya" Kasprzak and the Computer Systems
Unit team at Faculty of Informatics, Masaryk University as the original
reporters of CVE-2015-5252.

All samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0011</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5252</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5296</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5299</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160011"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160012" severity="medium">
    <xccdf:title>RHSA-2016:0012: gnutls security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

All gnutls users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the GnuTLS library must be restarted.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0012</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160012"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160043" severity="medium">
    <xccdf:title>RHSA-2016:0043: openssh security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation.
These packages include the core files necessary for both the OpenSSH client
and server.

An information leak flaw was found in the way the OpenSSH client roaming
feature was implemented. A malicious server could potentially use this flaw
to leak portions of memory (possibly including private SSH keys) of a
successfully authenticated OpenSSH client. (CVE-2016-0777)

A buffer overflow flaw was found in the way the OpenSSH client roaming
feature was implemented. A malicious server could potentially use this flaw
to execute arbitrary code on a successfully authenticated OpenSSH client if
that client used certain non-default configuration options. (CVE-2016-0778)

Red Hat would like to thank Qualys for reporting these issues.

All openssh users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the OpenSSH server daemon (sshd) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0043</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0777</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0778</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160043"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160045" severity="high">
    <xccdf:title>RHSA-2016:0045: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* Two flaws were found in the way the Linux kernel's networking
implementation handled UDP packets with incorrect checksum values. A remote
attacker could potentially use these flaws to trigger an infinite loop in
the kernel, resulting in a denial of service on the system, or cause a
denial of service in applications using the edge triggered epoll
functionality. (CVE-2015-5364, CVE-2015-5366, Important)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0045</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5364</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5366</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160045"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160049" severity="high">
    <xccdf:title>RHSA-2016:0049: java-1.8.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

An out-of-bounds write flaw was found in the JPEG image format decoder in
the AWT component in OpenJDK. A specially crafted JPEG image could cause
a Java application to crash or, possibly execute arbitrary code. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2016-0483)

An integer signedness issue was found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could possibly cause
the Java Virtual Machine to execute arbitrary code, allowing an untrusted
Java application or applet to bypass Java sandbox restrictions.
(CVE-2016-0494)

It was discovered that the password-based encryption (PBE) implementation
in the Libraries component in OpenJDK used an incorrect key length. This
could, in certain cases, lead to generation of keys that were weaker than
expected. (CVE-2016-0475)

It was discovered that the JAXP component in OpenJDK did not properly
enforce the totalEntitySizeLimit limit. An attacker able to make a Java
application process a specially crafted XML file could use this flaw to
make the application consume an excessive amount of memory. (CVE-2016-0466)

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

Multiple flaws were discovered in the Networking and JMX components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2016-0402, CVE-2016-0448)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0049</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160049"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160050" severity="high">
    <xccdf:title>RHSA-2016:0050: java-1.8.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

An out-of-bounds write flaw was found in the JPEG image format decoder in
the AWT component in OpenJDK. A specially crafted JPEG image could cause
a Java application to crash or, possibly execute arbitrary code. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2016-0483)

An integer signedness issue was found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could possibly cause
the Java Virtual Machine to execute arbitrary code, allowing an untrusted
Java application or applet to bypass Java sandbox restrictions.
(CVE-2016-0494)

It was discovered that the password-based encryption (PBE) implementation
in the Libraries component in OpenJDK used an incorrect key length. This
could, in certain cases, lead to generation of keys that were weaker than
expected. (CVE-2016-0475)

It was discovered that the JAXP component in OpenJDK did not properly
enforce the totalEntitySizeLimit limit. An attacker able to make a Java
application process a specially crafted XML file could use this flaw to
make the application consume an excessive amount of memory. (CVE-2016-0466)

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

Multiple flaws were discovered in the Networking and JMX components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2016-0402, CVE-2016-0448)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0050</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160050"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160053" severity="high">
    <xccdf:title>RHSA-2016:0053: java-1.7.0-openjdk security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An out-of-bounds write flaw was found in the JPEG image format decoder in
the AWT component in OpenJDK. A specially crafted JPEG image could cause
a Java application to crash or, possibly execute arbitrary code. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2016-0483)

An integer signedness issue was found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could possibly cause
the Java Virtual Machine to execute arbitrary code, allowing an untrusted
Java application or applet to bypass Java sandbox restrictions.
(CVE-2016-0494)

It was discovered that the JAXP component in OpenJDK did not properly
enforce the totalEntitySizeLimit limit. An attacker able to make a Java
application process a specially crafted XML file could use this flaw to
make the application consume an excessive amount of memory. (CVE-2016-0466)

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

Multiple flaws were discovered in the Libraries, Networking, and JMX
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4871,
CVE-2016-0402, CVE-2016-0448)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0053</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160053"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160054" severity="high">
    <xccdf:title>RHSA-2016:0054: java-1.7.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An out-of-bounds write flaw was found in the JPEG image format decoder in
the AWT component in OpenJDK. A specially crafted JPEG image could cause
a Java application to crash or, possibly execute arbitrary code. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2016-0483)

An integer signedness issue was found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could possibly cause
the Java Virtual Machine to execute arbitrary code, allowing an untrusted
Java application or applet to bypass Java sandbox restrictions.
(CVE-2016-0494)

It was discovered that the JAXP component in OpenJDK did not properly
enforce the totalEntitySizeLimit limit. An attacker able to make a Java
application process a specially crafted XML file could use this flaw to
make the application consume an excessive amount of memory. (CVE-2016-0466)

A flaw was found in the way TLS 1.2 could use the MD5 hash function for
signing ServerKeyExchange and Client Authentication packets during a TLS
handshake. A man-in-the-middle attacker able to force a TLS connection to
use the MD5 hash function could use this flaw to conduct collision attacks
to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)

Multiple flaws were discovered in the Libraries, Networking, and JMX
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4871,
CVE-2016-0402, CVE-2016-0448)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0054</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-4871</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160054"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160055" severity="high">
    <xccdf:title>RHSA-2016:0055: java-1.8.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 8 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-7575, CVE-2015-8126, CVE-2015-8472, CVE-2016-0402, CVE-2016-0448,
CVE-2016-0466, CVE-2016-0475, CVE-2016-0483, CVE-2016-0494)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.8.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 8 Update 71 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0055</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0475</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160055"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160056" severity="high">
    <xccdf:title>RHSA-2016:0056: java-1.7.0-oracle security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-7575, CVE-2015-8126, CVE-2015-8472, CVE-2016-0402, CVE-2016-0448,
CVE-2016-0466, CVE-2016-0483, CVE-2016-0494)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 95 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0056</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7575</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160056"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160057" severity="high">
    <xccdf:title>RHSA-2016:0057: java-1.6.0-sun security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2015-8126, CVE-2015-8472, CVE-2016-0402, CVE-2016-0448, CVE-2016-0466,
CVE-2016-0483, CVE-2016-0494)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 111 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0057</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8126</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8472</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160057"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160063" severity="high">
    <xccdf:title>RHSA-2016:0063: ntp security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

It was discovered that ntpd as a client did not correctly check the
originate timestamp in received packets. A remote attacker could use this
flaw to send a crafted packet to an ntpd client that would effectively
disable synchronization with the server, or push arbitrary offset/delay
measurements to modify the time on the client. (CVE-2015-8138)

All ntp users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the ntpd daemon will restart automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0063</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8138</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160063"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160064" severity="high">
    <xccdf:title>RHSA-2016:0064: kernel security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A use-after-free flaw was found in the way the Linux kernel's key
management subsystem handled keyring object reference counting in certain
error path of the join_session_keyring() function. A local, unprivileged
user could use this flaw to escalate their privileges on the system.
(CVE-2016-0728, Important)

Red Hat would like to thank the Perception Point research team for
reporting this issue.

All kernel users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0064</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0728</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160064"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160065" severity="high">
    <xccdf:title>RHSA-2016:0065: kernel-rt security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A use-after-free flaw was found in the way the Linux kernel's key
management subsystem handled keyring object reference counting in certain
error path of the join_session_keyring() function. A local, unprivileged
user could use this flaw to escalate their privileges on the system.
(CVE-2016-0728, Important)

Red Hat would like to thank the Perception Point research team for
reporting this issue.

All kernel-rt users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0065</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0728</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160065"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160067" severity="high">
    <xccdf:title>RHSA-2016:0067: java-1.6.0-openjdk security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An out-of-bounds write flaw was found in the JPEG image format decoder in
the AWT component in OpenJDK. A specially crafted JPEG image could cause
a Java application to crash or, possibly execute arbitrary code. An
untrusted Java application or applet could use this flaw to bypass Java
sandbox restrictions. (CVE-2016-0483)

An integer signedness issue was found in the font parsing code in the 2D
component in OpenJDK. A specially crafted font file could possibly cause
the Java Virtual Machine to execute arbitrary code, allowing an untrusted
Java application or applet to bypass Java sandbox restrictions.
(CVE-2016-0494)

It was discovered that the JAXP component in OpenJDK did not properly
enforce the totalEntitySizeLimit limit. An attacker able to make a Java
application process a specially crafted XML file could use this flaw to
make the application consume an excessive amount of memory. (CVE-2016-0466)

Multiple flaws were discovered in the Networking and JMX components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2016-0402, CVE-2016-0448)

Note: This update also disallows the use of the MD5 hash algorithm in the
certification path processing. The use of MD5 can be re-enabled by removing
MD5 from the jdk.certpath.disabledAlgorithms security property defined in
the java.security file.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0067</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0402</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0448</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0466</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0483</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0494</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160067"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160071" severity="high">
    <xccdf:title>RHSA-2016:0071: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2016-1930, CVE-2016-1935)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bob Clary, Christian Holler, Nils Ohlmeier, Gary
Kwong, Jesse Ruderman, Carsten Book, Randell Jesup, and Aki Helin as the
original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0071</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1930</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1935</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160071"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160073" severity="medium">
    <xccdf:title>RHSA-2016:0073: bind security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND processed certain
malformed Address Prefix List (APL) records. A remote, authenticated
attacker could use this flaw to cause named to crash. (CVE-2015-8704)

Red Hat would like to thank ISC for reporting this issue.

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0073</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160073"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160074" severity="medium">
    <xccdf:title>RHSA-2016:0074: bind97 security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND processed certain
malformed Address Prefix List (APL) records. A remote, authenticated
attacker could use this flaw to cause named to crash. (CVE-2015-8704)

Red Hat would like to thank ISC for reporting this issue.

All bind97 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0074</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-8704</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160074"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160082" severity="high">
    <xccdf:title>RHSA-2016:0082: qemu-kvm security update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An out-of-bounds read/write flaw was discovered in the way QEMU's Firmware
Configuration device emulation processed certain firmware configurations.
A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the
QEMU process instance or, potentially, execute arbitrary code on the host
with privileges of the QEMU process. (CVE-2016-1714)

Red Hat would like to thank Donghai Zhu of Alibaba for reporting this
issue.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0082</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1714</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160082"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160083" severity="high">
    <xccdf:title>RHSA-2016:0083: qemu-kvm security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

An out-of-bounds read/write flaw was discovered in the way QEMU's Firmware
Configuration device emulation processed certain firmware configurations.
A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the
QEMU process instance or, potentially, execute arbitrary code on the host
with privileges of the QEMU process. (CVE-2016-1714)

Red Hat would like to thank Donghai Zhu of Alibaba for reporting this
issue.

This update also fixes the following bugs:

* Incorrect handling of the last sector of an image file could trigger an
assertion failure in qemu-img. This update changes the handling of the last
sector, and no assertion failure occurs. (BZ#1298828)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0083</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1714</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160083"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160152" severity="medium">
    <xccdf:title>RHSA-2016:0152: sos security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sos package contains a set of tools that gather information from system
hardware, logs and configuration files. The information can then be used
for diagnostic purposes and debugging.

An insecure temporary file use flaw was found in the way sos created 
certain sosreport files. A local attacker could possibly use this flaw 
to perform a symbolic link attack to reveal the contents of sosreport 
files, or in some cases modify arbitrary files and escalate their 
privileges on the system. (CVE-2015-7529)

This issue was discovered by Mateusz Guzik of Red Hat.

This update also fixes the following bug:

* Previously, when the hpasm plug-in ran the "hpasmcli" command in a Python
Popen constructor or a system pipeline, the command would hang and
eventually time out after 300 seconds. Sos was forced to wait for the time
out to finish, unnecessarily prolonging its run time. With this update, the
timeout of the "hpasmcli" command has been set to 0, eliminating the delay
and speeding up sos completion time. (BZ#1291828)

All sos users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0152</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7529</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160152"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160175" severity="high">
    <xccdf:title>RHSA-2016:0175: glibc security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A stack-based buffer overflow was found in the way the libresolv library
performed dual A/AAAA DNS queries. A remote attacker could create a
specially crafted DNS response which could cause libresolv to crash or,
potentially, execute code with the permissions of the user running the
library. Note: this issue is only exposed when libresolv is called from the
nss_dns NSS service module. (CVE-2015-7547)

This issue was discovered by the Google Security Team and Red Hat.

This update also fixes the following bugs:

* The dynamic loader has been enhanced to allow the loading of more shared
libraries that make use of static thread local storage. While static thread
local storage is the fastest access mechanism it may also prevent the
shared library from being loaded at all since the static storage space is a
limited and shared process-global resource. Applications which would
previously fail with "dlopen: cannot load any more object with static TLS"
should now start up correctly. (BZ#1291270)

* A bug in the POSIX realtime support would cause asynchronous I/O or
certain timer API calls to fail and return errors in the presence of large
thread-local storage data that exceeded PTHREAD_STACK_MIN in size
(generally 16 KiB). The bug in librt has been corrected and the impacted
APIs no longer return errors when large thread-local storage data is
present in the application. (BZ#1301625)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0175</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160175"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160176" severity="high">
    <xccdf:title>RHSA-2016:0176: glibc security and bug fix update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The glibc packages provide the standard C libraries (libc), POSIX 
thread libraries (libpthread), standard math libraries (libm), and the 
name service cache daemon (nscd) used by multiple programs on the 
system. Without these libraries, the Linux system cannot function 
correctly.

A stack-based buffer overflow was found in the way the libresolv library
performed dual A/AAAA DNS queries. A remote attacker could create a
specially crafted DNS response which could cause libresolv to crash or,
potentially, execute code with the permissions of the user running the
library. Note: this issue is only exposed when libresolv is called from the
nss_dns NSS service module. (CVE-2015-7547)

It was discovered that the calloc implementation in glibc could return
memory areas which contain non-zero bytes. This could result in unexpected
application behavior such as hangs or crashes. (CVE-2015-5229)

The CVE-2015-7547 issue was discovered by the Google Security Team and Red
Hat. Red Hat would like to thank Jeff Layton for reporting the
CVE-2015-5229 issue.

This update also fixes the following bugs:

* The existing implementation of the "free" function causes all memory
pools beyond the first to return freed memory directly to the operating
system as quickly as possible. This can result in performance degradation
when the rate of free calls is very high. The first memory pool (the main
pool) does provide a method to rate limit the returns via M_TRIM_THRESHOLD,
but this method is not available to subsequent memory pools.

With this update, the M_TRIM_THRESHOLD method is extended to apply to all
memory pools, which improves performance for threads with very high amounts
of free calls and limits the number of "madvise" system calls. The change
also increases the total transient memory usage by processes because the
trim threshold must be reached before memory can be freed.

To return to the previous behavior, you can either set M_TRIM_THRESHOLD
using the "mallopt" function, or set the MALLOC_TRIM_THRESHOLD environment
variable to 0. (BZ#1298930)

* On the little-endian variant of 64-bit IBM Power Systems (ppc64le), a bug
in the dynamic loader could cause applications compiled with profiling
enabled to fail to start with the error "monstartup: out of memory".
The bug has been corrected and applications compiled for profiling now
start correctly. (BZ#1298956)

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0176</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5229</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7547</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160176"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160185" severity="high">
    <xccdf:title>RHSA-2016:0185: kernel security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's keys subsystem did not correctly
garbage collect uninstantiated keyrings. A local attacker could use this
flaw to crash the system or, potentially, escalate their privileges on the
system. (CVE-2015-7872, Important)

* A flaw was found in the way the Linux kernel handled IRET faults during
the processing of NMIs. An unprivileged, local user could use this flaw to
crash the system or, potentially (although highly unlikely), escalate their
privileges on the system. (CVE-2015-5157, Moderate)

This update also fixes the following bugs:

* Previously, processing packets with a lot of different IPv6 source
addresses caused the kernel to return warnings concerning soft-lockups due
to high lock contention and latency increase. With this update, lock
contention is reduced by backing off concurrent waiting threads on the
lock. As a result, the kernel no longer issues warnings in the described
scenario. (BZ#1285370)

* Prior to this update, block device readahead was artificially limited.
As a consequence, the read performance was poor, especially on RAID
devices. Now, per-device readahead limits are used for each device instead
of a global limit. As a result, read performance has improved, especially
on RAID devices. (BZ#1287550)

* After injecting an EEH error, the host was previously not recovering and
observing I/O hangs in HTX tool logs. This update makes sure that when one
or both of EEH_STATE_MMIO_ACTIVE and EEH_STATE_MMIO_ENABLED flags is marked
in the PE state, the PE's IO path is regarded as enabled as well. As a
result, the host no longer hangs and recovers as expected. (BZ#1289101)

* The genwqe device driver was previously using the GFP_ATOMIC flag for
allocating consecutive memory pages from the kernel's atomic memory pool,
even in non-atomic situations. This could lead to allocation failures
during memory pressure. With this update, the genwqe driver's memory
allocations use the GFP_KERNEL flag, and the driver can allocate memory
even during memory pressure situations. (BZ#1289450)

* The nx842 co-processor for IBM Power Systems could in some circumstances
provide invalid data due to a data corruption bug during uncompression.
With this update, all compression and uncompression calls to the nx842
co-processor contain a cyclic redundancy check (CRC) flag, which forces all
compression and uncompression operations to check data integrity and
prevents the co-processor from providing corrupted data. (BZ#1289451)

* A failed "updatepp" operation on the little-endian variant of IBM Power
Systems could previously cause a wrong hash value to be used for the next
hash insert operation in the page table. This could result in a missing
hash pte update or invalidate operation, potentially causing memory
corruption. With this update, the hash value is always recalculated after a
failed "updatepp" operation, avoiding memory corruption. (BZ#1289452)

* Large Receive Offload (LRO) flag disabling was not being propagated
downwards from above devices in vlan and bond hierarchy, breaking the flow
of traffic. This problem has been fixed and LRO flags now propagate
correctly. (BZ#1292072)

* Due to rounding errors in the CPU frequency of the intel_pstate driver,
the CPU frequency never reached the value requested by the user. A kernel
patch has been applied to fix these rounding errors. (BZ#1296276)

* When running several containers (up to 100), reports of hung tasks were
previously reported. This update fixes the AB-BA deadlock in the
dm_destroy() function, and the hung reports no longer occur. (BZ#1296566)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0185</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-5157</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7872</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160185"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160188" severity="medium">
    <xccdf:title>RHSA-2016:0188: sos security and bug fix update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The sos package contains a set of utilities that gather information from
system hardware, logs, and configuration files. The information can then be
used for diagnostic purposes and debugging.

An insecure temporary file use flaw was found in the way sos created
certain sosreport files. A local attacker could possibly use this flaw to
perform a symbolic link attack to reveal the contents of sosreport files,
or in some cases modify arbitrary files and escalate their privileges on
the system. (CVE-2015-7529)

This issue was discovered by Mateusz Guzik of Red Hat.

This update also fixes the following bug:

* Previously, the sosreport tool was not collecting the /var/lib/ceph and
/var/run/ceph directories when run with the ceph plug-in enabled, causing
the generated sosreport archive to miss vital troubleshooting information
about ceph. With this update, the ceph plug-in for sosreport collects these
directories, and the generated report contains more useful information.
(BZ#1291347)

All users of sos are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0188</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-7529</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160188"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160189" severity="medium">
    <xccdf:title>RHSA-2016:0189: polkit security update (Moderate)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>PolicyKit is a toolkit for defining and handling authorizations.

A denial of service flaw was found in how polkit handled authorization
requests. A local, unprivileged user could send malicious requests to
polkit, which could then cause the polkit daemon to corrupt its memory and
crash. (CVE-2015-3256)

All polkit users should upgrade to these updated packages, which contain a
backported patch to correct this issue. The system must be rebooted for
this update to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0189</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2015-3256</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160189"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160197" severity="high">
    <xccdf:title>RHSA-2016:0197: firefox security update (Critical)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Multiple security flaws were found in the graphite2 font library shipped
with Firefox. A web page containing malicious content could cause Firefox
to crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2016-1521, CVE-2016-1522, CVE-2016-1523)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.6.1 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0197</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1521</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1522</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1523</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-1969</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160197"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-20160204" severity="high">
    <xccdf:title>RHSA-2016:0204: 389-ds-base security and bug fix update (Important)</xccdf:title>
    <xccdf:description xml:lang="en-US">
      <xhtml:pre>The 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server.
The base packages include the Lightweight Directory Access Protocol (LDAP)
server and command-line utilities for server administration.

An infinite-loop vulnerability was discovered in the 389 directory server,
where the server failed to correctly handle unexpectedly closed client
connections. A remote attacker able to connect to the server could use this
flaw to make the directory server consume an excessive amount of CPU and
stop accepting connections (denial of service). (CVE-2016-0741)

This update fixes the following bugs:

* Previously, if a simple paged results search failed in the back end, the
simple paged results slot was not released. Consequently, the simple paged
results slots in a connection object could be accumulated. With this
update, the simple paged results slot is released correctly when a search
fails, and unused simple paged results slots are no longer left in a
connection object. (BZ#1290725)

* Previously, when several values of the same attribute were deleted using
the ldapmodify command, and at least one of them was added again during the
same operation, the equality index was not updated. As a consequence, an
exact search for the re-added attribute value did not return the entry. The
logic of the index code has been modified to update the index if at least
one of the values in the entry changes, and the exact search for the
re-added attribute value now returns the correct entry. (BZ#1290726)

* Prior to this update, when the cleanAllRUV task was running, a bogus
attrlist_replace error message was logged repeatedly due to a memory
corruption. With this update, the appropriate memory copy function memmove
is used, which fixes the memory corruption. As a result, the error messages
are no longer logged in this scenario. (BZ#1295684)

* To fix a simple paged results bug, an exclusive lock on a connection was
previously added. This consequently caused a self deadlock in a particular
case. With this update, the exclusive lock on a connection has been changed
to the re-entrant type, and the self deadlock no longer occurs.
(BZ#1298105)

* Previously, an unnecessary lock was sometimes acquired on a connection
object, which could consequently cause a deadlock. A patch has been applied
to remove the unnecessary locking, and the deadlock no longer occurs.
(BZ#1299346)

Users of 389-ds-base are advised to upgrade to these updated packages,
which correct these issues. After installing this update, the 389 server
service will be restarted automatically.</xhtml:pre>
    </xccdf:description>
    <xccdf:ident system="https://access.redhat.com/errata">RHSA-2016:0204</xccdf:ident>
    <xccdf:ident system="http://cve.mitre.org">CVE-2016-0741</xccdf:ident>
    <xccdf:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
      <xccdf:check-content-ref href="com.redhat.rhsa-all.xml" name="oval:com.redhat.rhsa:def:20160204"/>
    </xccdf:check>
  </xccdf:Rule>
  <xccdf:Rule selected="true" id="oval-com.redhat.rhsa-def-2016021