<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:apache-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#apache apache-definitions-schema.xsd">
<generator>
<oval:schema_version>5.1</oval:schema_version>
<oval:timestamp>2005-10-12T18:13:45</oval:timestamp>
</generator>
<definitions>
<definition id="oval:org.apache.httpd:def:20092699" version="1" class="vulnerability">
<metadata>
<title>Solaris pollset DoS</title>
<reference source="CVE" ref_id="CVE-2009-2699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2699"/>
<description>
Faulty error handling was found affecting Solaris pollset support
(Event Port backend) caused by a bug in APR.  A remote attacker
could trigger this issue on Solaris servers which used prefork or
event MPMs, resulting in a denial of service.
</description>
<apache_httpd_repository>
<public>20090923</public>
<reported>20090805</reported>
<released>20091005</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2213" comment="the version of httpd is 2.2.13"/>
<criterion test_ref="oval:org.apache.httpd:tst:2212" comment="the version of httpd is 2.2.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20093094" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_ftp DoS</title>
<reference source="CVE" ref_id="CVE-2009-3094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094"/>
<description>
A NULL pointer dereference flaw was found in the mod_proxy_ftp
module. A malicious FTP server to which requests are being proxied
could use this flaw to crash an httpd child process via a malformed
reply to the EPSV or PASV commands, resulting in a limited denial of
service.
</description>
<apache_httpd_repository>
<public>20090802</public>
<reported>20090904</reported>
<released>20091005</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2213" comment="the version of httpd is 2.2.13"/>
<criterion test_ref="oval:org.apache.httpd:tst:2212" comment="the version of httpd is 2.2.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20093095" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_ftp FTP command injection</title>
<reference source="CVE" ref_id="CVE-2009-3095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"/>
<description>
A flaw was found in the mod_proxy_ftp module. In a reverse proxy
configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands
to the FTP server.
</description>
<apache_httpd_repository>
<public>20090803</public>
<reported>20090903</reported>
<released>20091005</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2213" comment="the version of httpd is 2.2.13"/>
<criterion test_ref="oval:org.apache.httpd:tst:2212" comment="the version of httpd is 2.2.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20092412" version="1" class="vulnerability">
<metadata>
<title>APR apr_palloc heap overflow</title>
<reference source="CVE" ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"/>
<description>
A flaw in apr_palloc() in the bundled copy of APR could
cause heap overflows in programs that try to apr_palloc() a user
controlled size.  The Apache HTTP Server itself does not pass 
unsanitized user-provided sizes to this function, so it could only
be triggered through some other application which uses apr_palloc()
in a vulnerable way.
</description>
<apache_httpd_repository>
<public>20090804</public>
<reported>20090727</reported>
<released>20090809</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2212" comment="the version of httpd is 2.2.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091956" version="1" class="vulnerability">
<metadata>
<title>APR-util off-by-one overflow</title>
<reference source="CVE" ref_id="CVE-2009-1956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956"/>
<description>
An off-by-one overflow flaw was found in the way the bundled copy of
the APR-util library processed a variable list of arguments. An
attacker could provide a specially-crafted string as input for the
formatted output conversion routine, which could, on big-endian
platforms, potentially lead to the disclosure of sensitive information
or a denial of service.
</description>
<apache_httpd_repository>
<public>20090424</public>
<reported/>
<released>200900727</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091955" version="1" class="vulnerability">
<metadata>
<title>APR-util XML DoS</title>
<reference source="CVE" ref_id="CVE-2009-1955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1955"/>
<description>
A denial of service flaw was found in the bundled copy of the APR-util
library Extensible Markup Language (XML) parser. A remote attacker
could create a specially-crafted XML document that would cause
excessive memory consumption when processed by the XML decoding
engine.
</description>
<apache_httpd_repository>
<public>20090601</public>
<reported/>
<released>20090727</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091891" version="1" class="vulnerability">
<metadata>
<title>mod_deflate DoS</title>
<reference source="CVE" ref_id="CVE-2009-1891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"/>
<description>
A denial of service flaw was found in the mod_deflate module. This
module continued to compress large files until compression was
complete, even if the network connection that requested the content
was closed before compression completed. This would cause mod_deflate
to consume large amounts of CPU if mod_deflate was enabled for a large
file.</description>
<apache_httpd_repository>
<public>20090626</public>
<reported>20090626</reported>
<released>20090727</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091890" version="1" class="vulnerability">
<metadata>
<title>mod_proxy reverse proxy DoS</title>
<reference source="CVE" ref_id="CVE-2009-1890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890"/>
<description>
A denial of service flaw was found in the mod_proxy module when it was
used as a reverse proxy. A remote attacker could use this flaw to
force a proxy process to consume large amounts of CPU time.
</description>
<apache_httpd_repository>
<public>20090702</public>
<reported>20090630</reported>
<released>20090727</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091195" version="1" class="vulnerability">
<metadata>
<title>AllowOverride Options handling bypass</title>
<reference source="CVE" ref_id="CVE-2009-1195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195"/>
<description>
A flaw was found in the handling of the "Options" and "AllowOverride"
directives.  In configurations using the "AllowOverride" directive
with certain "Options=" arguments, local users were not restricted
from executing commands from a Server-Side-Include script as intended.
</description>
<apache_httpd_repository>
<public>20090422</public>
<reported>20090309</reported>
<released>20090727</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20091191" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_ajp information disclosure</title>
<reference source="CVE" ref_id="CVE-2009-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1191"/>
<description>
An information disclosure flaw was found in mod_proxy_ajp in version
2.2.11 only. In certain
situations, if a user sent a carefully crafted HTTP request, the server
could return a response intended for another user.
</description>
<apache_httpd_repository>
<public>20090421</public>
<reported>20090305</reported>
<released>20090727</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20090023" version="1" class="vulnerability">
<metadata>
<title>APR-util heap underwrite</title>
<reference source="CVE" ref_id="CVE-2009-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0023"/>
<description>
A heap-based underwrite flaw was found in the way the bundled copy of
the APR-util library created compiled forms of particular search
patterns. An attacker could formulate a specially-crafted search
keyword, that would overwrite arbitrary heap memory locations when
processed by the pattern preparation engine.
</description>
<apache_httpd_repository>
<public>20090601</public>
<reported/>
<released>20090727</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2211" comment="the version of httpd is 2.2.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20082939" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_ftp globbing XSS</title>
<reference source="CVE" ref_id="CVE-2008-2939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2939"/>
<description>
A flaw was found in the handling of wildcards in the path of a FTP
URL with mod_proxy_ftp.  If mod_proxy_ftp is enabled to support
FTP-over-HTTP, requests containing globbing characters could lead
to cross-site scripting (XSS) attacks.</description>
<apache_httpd_repository>
<public>20080805</public>
<reported>20080728</reported>
<released>20081031</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:229" comment="the version of httpd is 2.2.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2063" comment="the version of httpd is 2.0.63"/>
<criterion test_ref="oval:org.apache.httpd:tst:2061" comment="the version of httpd is 2.0.61"/>
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20082364" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_http DoS</title>
<reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
<description>
A flaw was found in the handling of excessive interim responses
from an origin server when using mod_proxy_http.  A remote attacker
could cause a denial of service or high memory usage.</description>
<apache_httpd_repository>
<public>20080610</public>
<reported>20080529</reported>
<released>20080614</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20076420" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_balancer CSRF</title>
<reference source="CVE" ref_id="CVE-2007-6420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6420"/>
<description>
The mod_proxy_balancer provided an administrative interface that could be
vulnerable to cross-site request forgery (CSRF) attacks.
</description>
<apache_httpd_repository>
<public>20080109</public>
<reported>20071012</reported>
<released>20080614</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:228" comment="the version of httpd is 2.2.8"/>
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20076388" version="1" class="vulnerability">
<metadata>
<title>mod_status XSS</title>
<reference source="CVE" ref_id="CVE-2007-6388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6388"/>
<description>
A flaw was found in the mod_status module. On sites where mod_status is
enabled and the status pages were publicly accessible, a cross-site
scripting attack is possible.
Note that the server-status page is not enabled by default and it is best practice to not make this publicly available.</description>
<apache_httpd_repository>
<public>20080102</public>
<reported>20071215</reported>
<released>20080119</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2061" comment="the version of httpd is 2.0.61"/>
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1339" comment="the version of httpd is 1.3.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:1337" comment="the version of httpd is 1.3.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:1336" comment="the version of httpd is 1.3.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:1335" comment="the version of httpd is 1.3.35"/>
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20075000" version="1" class="vulnerability">
<metadata>
<title>mod_imagemap XSS</title>
<reference source="CVE" ref_id="CVE-2007-5000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000"/>
<description>
A flaw was found in the mod_imagemap module. On sites where
mod_imagemap is enabled and an imagemap file is publicly available, a
cross-site scripting attack is possible.</description>
<apache_httpd_repository>
<public>20071211</public>
<reported>20071023</reported>
<released>20080119</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2061" comment="the version of httpd is 2.0.61"/>
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1339" comment="the version of httpd is 1.3.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:1337" comment="the version of httpd is 1.3.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:1336" comment="the version of httpd is 1.3.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:1335" comment="the version of httpd is 1.3.35"/>
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20080005" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_ftp UTF-7 XSS</title>
<reference source="CVE" ref_id="CVE-2008-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0005"/>
<description>
A workaround was added in the mod_proxy_ftp module. On sites where
mod_proxy_ftp is enabled and a forward proxy is configured, a
cross-site scripting attack is possible against Web browsers which do
not correctly derive the response character set following the rules in
RFC 2616. 
</description>
<apache_httpd_repository>
<public>20080108</public>
<reported>20071215</reported>
<released>20080119</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2061" comment="the version of httpd is 2.0.61"/>
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20076422" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_balancer DoS</title>
<reference source="CVE" ref_id="CVE-2007-6422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6422"/>
<description>
A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer is enabled, an authorized user could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. This could lead to a denial of service if using a
threaded Multi-Processing Module. </description>
<apache_httpd_repository>
<public>20080102</public>
<reported>20071212</reported>
<released>20080119</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20076421" version="1" class="vulnerability">
<metadata>
<title>mod_proxy_balancer XSS</title>
<reference source="CVE" ref_id="CVE-2007-6421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6421"/>
<description>
A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer is enabled, a cross-site scripting attack against an
authorized user is possible. </description>
<apache_httpd_repository>
<public>20080102</public>
<reported>20071212</reported>
<released>20080119</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:226" comment="the version of httpd is 2.2.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:225" comment="the version of httpd is 2.2.5"/>
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20073847" version="1" class="vulnerability">
<metadata>
<title>mod_proxy crash</title>
<reference source="CVE" ref_id="CVE-2007-3847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3847"/>
<description>
A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module.</description>
<apache_httpd_repository>
<public>20061210</public>
<reported>20061210</reported>
<released>20070907</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20065752" version="1" class="vulnerability">
<metadata>
<title>mod_status cross-site scripting</title>
<reference source="CVE" ref_id="CVE-2006-5752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752"/>
<description>
A flaw was found in the mod_status module. On sites where the
server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack.
Note that the server-status
page is not enabled by default and it is best practice to not make
this publicly available.</description>
<apache_httpd_repository>
<public>20070620</public>
<reported>20061019</reported>
<released>20070907</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1337" comment="the version of httpd is 1.3.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:1336" comment="the version of httpd is 1.3.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:1335" comment="the version of httpd is 1.3.35"/>
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20073304" version="1" class="vulnerability">
<metadata>
<title>Signals to arbitrary processes</title>
<reference source="CVE" ref_id="CVE-2007-3304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304"/>
<description>The Apache HTTP server did not verify that a process
was an Apache child process before sending it signals. A local
attacker with the ability to run scripts on the HTTP server could
manipulate the scoreboard and cause arbitrary processes to be
terminated which could lead to a denial of service.</description>
<apache_httpd_repository>
<public>20070619</public>
<reported>20060515</reported>
<released>20070907</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1337" comment="the version of httpd is 1.3.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:1336" comment="the version of httpd is 1.3.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:1335" comment="the version of httpd is 1.3.35"/>
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20071862" version="1" class="vulnerability">
<metadata>
<title>mod_cache information leak</title>
<reference source="CVE" ref_id="CVE-2007-1862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1862"/>
<description>The recall_headers function in mod_mem_cache in Apache 2.2.4 did not
properly copy all levels of header data, which can cause Apache to
return HTTP headers containing previously used data, which could be
used by remote attackers to obtain potentially sensitive information.
</description>
<apache_httpd_repository>
<public>20070601</public>
<reported>20070426</reported>
<released>20070907</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20071863" version="1" class="vulnerability">
<metadata>
<title>mod_cache proxy DoS</title>
<reference source="CVE" ref_id="CVE-2007-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863"/>
<description>A bug was found in the mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module.</description>
<apache_httpd_repository>
<public>20070618</public>
<reported>20070502</reported>
<released>20070907</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2059" comment="the version of httpd is 2.0.59"/>
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:224" comment="the version of httpd is 2.2.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:223" comment="the version of httpd is 2.2.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20063747" version="1" class="vulnerability">
<metadata>
<title>mod_rewrite off-by-one error</title>
<reference source="CVE" ref_id="CVE-2006-3747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3747"/>
<description>
An off-by-one flaw exists in the Rewrite module, mod_rewrite.
Depending on the manner in which Apache httpd was compiled, this
software defect may result in a vulnerability which, in combination
with certain types of Rewrite rules in the web server configuration
files, could be triggered remotely.  For vulnerable builds, the nature
of the vulnerability can be denial of service (crashing of web server
processes) or potentially allow arbitrary code execution.
</description>
<apache_httpd_repository>
<public>20060727</public>
<reported>20060721</reported>
<released>20060727</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:222" comment="the version of httpd is 2.2.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2058" comment="the version of httpd is 2.0.58"/>
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1336" comment="the version of httpd is 1.3.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:1335" comment="the version of httpd is 1.3.35"/>
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20053357" version="1" class="vulnerability">
<metadata>
<title>mod_ssl access control DoS</title>
<reference source="CVE" ref_id="CVE-2005-3357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3357"/>
<description>
A NULL pointer dereference flaw in mod_ssl was discovered affecting server
configurations where an SSL virtual host is configured with access control
and a custom 400 error document. A remote attacker could send a carefully
crafted request to trigger this issue which would lead to a crash. This
crash would only be a denial of service if using the worker MPM.
</description>
<apache_httpd_repository>
<public>20051212</public>
<reported>20051205</reported>
<released>20060501</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20053352" version="1" class="vulnerability">
<metadata>
<title>mod_imap Referer Cross-Site Scripting</title>
<reference source="CVE" ref_id="CVE-2005-3352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3352"/>
<description>
A flaw in mod_imap when using the Referer directive with image maps.
In certain site configurations a remote attacker could perform a cross-site
scripting attack if a victim can be forced to visit a malicious 
URL using certain web browsers.  
</description>
<apache_httpd_repository>
<public>20051212</public>
<reported>20051101</reported>
<released>20060501</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:220" comment="the version of httpd is 2.2.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2055" comment="the version of httpd is 2.0.55"/>
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20063918" version="1" class="vulnerability">
<metadata>
<title>Expect header Cross-Site Scripting</title>
<reference source="CVE" ref_id="CVE-2006-3918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3918"/>
<description>
A flaw in the handling of invalid Expect headers.  If an attacker can
influence the Expect header that a victim sends to a target site they
could perform a cross-site scripting attack.  It is known that 
some versions of Flash can set an arbitrary Expect header which can 
trigger this flaw.  Not marked as a security issue for 2.0 or
2.2 as the cross-site scripting is only returned to the victim after
the server times out a connection.
</description>
<apache_httpd_repository>
<public>20060508</public>
<reported/>
<released>20060501</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1334" comment="the version of httpd is 1.3.34"/>
<criterion test_ref="oval:org.apache.httpd:tst:1333" comment="the version of httpd is 1.3.33"/>
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20052970" version="1" class="vulnerability">
<metadata>
<title>Worker MPM memory leak</title>
<reference source="CVE" ref_id="CVE-2005-2970" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2970"/>
<description>
A memory leak in the worker MPM would allow remote attackers to cause
a denial of service (memory consumption) via aborted connections,
which prevents the memory for the transaction pool from being reused
for other connections.  This issue was downgraded in severity to low
(from moderate) as sucessful exploitation of the race condition would
be difficult.
</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20051014</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20052728" version="1" class="vulnerability">
<metadata>
<title>Byterange filter DoS</title>
<reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
<description>
A flaw in the byterange filter would cause some responses to be buffered
into memory. If a server has a dynamic resource such as a CGI
script or PHP script which generates a large amount of data, an attacker
could send carefully crafted requests in order to consume resources,
potentially leading to a Denial of Service. 
</description>
<apache_httpd_repository>
<public>20050707</public>
<reported>20050707</reported>
<released>20051014</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20052700" version="1" class="vulnerability">
<metadata>
<title>SSLVerifyClient bypass</title>
<reference source="CVE" ref_id="CVE-2005-2700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2700"/>
<description>
A flaw in the mod_ssl handling of the "SSLVerifyClient"
directive. This flaw would occur if a virtual host has been configured
using "SSLVerifyClient optional" and further a directive "SSLVerifyClient
required" is set for a specific location.  For servers configured in this
fashion, an attacker may be able to access resources that should otherwise
be protected, by not supplying a client certificate when connecting.
</description>
<apache_httpd_repository>
<public>20050830</public>
<reported>20050830</reported>
<released>20051014</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20052491" version="1" class="vulnerability">
<metadata>
<title>PCRE overflow</title>
<reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
<description>
An integer overflow flaw was found in PCRE, a Perl-compatible regular
expression library included within httpd.  A local user who has the
ability to create .htaccess files could create a maliciously crafted
regular expression in such as way that they could gain the privileges
of a httpd child.
</description>
<apache_httpd_repository>
<public>20050801</public>
<reported/>
<released>20051014</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20052088" version="1" class="vulnerability">
<metadata>
<title>HTTP Request Spoofing</title>
<reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
<description>
A flaw occured when using the Apache server as a HTTP proxy. A remote
attacker could send a HTTP request with both a "Transfer-Encoding:
chunked" header and a Content-Length header, causing Apache to
incorrectly handle and forward the body of the request in a way that
causes the receiving server to process it as a separate HTTP request.
This could allow the bypass of web application firewall protection or
lead to cross-site scripting (XSS) attacks.
</description>
<apache_httpd_repository>
<public>20050611</public>
<reported/>
<released>20051014</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20051268" version="1" class="vulnerability">
<metadata>
<title>Malicious CRL off-by-one</title>
<reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
<description>
An off-by-one stack overflow was discovered in the mod_ssl CRL
verification callback. In order to exploit this issue the Apache
server would need to be configured to use a malicious certificate
revocation list (CRL)
</description>
<apache_httpd_repository>
<public>20050608</public>
<reported/>
<released>20051014</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2054" comment="the version of httpd is 2.0.54"/>
<criterion test_ref="oval:org.apache.httpd:tst:2053" comment="the version of httpd is 2.0.53"/>
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040942" version="1" class="vulnerability">
<metadata>
<title>Memory consumption DoS</title>
<reference source="CVE" ref_id="CVE-2004-0942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0942"/>
<description>
An issue was discovered where the field length limit was not enforced
for certain malicious requests.  This could allow a remote attacker who
is able to send large amounts of data to a server the ability to cause
Apache children to consume proportional amounts of memory, leading to
a denial of service.
</description>
<apache_httpd_repository>
<public>20041101</public>
<reported>20041028</reported>
<released>20050208</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040940" version="1" class="vulnerability">
<metadata>
<title>mod_include overflow</title>
<reference source="CVE" ref_id="CVE-2004-0940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0940"/>
<description>
A buffer overflow in mod_include could allow a local user who
is authorised to create server side include (SSI) files to gain
the privileges of a httpd child.
</description>
<apache_httpd_repository>
<public>20041021</public>
<reported>20041021</reported>
<released>20041028</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1332" comment="the version of httpd is 1.3.32"/>
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040885" version="1" class="vulnerability">
<metadata>
<title>SSLCipherSuite bypass</title>
<reference source="CVE" ref_id="CVE-2004-0885" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0885"/>
<description>
An issue has been discovered in the mod_ssl module when configured to use
the "SSLCipherSuite" directive in directory or location context. If a
particular location context has been configured to require a specific set
of cipher suites, then a client will be able to access that location using
any cipher suite allowed by the virtual host configuration. 
</description>
<apache_httpd_repository>
<public>20041001</public>
<reported>20041001</reported>
<released>20050208</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20041834" version="1" class="vulnerability">
<metadata>
<title>mod_disk_cache stores sensitive headers</title>
<reference source="CVE" ref_id="CVE-2004-1834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1834"/>
<description>
The experimental mod_disk_cache module stored client authentication
credentials for cached objects such as proxy authentication credentials
and Basic Authentication passwords on disk.  
</description>
<apache_httpd_repository>
<public>20040320</public>
<reported>20040302</reported>
<released>20050208</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2052" comment="the version of httpd is 2.0.52"/>
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040811" version="1" class="vulnerability">
<metadata>
<title>Basic authentication bypass</title>
<reference source="CVE" ref_id="CVE-2004-0811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0811"/>
<description>
A flaw in Apache 2.0.51 (only) broke the merging of the Satisfy
directive which could result in access being granted to
resources despite any configured authentication
</description>
<apache_httpd_repository>
<public>20040918</public>
<reported>20040918</reported>
<released>20040928</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2051" comment="the version of httpd is 2.0.51"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040786" version="1" class="vulnerability">
<metadata>
<title>IPv6 URI parsing heap overflow</title>
<reference source="CVE" ref_id="CVE-2004-0786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0786"/>
<description>
Testing using the Codenomicon HTTP Test Tool performed by the Apache
Software Foundation security group and Red Hat uncovered an input
validation issue in the IPv6 URI parsing routines in the apr-util library.
If a remote attacker sent a request including a carefully crafted URI, an
httpd child process could be made to crash.  One some BSD systems it
is believed this flaw may be able to lead to remote code execution.
</description>
<apache_httpd_repository>
<public>20040915</public>
<reported>20040825</reported>
<released>20040915</released>
<severity level="1">critical</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040747" version="1" class="vulnerability">
<metadata>
<title>Environment variable expansion flaw</title>
<reference source="CVE" ref_id="CVE-2004-0747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0747"/>
<description>
The Swedish IT Incident Centre (SITIC) reported a buffer overflow in the
expansion of environment variables during configuration file parsing. This
issue could allow a local user to gain the privileges of a httpd
child if a server can be forced to parse a carefully crafted .htaccess file 
written by a local user.
</description>
<apache_httpd_repository>
<public>20040915</public>
<reported>20040805</reported>
<released>20040915</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040751" version="1" class="vulnerability">
<metadata>
<title>Malicious SSL proxy can cause crash</title>
<reference source="CVE" ref_id="CVE-2004-0751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0751"/>
<description>
An issue was discovered in the mod_ssl module in Apache 2.0.44-2.0.50
which could be triggered if
the server is configured to allow proxying to a remote SSL server. A
malicious remote SSL server could force an httpd child process to crash by
sending a carefully crafted response header. This issue is not believed to
allow execution of arbitrary code and will only result in a denial
of service where a threaded process model is in use.
</description>
<apache_httpd_repository>
<public>20040707</public>
<reported>20040707</reported>
<released>20040915</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040748" version="1" class="vulnerability">
<metadata>
<title>SSL connection infinite loop</title>
<reference source="CVE" ref_id="CVE-2004-0748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0748"/>
<description>
An issue was discovered in the mod_ssl module in Apache 2.0.  
A remote attacker who forces an SSL connection to
be aborted in a particular state may cause an Apache child process to
enter an infinite loop, consuming CPU resources.
</description>
<apache_httpd_repository>
<public>20040707</public>
<reported>20040707</reported>
<released>20040915</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040809" version="1" class="vulnerability">
<metadata>
<title>WebDAV remote crash</title>
<reference source="CVE" ref_id="CVE-2004-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0809"/>
<description>
An issue was discovered in the mod_dav module which could be triggered
for a location where WebDAV authoring access has been configured. A
malicious remote client which is authorized to use the LOCK method
could force an httpd child process to crash by sending a particular
sequence of LOCK requests. This issue does not allow execution of
arbitrary code.  and will only result in a denial of service where a
threaded process model is in use.
</description>
<apache_httpd_repository>
<public>20040912</public>
<reported>20040912</reported>
<released>20040915</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2050" comment="the version of httpd is 2.0.50"/>
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040493" version="1" class="vulnerability">
<metadata>
<title>Header parsing memory leak</title>
<reference source="CVE" ref_id="CVE-2004-0493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0493"/>
<description>
A memory leak in parsing of HTTP headers which can be triggered
remotely may allow a denial of service attack due to excessive memory
consumption.
</description>
<apache_httpd_repository>
<public>20040701</public>
<reported>20040613</reported>
<released>20040701</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040488" version="1" class="vulnerability">
<metadata>
<title>FakeBasicAuth overflow</title>
<reference source="CVE" ref_id="CVE-2004-0488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0488"/>
<description>
A buffer overflow in the mod_ssl FakeBasicAuth code could be exploited
by an attacker using a (trusted) client certificate with a subject DN
field which exceeds 6K in length.
</description>
<apache_httpd_repository>
<public>20040517</public>
<reported/>
<released>20040701</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2049" comment="the version of httpd is 2.0.49"/>
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040492" version="1" class="vulnerability">
<metadata>
<title>mod_proxy buffer overflow</title>
<reference source="CVE" ref_id="CVE-2004-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492"/>
<description>
A buffer overflow was found in the Apache proxy module, mod_proxy, which
can be triggered by receiving an invalid Content-Length header. In order
to exploit this issue an attacker would need to get an Apache installation
that was configured as a proxy to connect to a malicious site. This would
cause the Apache child processing the request to crash, although this does
not represent a significant Denial of Service attack as requests will
continue to be handled by other Apache child processes.  This issue may
lead to remote arbitrary code execution on some BSD platforms.
</description>
<apache_httpd_repository>
<public>20030610</public>
<reported>20030608</reported>
<released>20041020</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1331" comment="the version of httpd is 1.3.31"/>
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030020" version="1" class="vulnerability">
<metadata>
<title>Error log escape filtering</title>
<reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
<description>
Apache does not filter terminal escape sequences from error logs,
which could make it easier for attackers to insert those sequences
into terminal emulators containing vulnerabilities related to escape
sequences.
</description>
<apache_httpd_repository>
<public>20030224</public>
<reported>20030224</reported>
<released>20040512</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030987" version="1" class="vulnerability">
<metadata>
<title>mod_digest nonce checking</title>
<reference source="CVE" ref_id="CVE-2003-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987"/>
<description>

mod_digest does not properly verify the nonce of a client response by
using a AuthNonce secret.  This could allow a malicious user who is
able to sniff network traffic to conduct a replay attack against a
website using Digest protection.  Note that mod_digest implements an
older version of the MD5 Digest Authentication specification which
is known not to work with modern browsers.  This issue does not affect
mod_auth_digest.

</description>
<apache_httpd_repository>
<public>20031218</public>
<reported>20031218</reported>
<released>20040512</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040174" version="1" class="vulnerability">
<metadata>
<title>listening socket starvation</title>
<reference source="CVE" ref_id="CVE-2004-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174"/>
<description>
A starvation issue on listening sockets occurs when a short-lived
connection on a rarely-accessed listening socket will cause a child to
hold the accept mutex and block out new connections until another
connection arrives on that rarely-accessed listening socket.  This
issue is known to affect some versions of AIX, Solaris, and Tru64; it
is known to not affect FreeBSD or Linux.

</description>
<apache_httpd_repository>
<public>20040318</public>
<reported>20040225</reported>
<released>20040512</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030993" version="1" class="vulnerability">
<metadata>
<title>Allow/Deny parsing on big-endian 64-bit platforms</title>
<reference source="CVE" ref_id="CVE-2003-0993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993"/>
<description>
A bug in the parsing of Allow/Deny rules using IP addresses
without a netmask on big-endian 64-bit platforms causes the rules
to fail to match.
</description>
<apache_httpd_repository>
<public>20031015</public>
<reported>20031015</reported>
<released>20040512</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1329" comment="the version of httpd is 1.3.29"/>
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20040113" version="1" class="vulnerability">
<metadata>
<title>mod_ssl memory leak</title>
<reference source="CVE" ref_id="CVE-2004-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0113"/>
<description>
A memory leak in mod_ssl allows a remote denial of service attack 
against an SSL-enabled server by sending plain HTTP requests to the
SSL port. 
</description>
<apache_httpd_repository>
<public>20040220</public>
<reported>20040220</reported>
<released>20040319</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2048" comment="the version of httpd is 2.0.48"/>
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030789" version="1" class="vulnerability">
<metadata>
<title>CGI output information leak</title>
<reference source="CVE" ref_id="CVE-2003-0789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0789"/>
<description>
A bug in mod_cgid mishandling of CGI redirect paths can result in
CGI output going to the wrong client when a threaded MPM
is used.
</description>
<apache_httpd_repository>
<public>20031027</public>
<reported>20031003</reported>
<released>20031027</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030542" version="1" class="vulnerability">
<metadata>
<title>Local configuration regular expression overflow</title>
<reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
<description>
By using a regular expression with more than 9 captures a buffer
overflow can occur in mod_alias or mod_rewrite.  To exploit this an
attacker would need to be able to create a carefully crafted configuration
file (.htaccess or httpd.conf)
</description>
<apache_httpd_repository>
<public>20031027</public>
<reported>20030804</reported>
<released>20031027</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1328" comment="the version of httpd is 1.3.28"/>
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2047" comment="the version of httpd is 2.0.47"/>
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030460" version="1" class="vulnerability">
<metadata>
<title>RotateLogs DoS</title>
<reference source="CVE" ref_id="CVE-2003-0460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0460"/>
<description>The rotatelogs support program on Win32 and OS/2 would quit logging
and exit if it received special control characters such as 0x1A.
</description>
<apache_httpd_repository>
<public>20030718</public>
<reported>20030704</reported>
<released>20030718</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1327" comment="the version of httpd is 1.3.27"/>
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030254" version="1" class="vulnerability">
<metadata>
<title>Remote DoS via IPv6 ftp proxy</title>
<reference source="CVE" ref_id="CVE-2003-0254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0254"/>
<description>
When a client requests that proxy ftp connect to a ftp server with
IPv6 address, and the proxy is unable to create an IPv6 socket,
an infinite loop occurs causing a remote Denial of Service.
</description>
<apache_httpd_repository>
<public>20030709</public>
<reported>20030625</reported>
<released>20030709</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030253" version="1" class="vulnerability">
<metadata>
<title>Remote DoS with multiple Listen directives</title>
<reference source="CVE" ref_id="CVE-2003-0253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0253"/>
<description>
In a server with multiple listening sockets a certain error returned
by accept() on a rarely access port can cause a temporary denial of
service, due to a bug in the prefork MPM.
</description>
<apache_httpd_repository>
<public>20030709</public>
<reported>20030625</reported>
<released>20030709</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030192" version="1" class="vulnerability">
<metadata>
<title>mod_ssl renegotiation issue</title>
<reference source="CVE" ref_id="CVE-2003-0192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0192"/>
<description>
A bug in the optional renegotiation code in mod_ssl included with 
Apache httpd can cause cipher suite restrictions to be ignored.
This is triggered if optional renegotiation is used (SSLOptions
+OptRenegotiate) along with verification of client certificates
and a change to the cipher suite over the renegotiation.
</description>
<apache_httpd_repository>
<public>20030709</public>
<reported>20030430</reported>
<released>20030709</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2046" comment="the version of httpd is 2.0.46"/>
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030245" version="1" class="vulnerability">
<metadata>
<title>APR remote crash</title>
<reference source="CVE" ref_id="CVE-2003-0245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0245"/>
<description>
A vulnerability in the apr_psprintf function in the Apache Portable
Runtime (APR) library allows remote 
attackers to cause a denial of service (crash) and possibly execute
arbitrary code via long strings, as demonstrated using XML objects to
mod_dav, and possibly other vectors.
</description>
<apache_httpd_repository>
<public>20030528</public>
<reported>20030409</reported>
<released>20030528</released>
<severity level="1">critical</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030189" version="1" class="vulnerability">
<metadata>
<title>Basic Authentication DoS</title>
<reference source="CVE" ref_id="CVE-2003-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0189"/>
<description>
A build system problem in Apache 2.0.40 through 2.0.45 allows remote attackers
to cause a denial of access to authenticated content when a threaded
server is used. 
</description>
<apache_httpd_repository>
<public>20030528</public>
<reported>20030425</reported>
<released>20030528</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030134" version="1" class="vulnerability">
<metadata>
<title>OS2 device name DoS</title>
<reference source="CVE" ref_id="CVE-2003-0134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0134"/>
<description>
Apache on OS2 up to and including Apache 2.0.45
have a Denial of Service vulnerability caused by 
device names.
</description>
<apache_httpd_repository>
<public>20030331</public>
<reported/>
<released>20030528</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030083" version="1" class="vulnerability">
<metadata>
<title>Filtered escape sequences</title>
<reference source="CVE" ref_id="CVE-2003-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0083"/>
<description>
Apache did not filter terminal escape sequences from its
access logs, which could make it easier for attackers to insert those
sequences into terminal emulators containing vulnerabilities related
to escape sequences.
</description>
<apache_httpd_repository>
<public>20030224</public>
<reported>20030224</reported>
<released>20040402</released>
<severity level="4">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2045" comment="the version of httpd is 2.0.45"/>
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030132" version="1" class="vulnerability">
<metadata>
<title>Line feed memory leak DoS</title>
<reference source="CVE" ref_id="CVE-2003-0132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0132"/>
<description>
Apache 2.0 versions before Apache 2.0.45 had a significant Denial of
Service vulnerability.  Remote attackers could cause a denial of service
(memory consumption) via large chunks of linefeed characters, which
causes Apache to allocate 80 bytes for each linefeed.
</description>
<apache_httpd_repository>
<public>20040402</public>
<reported/>
<released>20040402</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2044" comment="the version of httpd is 2.0.44"/>
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030016" version="1" class="vulnerability">
<metadata>
<title>MS-DOS device name filtering</title>
<reference source="CVE" ref_id="CVE-2003-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0016"/>
<description>On Windows platforms Apache did not 
correctly filter MS-DOS device names which 
could lead to denial of service attacks or remote code execution.
</description>
<apache_httpd_repository>
<public>20030120</public>
<reported>20021204</reported>
<released>20030120</released>
<severity level="1">critical</severity>
<flaw type="msdos-device"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20030017" version="1" class="vulnerability">
<metadata>
<title>Apache can serve unexpected files</title>
<reference source="CVE" ref_id="CVE-2003-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0017"/>
<description>
On Windows platforms Apache could be forced to serve unexpected files
by appending illegal characters such as '&lt;' to the request URL
</description>
<apache_httpd_repository>
<public>20030120</public>
<reported>20021115</reported>
<released>20030120</released>
<severity level="2">important</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2043" comment="the version of httpd is 2.0.43"/>
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020843" version="1" class="vulnerability">
<metadata>
<title>Buffer overflows in ab utility</title>
<reference source="CVE" ref_id="CVE-2002-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0843"/>
<description>Buffer overflows in the benchmarking utility ab could be exploited if
ab is run against a malicious server
</description>
<apache_httpd_repository>
<public>20021003</public>
<reported>20020923</reported>
<released>20021003</released>
<severity level="2">important</severity>
<flaw type="buf"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020839" version="1" class="vulnerability">
<metadata>
<title>Shared memory permissions lead to local privilege escalation</title>
<reference source="CVE" ref_id="CVE-2002-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0839"/>
<description>The permissions of the shared memory used for the scoreboard
allows an attacker who can execute under
the Apache UID to send a signal to any process as root or cause a local 
denial of service attack.
</description>
<apache_httpd_repository>
<public>20021003</public>
<reported>20011111</reported>
<released>20021003</released>
<severity level="2">important</severity>
<flaw type="perm"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020840" version="1" class="vulnerability">
<metadata>
<title>Error page XSS using wildcard DNS</title>
<reference source="CVE" ref_id="CVE-2002-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0840"/>
<description>Cross-site scripting (XSS) vulnerability in the default error page of
Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when
UseCanonicalName is "Off" and support for wildcard DNS is present,
allows remote attackers to execute script as other web page visitors
via the Host: header.</description>
<apache_httpd_repository>
<public>20021002</public>
<reported>20020920</reported>
<released>20021003</released>
<severity level="4">low</severity>
<flaw type="css"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1326" comment="the version of httpd is 1.3.26"/>
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20021156" version="1" class="vulnerability">
<metadata>
<title>CGI scripts source revealed using WebDAV</title>
<reference source="CVE" ref_id="CVE-2002-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1156"/>
<description>In Apache 2.0.42 only, for a location where both WebDAV and CGI were
enabled, a POST request to a CGI script would reveal the CGI source to
a remote user. </description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20021003</released>
<severity level="3">moderate</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2042" comment="the version of httpd is 2.0.42"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20021593" version="1" class="vulnerability">
<metadata>
<title>mod_dav crash</title>
<reference source="CVE" ref_id="CVE-2002-1593" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1593"/>
<description>
A flaw was found in handling of versioning hooks in mod_dav.  An attacker
could send a carefully crafted request in such a way to cause the child
process handling the connection to crash.  This issue will only result
in a denial of service where a threaded process model is in use.
</description>
<apache_httpd_repository>
<public>20020919</public>
<reported/>
<released>20020924</released>
<severity level="3">moderate</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2040" comment="the version of httpd is 2.0.40"/>
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020661" version="1" class="vulnerability">
<metadata>
<title>Path vulnerability</title>
<reference source="CVE" ref_id="CVE-2002-0661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0661"/>
<description>Certain URIs would bypass security
and allow users to invoke or access any file depending on the system 
configuration.  Affects Windows, OS2, Netware and Cygwin platforms
only.</description>
<apache_httpd_repository>
<public>20020809</public>
<reported>20020807</reported>
<released>20020809</released>
<severity level="2">important</severity>
<flaw type="priv"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020654" version="1" class="vulnerability">
<metadata>
<title>Path revealing exposures</title>
<reference source="CVE" ref_id="CVE-2002-0654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0654"/>
<description>A path-revealing exposure was present in multiview type
map negotiation (such as the default error documents) where a
module would report the full path of the typemapped .var file when
multiple documents or no documents could be served.  
Additionally a path-revealing exposure in cgi/cgid when Apache
fails to invoke a script.  The modules would report "couldn't create 
child process /path-to-script/script.pl" revealing the full path
of the script.</description>
<apache_httpd_repository>
<public>20020809</public>
<reported>20020705</reported>
<released>20020809</released>
<severity level="4">low</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2039" comment="the version of httpd is 2.0.39"/>
<criterion test_ref="oval:org.apache.httpd:tst:2037" comment="the version of httpd is 2.0.37"/>
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020392" version="1" class="vulnerability">
<metadata>
<title>Apache Chunked encoding vulnerability</title>
<reference source="CVE" ref_id="CVE-2002-0392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392"/>
<description>Malicious requests can cause various effects
ranging from a relatively harmless increase in
system resources through to denial of service attacks and in some
cases the ability to execute arbitrary remote code.</description>
<apache_httpd_repository>
<public>20020617</public>
<reported>20020527</reported>
<released>20020618</released>
<severity level="1">critical</severity>
<flaw type="buf"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2036" comment="the version of httpd is 2.0.36"/>
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1324" comment="the version of httpd is 1.3.24"/>
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20021592" version="1" class="vulnerability">
<metadata>
<title>Warning messages could be displayed to users</title>
<reference source="CVE" ref_id="CVE-2002-1592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1592"/>
<description>
In some cases warning messages could get returned to end users in 
addition to being recorded in the error log.  This could reveal the
path to a CGI script for example, a minor security exposure.
</description>
<apache_httpd_repository>
<public>20020422</public>
<reported/>
<released>20020508</released>
<severity level="">low</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:2035" comment="the version of httpd is 2.0.35"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20020061" version="1" class="vulnerability">
<metadata>
<title>Win32 Apache Remote command execution</title>
<reference source="CVE" ref_id="CVE-2002-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0061"/>
<description>Apache for Win32 before 1.3.24 and 2.0.34-beta allows remote 
attackers to execute arbitrary commands via parameters passed
to batch file CGI scripts.</description>
<apache_httpd_repository>
<public/>
<reported>20020213</reported>
<released>20020322</released>
<severity level="1">critical</severity>
<flaw type="metachar"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1322" comment="the version of httpd is 1.3.22"/>
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20010729" version="1" class="vulnerability">
<metadata>
<title>Requests can cause directory listing to be displayed</title>
<reference source="CVE" ref_id="CVE-2001-0729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0729"/>
<description>A vulnerability was found in the Win32 port of
Apache 1.3.20.  A client submitting a very long URI
could cause a directory listing to be returned rather than
the default index page. </description>
<apache_httpd_repository>
<public>20010928</public>
<reported>20010918</reported>
<released>20011012</released>
<severity level="2">important</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20010730" version="1" class="vulnerability">
<metadata>
<title>split-logfile can cause arbitrary log files to be written to</title>
<reference source="CVE" ref_id="CVE-2001-0730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0730"/>
<description>A vulnerability was found in the split-logfile support
    program.  A request with a specially crafted Host:
    header could allow any file with a .log extension on 
    the system to be written to. </description>
<apache_httpd_repository>
<public>20010928</public>
<reported/>
<released>20011012</released>
<severity level="3">moderate</severity>
<flaw type="dot"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20010731" version="1" class="vulnerability">
<metadata>
<title>Multiviews can cause a directory listing to be displayed</title>
<reference source="CVE" ref_id="CVE-2001-0731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0731"/>
<description>A vulnerability was found when Multiviews 
    are used to negotiate the directory index.  In some
    configurations, requesting a URI with a QUERY_STRING of 
    M=D could
    return a directory listing rather than the expected index page.</description>
<apache_httpd_repository>
<public>20010709</public>
<reported/>
<released>20011012</released>
<severity level="2">important</severity>
<flaw type="other"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20011342" version="1" class="vulnerability">
<metadata>
<title>Denial of service attack on Win32 and OS2</title>
<reference source="CVE" ref_id="CVE-2001-1342" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1342"/>
<description>A vulnerability was found in the Win32 and OS2 ports of Apache 1.3. A
  client submitting a carefully constructed URI could cause a General
  Protection Fault in a child process, bringing up a message box which
  would have to be cleared by the operator to resume operation. This
  vulnerability introduced no identified means to compromise the server
  other than introducing a possible denial of service. </description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20010522</released>
<severity level="2">important</severity>
<flaw type="dos-malform"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1320" comment="the version of httpd is 1.3.20"/>
<criterion test_ref="oval:org.apache.httpd:tst:1319" comment="the version of httpd is 1.3.19"/>
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20010925" version="1" class="vulnerability">
<metadata>
<title>Requests can cause directory listing to be displayed</title>
<reference source="CVE" ref_id="CVE-2001-0925" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0925"/>
<description>The default installation can lead mod_negotiation and 
    mod_dir or mod_autoindex to display a 
    directory listing instead of the multiview index.html file if a 
    very long path was created artificially by using many slashes.  </description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20010228</released>
<severity level="2">important</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1317" comment="the version of httpd is 1.3.17"/>
<criterion test_ref="oval:org.apache.httpd:tst:1314" comment="the version of httpd is 1.3.14"/>
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20000913" version="1" class="vulnerability">
<metadata>
<title>Rewrite rules that include references allow access to any file</title>
<reference source="CVE" ref_id="CVE-2000-0913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0913"/>
<description>The Rewrite module, mod_rewrite, can allow access to
    any file on the web server.  The vulnerability occurs only with
    certain specific cases of using regular expression references in
    RewriteRule directives:  If the destination
    of a RewriteRule contains regular expression references
    then an attacker will be able to access any file on the server.</description>
<apache_httpd_repository>
<public>20000929</public>
<reported/>
<released>20001013</released>
<severity level="2">important</severity>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20001204" version="1" class="vulnerability">
<metadata>
<title>Mass virtual hosting can display CGI source</title>
<reference source="CVE" ref_id="CVE-2000-1204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1204"/>
<description>A security problem for users of the mass virtual hosting module, 
    mod_vhost_alias, causes
    the source to a CGI to be sent if the cgi-bin directory is 
    under the document root.  However, it is not normal to have your 
    cgi-bin directory under a document root.</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20001013</released>
<severity level="2">important</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20000505" version="1" class="vulnerability">
<metadata>
<title>Requests can cause directory listing to be displayed on NT</title>
<reference source="CVE" ref_id="CVE-2000-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0505"/>
<description>A security hole on Apache for Windows allows a user to 
    view the listing of a 
    directory instead of the default HTML page by sending a carefully 
    constructed request.</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20001013</released>
<severity level="3">moderate</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1312" comment="the version of httpd is 1.3.12"/>
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20001205" version="1" class="vulnerability">
<metadata>
<title>Cross-site scripting can reveal private session information</title>
<reference source="CVE" ref_id="CVE-2000-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1205"/>
<description>Apache was vulnerable to cross site scripting issues.
    It was shown that malicious HTML tags can be embedded in client web 
    requests if the server or script handling the request does not 
    carefully encode all information displayed to 
    the user.  Using these vulnerabilities attackers could, for 
    example, obtain copies of your private 
    cookies used to authenticate
    you to other sites.</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20000225</released>
<severity level="2">important</severity>
<flaw type="css"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:1311" comment="the version of httpd is 1.3.11"/>
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:20001206" version="1" class="vulnerability">
<metadata>
<title>Mass virtual hosting security issue</title>
<reference source="CVE" ref_id="CVE-2000-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1206"/>
<description>A security problem can occur for sites using mass name-based virtual 
hosting (using
the new mod_vhost_alias module) or with special 
mod_rewrite rules.



</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>20000121</released>
<severity level="3">moderate</severity>
<flaw type="unk"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:139" comment="the version of httpd is 1.3.9"/>
<criterion test_ref="oval:org.apache.httpd:tst:136" comment="the version of httpd is 1.3.6"/>
<criterion test_ref="oval:org.apache.httpd:tst:134" comment="the version of httpd is 1.3.4"/>
<criterion test_ref="oval:org.apache.httpd:tst:133" comment="the version of httpd is 1.3.3"/>
<criterion test_ref="oval:org.apache.httpd:tst:132" comment="the version of httpd is 1.3.2"/>
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
<definition id="oval:org.apache.httpd:def:19991199" version="1" class="vulnerability">
<metadata>
<title>Multiple header Denial of Service vulnerability</title>
<reference source="CVE" ref_id="CVE-1999-1199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1199"/>
<description>A serious problem exists when a client
sends a large number of headers with the same header name. Apache uses
up memory faster than the amount of memory required to simply store
the received data itself. That is, memory use increases faster and
faster as more headers are received, rather than increasing at a
constant rate. This makes a denial of service attack based on this
method more effective than methods which cause Apache to use memory at
a constant rate, since the attacker has to send less data.</description>
<apache_httpd_repository>
<public/>
<reported/>
<released>19980923</released>
<severity level="2">important</severity>
<flaw type="memleak"/>
</apache_httpd_repository>
</metadata>
<criteria operator="OR">
<criteria operator="OR">
<criterion test_ref="oval:org.apache.httpd:tst:131" comment="the version of httpd is 1.3.1"/>
<criterion test_ref="oval:org.apache.httpd:tst:130" comment="the version of httpd is 1.3.0"/>
</criteria>
</criteria>
</definition>
</definitions>
<tests>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2213" version="1" comment="the version of httpd is 2.2.13" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2213"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2212" version="1" comment="the version of httpd is 2.2.12" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2212"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2211" version="1" comment="the version of httpd is 2.2.11" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2211"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:229" version="1" comment="the version of httpd is 2.2.9" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:229"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:228" version="1" comment="the version of httpd is 2.2.8" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:228"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:226" version="1" comment="the version of httpd is 2.2.6" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:226"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:225" version="1" comment="the version of httpd is 2.2.5" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:225"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:224" version="1" comment="the version of httpd is 2.2.4" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:224"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:223" version="1" comment="the version of httpd is 2.2.3" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:223"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:222" version="1" comment="the version of httpd is 2.2.2" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:222"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:220" version="1" comment="the version of httpd is 2.2.0" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:220"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2063" version="1" comment="the version of httpd is 2.0.63" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2063"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2061" version="1" comment="the version of httpd is 2.0.61" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2061"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2059" version="1" comment="the version of httpd is 2.0.59" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2059"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2058" version="1" comment="the version of httpd is 2.0.58" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2058"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2055" version="1" comment="the version of httpd is 2.0.55" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2055"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2054" version="1" comment="the version of httpd is 2.0.54" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2054"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2053" version="1" comment="the version of httpd is 2.0.53" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2053"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2052" version="1" comment="the version of httpd is 2.0.52" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2052"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2051" version="1" comment="the version of httpd is 2.0.51" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2051"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2050" version="1" comment="the version of httpd is 2.0.50" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2050"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2049" version="1" comment="the version of httpd is 2.0.49" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2049"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2048" version="1" comment="the version of httpd is 2.0.48" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2048"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2047" version="1" comment="the version of httpd is 2.0.47" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2047"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2046" version="1" comment="the version of httpd is 2.0.46" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2046"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2045" version="1" comment="the version of httpd is 2.0.45" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2045"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2044" version="1" comment="the version of httpd is 2.0.44" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2044"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2043" version="1" comment="the version of httpd is 2.0.43" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2043"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2042" version="1" comment="the version of httpd is 2.0.42" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2042"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2040" version="1" comment="the version of httpd is 2.0.40" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2040"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2039" version="1" comment="the version of httpd is 2.0.39" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2039"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2037" version="1" comment="the version of httpd is 2.0.37" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2037"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2036" version="1" comment="the version of httpd is 2.0.36" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2036"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:2035" version="1" comment="the version of httpd is 2.0.35" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:2035"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1339" version="1" comment="the version of httpd is 1.3.39" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1339"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1337" version="1" comment="the version of httpd is 1.3.37" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1337"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1336" version="1" comment="the version of httpd is 1.3.36" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1336"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1335" version="1" comment="the version of httpd is 1.3.35" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1335"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1334" version="1" comment="the version of httpd is 1.3.34" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1334"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1333" version="1" comment="the version of httpd is 1.3.33" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1333"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1332" version="1" comment="the version of httpd is 1.3.32" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1332"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1331" version="1" comment="the version of httpd is 1.3.31" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1331"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1329" version="1" comment="the version of httpd is 1.3.29" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1329"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1328" version="1" comment="the version of httpd is 1.3.28" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1328"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1327" version="1" comment="the version of httpd is 1.3.27" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1327"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1326" version="1" comment="the version of httpd is 1.3.26" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1326"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1324" version="1" comment="the version of httpd is 1.3.24" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1324"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1322" version="1" comment="the version of httpd is 1.3.22" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1322"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1320" version="1" comment="the version of httpd is 1.3.20" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1320"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1319" version="1" comment="the version of httpd is 1.3.19" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1319"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1317" version="1" comment="the version of httpd is 1.3.17" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1317"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1314" version="1" comment="the version of httpd is 1.3.14" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1314"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1312" version="1" comment="the version of httpd is 1.3.12" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1312"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:1311" version="1" comment="the version of httpd is 1.3.11" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:1311"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:139" version="1" comment="the version of httpd is 1.3.9" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:139"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:136" version="1" comment="the version of httpd is 1.3.6" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:136"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:134" version="1" comment="the version of httpd is 1.3.4" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:134"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:133" version="1" comment="the version of httpd is 1.3.3" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:133"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:132" version="1" comment="the version of httpd is 1.3.2" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:132"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:131" version="1" comment="the version of httpd is 1.3.1" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:131"/>
</httpd_test>
<httpd_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:tst:130" version="1" comment="the version of httpd is 1.3.0" check="at least one">
<object object_ref="oval:org.apache.httpd:obj:1"/>
<state state_ref="oval:org.apache.httpd:ste:130"/>
</httpd_test>
</tests>
<objects>
<httpd_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" comment="the collection apache httpd binaries" version="1" id="oval:org.apache.httpd:obj:1">
<notes xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
<note>This is the single httpd object required by an apache httpd test and represents the collection of all httpd binaries on the system.</note>
</notes>
</httpd_object>
</objects>
<states>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2213" version="1" comment="the version of httpd is 2.2.13">
<version operation="equals" datatype="version">2.2.13</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2212" version="1" comment="the version of httpd is 2.2.12">
<version operation="equals" datatype="version">2.2.12</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2211" version="1" comment="the version of httpd is 2.2.11">
<version operation="equals" datatype="version">2.2.11</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:229" version="1" comment="the version of httpd is 2.2.9">
<version operation="equals" datatype="version">2.2.9</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:228" version="1" comment="the version of httpd is 2.2.8">
<version operation="equals" datatype="version">2.2.8</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:226" version="1" comment="the version of httpd is 2.2.6">
<version operation="equals" datatype="version">2.2.6</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:225" version="1" comment="the version of httpd is 2.2.5">
<version operation="equals" datatype="version">2.2.5</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:224" version="1" comment="the version of httpd is 2.2.4">
<version operation="equals" datatype="version">2.2.4</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:223" version="1" comment="the version of httpd is 2.2.3">
<version operation="equals" datatype="version">2.2.3</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:222" version="1" comment="the version of httpd is 2.2.2">
<version operation="equals" datatype="version">2.2.2</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:220" version="1" comment="the version of httpd is 2.2.0">
<version operation="equals" datatype="version">2.2.0</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2063" version="1" comment="the version of httpd is 2.0.63">
<version operation="equals" datatype="version">2.0.63</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2061" version="1" comment="the version of httpd is 2.0.61">
<version operation="equals" datatype="version">2.0.61</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2059" version="1" comment="the version of httpd is 2.0.59">
<version operation="equals" datatype="version">2.0.59</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2058" version="1" comment="the version of httpd is 2.0.58">
<version operation="equals" datatype="version">2.0.58</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2055" version="1" comment="the version of httpd is 2.0.55">
<version operation="equals" datatype="version">2.0.55</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2054" version="1" comment="the version of httpd is 2.0.54">
<version operation="equals" datatype="version">2.0.54</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2053" version="1" comment="the version of httpd is 2.0.53">
<version operation="equals" datatype="version">2.0.53</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2052" version="1" comment="the version of httpd is 2.0.52">
<version operation="equals" datatype="version">2.0.52</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2051" version="1" comment="the version of httpd is 2.0.51">
<version operation="equals" datatype="version">2.0.51</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2050" version="1" comment="the version of httpd is 2.0.50">
<version operation="equals" datatype="version">2.0.50</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2049" version="1" comment="the version of httpd is 2.0.49">
<version operation="equals" datatype="version">2.0.49</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2048" version="1" comment="the version of httpd is 2.0.48">
<version operation="equals" datatype="version">2.0.48</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2047" version="1" comment="the version of httpd is 2.0.47">
<version operation="equals" datatype="version">2.0.47</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2046" version="1" comment="the version of httpd is 2.0.46">
<version operation="equals" datatype="version">2.0.46</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2045" version="1" comment="the version of httpd is 2.0.45">
<version operation="equals" datatype="version">2.0.45</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2044" version="1" comment="the version of httpd is 2.0.44">
<version operation="equals" datatype="version">2.0.44</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2043" version="1" comment="the version of httpd is 2.0.43">
<version operation="equals" datatype="version">2.0.43</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2042" version="1" comment="the version of httpd is 2.0.42">
<version operation="equals" datatype="version">2.0.42</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2040" version="1" comment="the version of httpd is 2.0.40">
<version operation="equals" datatype="version">2.0.40</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2039" version="1" comment="the version of httpd is 2.0.39">
<version operation="equals" datatype="version">2.0.39</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2037" version="1" comment="the version of httpd is 2.0.37">
<version operation="equals" datatype="version">2.0.37</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2036" version="1" comment="the version of httpd is 2.0.36">
<version operation="equals" datatype="version">2.0.36</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:2035" version="1" comment="the version of httpd is 2.0.35">
<version operation="equals" datatype="version">2.0.35</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1339" version="1" comment="the version of httpd is 1.3.39">
<version operation="equals" datatype="version">1.3.39</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1337" version="1" comment="the version of httpd is 1.3.37">
<version operation="equals" datatype="version">1.3.37</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1336" version="1" comment="the version of httpd is 1.3.36">
<version operation="equals" datatype="version">1.3.36</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1335" version="1" comment="the version of httpd is 1.3.35">
<version operation="equals" datatype="version">1.3.35</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1334" version="1" comment="the version of httpd is 1.3.34">
<version operation="equals" datatype="version">1.3.34</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1333" version="1" comment="the version of httpd is 1.3.33">
<version operation="equals" datatype="version">1.3.33</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1332" version="1" comment="the version of httpd is 1.3.32">
<version operation="equals" datatype="version">1.3.32</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1331" version="1" comment="the version of httpd is 1.3.31">
<version operation="equals" datatype="version">1.3.31</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1329" version="1" comment="the version of httpd is 1.3.29">
<version operation="equals" datatype="version">1.3.29</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1328" version="1" comment="the version of httpd is 1.3.28">
<version operation="equals" datatype="version">1.3.28</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1327" version="1" comment="the version of httpd is 1.3.27">
<version operation="equals" datatype="version">1.3.27</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1326" version="1" comment="the version of httpd is 1.3.26">
<version operation="equals" datatype="version">1.3.26</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1324" version="1" comment="the version of httpd is 1.3.24">
<version operation="equals" datatype="version">1.3.24</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1322" version="1" comment="the version of httpd is 1.3.22">
<version operation="equals" datatype="version">1.3.22</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1320" version="1" comment="the version of httpd is 1.3.20">
<version operation="equals" datatype="version">1.3.20</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1319" version="1" comment="the version of httpd is 1.3.19">
<version operation="equals" datatype="version">1.3.19</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1317" version="1" comment="the version of httpd is 1.3.17">
<version operation="equals" datatype="version">1.3.17</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1314" version="1" comment="the version of httpd is 1.3.14">
<version operation="equals" datatype="version">1.3.14</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1312" version="1" comment="the version of httpd is 1.3.12">
<version operation="equals" datatype="version">1.3.12</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:1311" version="1" comment="the version of httpd is 1.3.11">
<version operation="equals" datatype="version">1.3.11</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:139" version="1" comment="the version of httpd is 1.3.9">
<version operation="equals" datatype="version">1.3.9</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:136" version="1" comment="the version of httpd is 1.3.6">
<version operation="equals" datatype="version">1.3.6</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:134" version="1" comment="the version of httpd is 1.3.4">
<version operation="equals" datatype="version">1.3.4</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:133" version="1" comment="the version of httpd is 1.3.3">
<version operation="equals" datatype="version">1.3.3</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:132" version="1" comment="the version of httpd is 1.3.2">
<version operation="equals" datatype="version">1.3.2</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:131" version="1" comment="the version of httpd is 1.3.1">
<version operation="equals" datatype="version">1.3.1</version>
</httpd_state>
<httpd_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#apache" id="oval:org.apache.httpd:ste:130" version="1" comment="the version of httpd is 1.3.0">
<version operation="equals" datatype="version">1.3.0</version>
</httpd_state>
</states>
</oval_definitions>
