OVAL def for CVE-2008-3450

2 Messages Forum Options Options
Embed this topic
Permalink
Hansen, Nick (HP SW DCA)
OVAL def for CVE-2008-3450
Reply Threaded More
Print post
Permalink
Please find the attached OVAL definition covering CVE-2008-3450 (Sun Alert 237986). Please let me know if there are any issue found with it.

Thanks,
--Nick



To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....

<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:sol-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd">
  <generator>
    <oval:product_name>Hewlett-Packard</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2008-08-05T10:37:22.000-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:com.hp.temp.oval:def:20080805001" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the namefs Kernel module may result in Arbitrary Code Execution or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3450"/>
        <description>Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-05T10:37:22.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 114984-02 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805001" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 114985-02 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805002" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114971-03 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805003" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 138570-01 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805004" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 136716-01 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805005" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237986" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 136717-01 or later installed" test_ref="oval:com.hp.temp.oval:tst:20080805006" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2059" version="1" class="inventory">
      <metadata>
        <title>Solaris 8 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.8::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 8 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-10T21:08:51.544-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:15.624-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1440" version="1" class="inventory">
      <metadata>
        <title>Solaris 10 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.10::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 10 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T21:53:52.343-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:49.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1457" version="1" class="inventory">
      <metadata>
        <title>Solaris 9 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.9::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 9 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-10T21:08:48.350-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:14.151-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1539" version="1" class="inventory">
      <metadata>
        <title>Solaris 8 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.8::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 8 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-10T21:08:48.692-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:14.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1926" version="1" class="inventory">
      <metadata>
        <title>Solaris 10 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.10::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 10 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T21:53:53.007-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:51.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1683" version="1" class="inventory">
      <metadata>
        <title>Solaris 9 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.9::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 9 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-10T21:08:49.960-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:14.277-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 114984-02 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805001">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805001"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805001"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 114985-02 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805002">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805002"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805001"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 114971-03 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805003">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805003"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805002"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 138570-01 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805004">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805004"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805003"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 136716-01 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805005">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805005"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805003"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 136717-01 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20080805006">
      <object object_ref="oval:com.hp.temp.oval:obj:20080805006"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20080805003"/>
    </patch_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3172" version="1" comment="Solaris 9 Installed" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3891"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3237" version="1" comment="sparc architecture" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3478"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3437" version="1" comment="Solaris 8 Installed" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3700"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3680" version="1" comment="Solaris 10 Installed" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3597"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3912" version="1" comment="ix86 architecture" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3443"/>
    </uname_test>
  </tests>
  <objects>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805001">
      <base datatype="int">114984</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805002">
      <base datatype="int">114985</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805003">
      <base datatype="int">114971</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805004">
      <base datatype="int">138570</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805005">
      <base datatype="int">136716</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20080805006">
      <base datatype="int">136717</base>
    </patch_object>
    <uname_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object."/>
  </objects>
  <states>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20080805001">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20080805002">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20080805003">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3443" version="1" comment="processor type is ix86">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3478" version="1" comment="processor type is SPARC">
      <processor_type operation="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3597" version="1">
      <os_release>5.10</os_release>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3700" version="1" comment="os release is 5.8">
      <os_release>5.8</os_release>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3891" version="1" comment="os release is 5.9">
      <os_release>5.9</os_release>
    </uname_state>
  </states>
</oval_definitions>

Worrell, Bryan A.
Re: OVAL def for CVE-2008-3450
Reply Threaded More
Print post
Permalink
Nick,

Thank you for your submission to the OVAL Repository.  Your submission
has been processed and is available for further community review via
the OVAL Repository website.

Thanks,
Bryan Worrell



__
Bryan Worrell    
The MITRE Corporation
bworrell@...




>-----Original Message-----
>From: Hansen, Nick [mailto:nick.hansen@...]
>Sent: Tuesday, August 05, 2008 1:24 PM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>Subject: [OVAL-DISCUSSION-LIST] OVAL def for CVE-2008-3450
>
>Please find the attached OVAL definition covering CVE-2008-3450 (Sun
>Alert 237986). Please let me know if there are any issue found with
it.

>
>Thanks,
>--Nick
>
>
>
>To unsubscribe, send an email message to LISTSERV@... with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>DISCUSSION-LIST-request@....

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....