<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">

<generator>
	<oval:product_name>CentOS Errata System</oval:product_name>
	<oval:schema_version>5.3</oval:schema_version>
	<oval:timestamp>2011-10-26T12:58:53</oval:timestamp>
</generator>

<definitions>
	<definition id="oval:org.centos.cesa:def:20111409" version="502" class="patch">
		<metadata>
			<title>RHSA-2011:1409: openssl security update (Moderate)</title>
			<affected family="unix">
				<platform>CentOS Linux 6</platform>
			</affected>

			<reference source="RHSA" ref_id="RHSA-2011:1409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1409.html"/>
			<reference source="CVE" ref_id="CVE-2011-3207" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3207.html"/>
    
			<description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An uninitialized variable use flaw was found in OpenSSL. This flaw could
cause an application using the OpenSSL Certificate Revocation List (CRL)
checking functionality to incorrectly accept a CRL that has a nextUpdate
date in the past. (CVE-2011-3207)

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. For the update to take effect, all
services linked to the OpenSSL library must be restarted, or the system
rebooted.</description>

			<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

			<advisory from="secalert@centos.org">

				<severity>Moderate</severity>

				<rights>Copyright 2011 Red Hat, Inc.</rights>
				<issued date="2011-10-26"/>
				<updated date="2011-10-26"/>
				<cve href="https://www.redhat.com/security/data/cve/CVE-2011-3207.html">CVE-2011-3207</cve>
				<bugzilla href="http://bugzilla.redhat.com/736087" id="736087">CVE-2011-3207 openssl: CRL verification vulnerability</bugzilla>
				<affected_cpe_list>
					<cpe>cpe:/o:centos:enterprise_linux</cpe>
				</affected_cpe_list>
			</advisory>

		</metadata>

		<criteria operator="AND">
 
			<criteria operator="OR">
				<criterion test_ref="oval:org.centos.cesa:tst:20111409002" comment="CentOS Linux 6 is installed" />
			</criteria>

			<criteria operator="OR">
 
				<criteria operator="AND">
					<criterion test_ref="oval:org.centos.cesa:tst:20111409005" comment="openssl is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:org.centos.cesa:tst:20111409006" comment="openssl is signed with CentOS key" />
				</criteria>

				<criteria operator="AND">
					<criterion test_ref="oval:org.centos.cesa:tst:20111409007" comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:org.centos.cesa:tst:20111409008" comment="openssl-static is signed with CentOS key" />
				</criteria>

				<criteria operator="AND">
					<criterion test_ref="oval:org.centos.cesa:tst:20111409009" comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:org.centos.cesa:tst:20111409010" comment="openssl-perl is signed with CentOS key" />
				</criteria>

				<criteria operator="AND">
					<criterion test_ref="oval:org.centos.cesa:tst:20111409011" comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:org.centos.cesa:tst:20111409012" comment="openssl-devel is signed with CentOS key" />
				</criteria>

			</criteria>

		</criteria>

	</definition>

</definitions>

<tests>
	<!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ -->

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409002"  version="502" comment="CentOS 6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409002" />
		<state state_ref="oval:org.centos.cesa:ste:20111409002" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409005"  version="502" comment="openssl is earlier than 0:1.0.0-10.el6_1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409005" />
		<state state_ref="oval:org.centos.cesa:ste:20111409003" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409006"  version="502" comment="openssl is signed with CentOS key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409005" />
		<state state_ref="oval:org.centos.cesa:ste:20111409001" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409007"  version="502" comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409006" />
		<state state_ref="oval:org.centos.cesa:ste:20111409003" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409008"  version="502" comment="openssl-static is signed with CentOS key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409006" />
		<state state_ref="oval:org.centos.cesa:ste:20111409001" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409009"  version="502" comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409007" />
		<state state_ref="oval:org.centos.cesa:ste:20111409003" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409010"  version="502" comment="openssl-perl is signed with CentOS key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409007" />
		<state state_ref="oval:org.centos.cesa:ste:20111409001" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409011"  version="502" comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409008" />
		<state state_ref="oval:org.centos.cesa:ste:20111409003" />
	</rpminfo_test>

	<rpminfo_test id="oval:org.centos.cesa:tst:20111409012"  version="502" comment="openssl-devel is signed with CentOS key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.centos.cesa:obj:20111409008" />
		<state state_ref="oval:org.centos.cesa:ste:20111409001" />
	</rpminfo_test>

</tests>

<objects>
	<!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ -->
	<rpminfo_object id="oval:org.centos.cesa:obj:20111409002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>centos-release</name>
	</rpminfo_object>

	<rpminfo_object id="oval:org.centos.cesa:obj:20111409005"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl</name>
	</rpminfo_object>

	<rpminfo_object id="oval:org.centos.cesa:obj:20111409006"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl-static</name>
	</rpminfo_object>

	<rpminfo_object id="oval:org.centos.cesa:obj:20111409007"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl-perl</name>
	</rpminfo_object>

	<rpminfo_object id="oval:org.centos.cesa:obj:20111409008"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl-devel</name>
	</rpminfo_object>

</objects>

<states>
	<!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ -->
	<rpminfo_state id="oval:org.centos.cesa:ste:20111409001"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<signature_keyid  operation="equals">0946fca2c105b9de</signature_keyid>
	</rpminfo_state>

	<rpminfo_state id="oval:org.centos.cesa:ste:20111409002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<version  operation="pattern match">^6[^[:digit:]]</version>
	</rpminfo_state>

	<rpminfo_state id="oval:org.centos.cesa:ste:20111409003"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<evr datatype="evr_string" operation="less than">0:1.0.0-10.el6_1.5</evr>
	</rpminfo_state>
</states>

</oval_definitions>

