|
|
|
Wood, Michael
|
Here is a new HP-UX 11 OVAL we would like to submit.
oval:com.hp.temp.oval:def:20080731001 CVE-2008-1662 Thanks, Michael Wood Hewlett-Packard To unsubscribe, send an email message to LISTSERV@... with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to OVAL-DISCUSSION-LIST-request@.... <?xml version="1.0" encoding="UTF-8"?> <oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:hpux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd"> <generator> <oval:product_name>Hewlett-Packard</oval:product_name> <oval:schema_version>5.4</oval:schema_version> <oval:timestamp>2008-07-31T12:40:22.000-04:00</oval:timestamp> </generator> <definitions> <definition id="oval:com.hp.temp.oval:def:20080731001" version="0" class="vulnerability"> <metadata> <title>HP-UX Running System Administration Manager (SAM), Unintended Remote Access</title> <affected family="unix"> <platform>HP-UX 11</platform> </affected> <reference source="CVE" ref_id="CVE-2008-1662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1662"/> <description>A potential security vulnerability has been identified in HP-UX running System Administration Manager (SAM). This vulnerability may allow unintended remote access.</description> <oval_repository> <dates> <submitted date="2008-07-31T12:40:22.000-04:00"> <contributor organization="Hewlett-Packard">Michael Wood</contributor> </submitted> </dates> <status>DRAFT</status> </oval_repository> </metadata> <criteria operator="OR"> <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286"> <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/> <criteria operator="OR" comment="filesets tests"> <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:com.hp.temp.oval:tst:20080731001"/> <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:com.hp.temp.oval:tst:20080731002"/> <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:com.hp.temp.oval:tst:20080731003"/> </criteria> <criterion comment="Patch PHCO_36562 is installed" test_ref="oval:com.hp.temp.oval:tst:20080731004" negate="true"/> </criteria> <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286"> <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/> <criteria operator="OR" comment="filesets tests"> <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:com.hp.temp.oval:tst:20080731001"/> <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:com.hp.temp.oval:tst:20080731002"/> <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:com.hp.temp.oval:tst:20080731003"/> </criteria> <criterion comment="Patch PHCO_36563 is installed" test_ref="oval:com.hp.temp.oval:tst:20080731005" negate="true"/> </criteria> </criteria> </definition> </definitions> <tests> <swlist_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="InternetSrvcs.INETSVCS-BOOT is installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080731001"> <object object_ref="oval:com.hp.temp.oval:obj:20080731001"/> </swlist_test> <swlist_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="OS-Core.UX-CORE is installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080731002"> <object object_ref="oval:com.hp.temp.oval:obj:20080731002"/> </swlist_test> <swlist_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="SystemAdmin.SAM is installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080731003"> <object object_ref="oval:com.hp.temp.oval:obj:20080731003"/> </swlist_test> <patch53_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="Patch PHCO_36562 is installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080731004"> <object object_ref="oval:com.hp.temp.oval:obj:20080731004"/> </patch53_test> <patch53_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="Patch PHCO_36563 is installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080731005"> <object object_ref="oval:com.hp.temp.oval:obj:20080731005"/> </patch53_test> <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3704" version="1" comment="HP Release B.11.11" check_existence="at_least_one_exists" check="all"> <object object_ref="oval:org.mitre.oval:obj:2759"/> <state state_ref="oval:org.mitre.oval:ste:3389"/> </uname_test> <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3901" version="1" comment="HP Release B.11.23" check_existence="at_least_one_exists" check="all"> <object object_ref="oval:org.mitre.oval:obj:2759"/> <state state_ref="oval:org.mitre.oval:ste:3324"/> </uname_test> </tests> <objects> <swlist_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.temp.oval:obj:20080731001"> <swlist>InternetSrvcs.INETSVCS-BOOT</swlist> </swlist_object> <swlist_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.temp.oval:obj:20080731002"> <swlist>OS-Core.UX-CORE</swlist> </swlist_object> <swlist_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.temp.oval:obj:20080731003"> <swlist>SystemAdmin.SAM</swlist> </swlist_object> <patch53_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.temp.oval:obj:20080731004"> <behaviors supersedence="true"/> <swtype>PH</swtype> <area_patched>CO</area_patched> <patch_base>36562</patch_base> </patch53_object> <patch53_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.temp.oval:obj:20080731005"> <behaviors supersedence="true"/> <swtype>PH</swtype> <area_patched>CO</area_patched> <patch_base>36563</patch_base> </patch53_object> <uname_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object."/> </objects> <states> <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3324" version="1"> <os_release>B.11.23</os_release> </uname_state> <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3389" version="1"> <os_release>B.11.11</os_release> </uname_state> </states> </oval_definitions> |
|
Worrell, Bryan A.
|
Michael,
Thank you for your submission to the OVAL Repository. Your submission has been processed and is available for further community review via the OVAL Repository website. Thanks, Bryan Worrell __ Bryan Worrell The MITRE Corporation bworrell@... >-----Original Message----- >From: Wood, Michael [mailto:michael.wood@...] >Sent: Thursday, July 31, 2008 12:44 PM >To: oval-discussion-list OVAL Discussion List/Closed Public Discussi >Subject: [OVAL-DISCUSSION-LIST] New HP-UX 11 OVAL > >Here is a new HP-UX 11 OVAL we would like to submit. > >oval:com.hp.temp.oval:def:20080731001 CVE-2008-1662 > >Thanks, > >Michael Wood >Hewlett-Packard > >To unsubscribe, send an email message to LISTSERV@... with >SIGNOFF OVAL-DISCUSSION-LIST >in the BODY of the message. If you have difficulties, write to OVAL- >DISCUSSION-LIST-request@.... To unsubscribe, send an email message to LISTSERV@... with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to OVAL-DISCUSSION-LIST-request@.... |
||||||||||||||||||
|
Wood, Michael
|
In reply to this post by Wood, Michael
Here is new HP-UX 11 OVAL we would like to submit. The file hp-ux-11.xml contains
oval:com.hp.oval:def:6 - CVE-2008-1668 Thanks, Michael Wood Hewlett-Packard To unsubscribe, send an email message to LISTSERV@... with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to OVAL-DISCUSSION-LIST-request@.... <?xml version="1.0" encoding="UTF-8"?> <oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval1="http://oval.mitre.org/XMLSchema/oval-definitions-5" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#aix aix-definitions-schema.xsd"> <generator> <oval:product_name>Hewlett-Packard Live Network</oval:product_name> <oval:schema_version>5.4</oval:schema_version> <oval:timestamp>2008-08-12T20:31:59.000-00:00</oval:timestamp> </generator> <definitions> <definition id="oval:com.hp.oval:def:6" version="0" class="vulnerability"> <metadata> <title>HP-UX Running ftpd, Remote Privileged Access</title> <affected family="unix"> <platform>HP-UX 11</platform> </affected> <reference source="CVE" ref_id="CVE-2008-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1668"/> <description>A potential security vulnerability has been identified with HP-UX running ftpd. The vulnerability could be exploited to allow remote privileged access.</description> <oval_repository> <dates> <submitted date="2008-08-12T16:30:32.000-04:00"> <contributor organization="Hewlett-Packard">Michael Wood</contributor> </submitted> </dates> <status>DRAFT</status> </oval_repository> </metadata> <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02356"> <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/> <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:com.hp.oval:tst:13"/> <criterion comment="Patch PHNE_38458 is installed" test_ref="oval:com.hp.oval:tst:14" negate="true"/> </criteria> </definition> </definitions> <tests> <swlist_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" version="1" id="oval:com.hp.oval:tst:13"> <object object_ref="oval:com.hp.oval:obj:12"/> </swlist_test> <patch53_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" check_existence="at_least_one_exists" comment="Patch PHNE_38458 is installed" check="at least one" version="1" id="oval:com.hp.oval:tst:14"> <object object_ref="oval:com.hp.oval:obj:13"/> </patch53_test> <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3704" version="1" comment="HP Release B.11.11" check_existence="at_least_one_exists" check="all"> <object object_ref="oval:org.mitre.oval:obj:2759"/> <state state_ref="oval:org.mitre.oval:ste:3389"/> </uname_test> </tests> <objects> <swlist_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.oval:obj:12"> <swlist>InternetSrvcs.INETSVCS-RUN</swlist> </swlist_object> <patch53_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" version="1" id="oval:com.hp.oval:obj:13"> <behaviors supersedence="true"/> <swtype>PH</swtype> <area_patched>NE</area_patched> <patch_base>38458</patch_base> </patch53_object> <uname_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object."/> </objects> <states> <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3389" version="1"> <os_release>B.11.11</os_release> </uname_state> </states> </oval_definitions> |
||||||||||||||||||
|
Worrell, Bryan A.
|
Michael,
Thank you for your submission to the OVAL Repository. Your submission has been processed and is available for further community review via the OVAL Repository website. Thanks, Bryan Worrell __ Bryan Worrell The MITRE Corporation bworrell@... >-----Original Message----- >From: Wood, Michael [mailto:michael.wood@...] >Sent: Tuesday, August 12, 2008 4:37 PM >To: oval-discussion-list OVAL Discussion List/Closed Public Discussi >Subject: [OVAL-DISCUSSION-LIST] New HP-UX 11 OVAL > >Here is new HP-UX 11 OVAL we would like to submit. The file hp-ux- >11.xml contains > >oval:com.hp.oval:def:6 - CVE-2008-1668 > >Thanks, > >Michael Wood >Hewlett-Packard > >To unsubscribe, send an email message to LISTSERV@... with >SIGNOFF OVAL-DISCUSSION-LIST >in the BODY of the message. If you have difficulties, write to OVAL- >DISCUSSION-LIST-request@.... To unsubscribe, send an email message to LISTSERV@... with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to OVAL-DISCUSSION-LIST-request@.... |
||||||||||||||||||
| Free Forum Powered by Nabble | Forum Help |