OVAL for Sun Alert 268288

4 messages Options
Embed this post
Permalink
Peng, Pai

OVAL for Sun Alert 268288

Reply Threaded More More options
Print post
Permalink
Some javascript/style in this post has been disabled (why?)

I'd like to submit one OVAL definition to cover CVE-2009-3746.

 

Thanks,

Pai

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].
<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:sol-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd">
  <generator>
    <oval:product_name>Hewlett-Packard</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-02T17:25:38.000-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:com.hp.temp.oval:def:20091102001" version="0" class="vulnerability">
      <metadata>
        <title>A Regression in the Solaris 10 Gnome-XScreenSaver (see xscreensaver(1)) may Allow Pop-up Windows to Appear through XScreenSaver when the Accessibility Feature is On</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3746" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3746"/>
        <description>XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-02T17:25:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR" comment="patch 120094-27 or 120094-28 installed">
            <criterion comment="Patch 120094-27 installed" test_ref="oval:com.hp.temp.oval:tst:20091102001"/>
            <criterion comment="Patch 120094-28 installed" test_ref="oval:com.hp.temp.oval:tst:20091102002"/>
          </criteria>
          <criterion comment="Patch 120094-29 or later installed" test_ref="oval:com.hp.temp.oval:tst:20091102003" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR" comment="patch 120095-27 or 120095-28 installed">
            <criterion comment="Patch 120095-27 installed" test_ref="oval:com.hp.temp.oval:tst:20091102004"/>
            <criterion comment="Patch 120095-28 installed" test_ref="oval:com.hp.temp.oval:tst:20091102005"/>
          </criteria>
          <criterion comment="Patch 120095-29 or later installed" test_ref="oval:com.hp.temp.oval:tst:20091102006" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1440" version="1" class="inventory">
      <metadata>
        <title>Solaris 10 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.10::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 10 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T21:53:52.343-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:49.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1926" version="1" class="inventory">
      <metadata>
        <title>Solaris 10 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.10::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 10 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T21:53:53.007-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:51.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120094-27 installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102001">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102001"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102001"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120094-28 installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102002">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102001"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102002"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120094-29 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102003">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102001"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102003"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120095-27 installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102004">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102002"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102001"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120095-28 installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102005">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102002"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102002"/>
    </patch_test>
    <patch_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" check_existence="at_least_one_exists" comment="Patch 120095-29 or later installed" check="at least one" version="1" id="oval:com.hp.temp.oval:tst:20091102006">
      <object object_ref="oval:com.hp.temp.oval:obj:20091102002"/>
      <state state_ref="oval:com.hp.temp.oval:ste:20091102003"/>
    </patch_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3237" version="1" comment="sparc architecture" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3478"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3680" version="1" comment="Solaris 10 Installed" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3597"/>
    </uname_test>
    <uname_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:tst:3912" version="1" comment="ix86 architecture" check_existence="at_least_one_exists" check="at least one">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3443"/>
    </uname_test>
  </tests>
  <objects>
    <uname_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object."/>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20091102001">
      <base datatype="int">120094</base>
    </patch_object>
    <patch_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" version="1" id="oval:com.hp.temp.oval:obj:20091102002">
      <base datatype="int">120095</base>
    </patch_object>
  </objects>
  <states>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3478" version="1" comment="processor type is SPARC">
      <processor_type operation="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3597" version="1" comment="os release is 5.10">
      <os_release>5.10</os_release>
    </uname_state>
    <uname_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" id="oval:org.mitre.oval:ste:3443" version="1" comment="processor type is ix86">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20091102001">
      <version datatype="int">27</version>
    </patch_state>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20091102002">
      <version datatype="int">28</version>
    </patch_state>
    <patch_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" operator="AND" version="1" id="oval:com.hp.temp.oval:ste:20091102003">
      <version operation="greater than or equal" datatype="int">29</version>
    </patch_state>
  </states>
</oval_definitions>
Lah, Mike M.

Re: OVAL for Sun Alert 268288

Reply Threaded More More options
Print post
Permalink
Some javascript/style in this post has been disabled (why?)

Peng,

 

Thank you for your submission.  I noticed that you are using the deprecated patch_test.  Is it possible to use the newer patch54_test (and the patch54_object) instead?

 

Thanks,

Mike

 

====================================================

Mike Lah

G022 -  Information Assurance Industry Collaboration

The MITRE Corporation

[hidden email]

 

From: Peng, Pai [mailto:[hidden email]]
Sent: Tuesday, November 03, 2009 11:26 AM
To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
Subject: [OVAL-DISCUSSION-LIST] OVAL for Sun Alert 268288

 

I'd like to submit one OVAL definition to cover CVE-2009-3746.

 

Thanks,

Pai

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].
Lah, Mike M.

Re: OVAL for Sun Alert 268288

Reply Threaded More More options
Print post
Permalink
In reply to this post by Peng, Pai
Some javascript/style in this post has been disabled (why?)

Pai,

 

I was wondering if you had a chance to see if the patch54_test would be appropriate for this definition?

 

Thanks,

Mike

 

====================================================

Mike Lah

G022 -  Information Assurance Industry Collaboration

The MITRE Corporation

[hidden email]

 

From: Peng, Pai [mailto:[hidden email]]
Sent: Tuesday, November 03, 2009 11:26 AM
To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
Subject: [OVAL-DISCUSSION-LIST] OVAL for Sun Alert 268288

 

I'd like to submit one OVAL definition to cover CVE-2009-3746.

 

Thanks,

Pai

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].
Peng, Pai

Re: OVAL for Sun Alert 268288

Reply Threaded More More options
Print post
Permalink
Some javascript/style in this post has been disabled (why?)

Mike,

 

We are working on switching from patch_test to the new patch54_test. I will re-submit this OVAL sometime later.

 

Thanks,

Pai

 

From: Lah, Mike M. [mailto:[hidden email]]
Sent: Thursday, November 12, 2009 12:16 PM
To: [hidden email]
Subject: Re: [OVAL-DISCUSSION-LIST] OVAL for Sun Alert 268288

 

Pai,

 

I was wondering if you had a chance to see if the patch54_test would be appropriate for this definition?

 

Thanks,

Mike

 

====================================================

Mike Lah

G022 -  Information Assurance Industry Collaboration

The MITRE Corporation

[hidden email]

 

From: Peng, Pai [mailto:[hidden email]]
Sent: Tuesday, November 03, 2009 11:26 AM
To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
Subject: [OVAL-DISCUSSION-LIST] OVAL for Sun Alert 268288

 

I'd like to submit one OVAL definition to cover CVE-2009-3746.

 

Thanks,

Pai

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].

To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to [hidden email].