<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
<generator>
<oval:product_name>Oracle Errata System</oval:product_name>
<oval:product_version>Oracle Linux</oval:product_version>
<oval:schema_version>5.11</oval:schema_version>
<oval:timestamp>2024-09-21T19:04:02</oval:timestamp>
</generator>
<definitions>
<definition id="oval:com.oracle.elsa:def:20070640" version="501" class="patch">
<metadata>
<title>
ELSA-2007-0640:  conga security, bug fix, and enhancement update (MODERATE)
</title>
<affected family="unix">
<platform>Oracle Linux 5</platform>

</affected>
<reference source="elsa" ref_id="ELSA-2007-0640" ref_url="https://linux.oracle.com/errata/ELSA-2007-0640.html"/>
<reference source="CVE" ref_id="CVE-2007-4136" ref_url="https://linux.oracle.com/cve/CVE-2007-4136.html"/>

<description>
[0.10.0-6.el5.0.1]
- Replaced Redhat copyrighted and trademarked images in the conga-0.10.0 tarball.

[0.10.0-6]

- Fixed bz253783
- Fixed bz253914 (conga doesn't allow you to reuse nfs export and nfs client resources)
- Fixed bz254038 (Impossible to set many valid quorum disk configurations via conga)
- Fixed bz253994 (Cannot specify multicast address for a cluster)
- Resolves: bz253783, bz253914, bz254038, bz253994

[0.10.0-5]

- Fixed bz249291 (delete node task fails to do all items listed in the help document)
- Fixed bz253341 (failure to start cluster service which had been modifed for correction)
- Related: bz253341
- Resolves: bz249291

[0.10.0-4]

- Fixed bz230451 (fence_xvm.key file is not automatically created. Should have a least a default)
- Fixed bz249097 (allow a space as a valid password char)
- Fixed bz250834 (ZeroDivisionError when attempting to click an empty lvm volume group)
- Fixed bz250443 (storage name warning utility produces a storm of warnings which can lock your browser)
- Resolves: bz249097, bz250443, bz250834
- Related: bz230451

[0.10.0-3]

- Fixed bz245947 (luci/Conga cluster configuration tool not initializing cluster node members)
- Fixed bz249641 (conga is unable to do storage operations if there is an lvm snapshot present)
- Fixed bz249342 (unknown ricci error when adding new node to cluster)
- Fixed bz249291 (delete node task fails to do all items listed in the help document)
- Fixed bz249091 (RFE: tell user they are about to kill all their nodes)
- Fixed bz249066 (AttributeError when attempting to configure a fence device)
- Fixed bz249086 (Unable to add a new fence device to cluster)
- Fixed bz249868 (Use of failover domain not correctly shown)
- Resolves bz245947, bz249641, bz249342, bz249291, bz249091,
- Resolves bz249066, bz249086, bz249868
- Related: bz249351

[0.10.0-2]

- Fixed bz245202 (Conga needs to support Internet Explorer 6.0 and later)
- Fixed bz248317 (luci sets incorrect permissions on /usr/lib64/luci and /var/lib/luci) 
- Resolves: bz245202 bz248317

[0.10.0-1]
- Fixed bz238655 (conga does not set the 'nodename' attribute for manual fencing)
- Fixed bz221899 (Node log displayed in partially random order)
- Fixed bz225782 (Need more luci service information on startup - no info written to log about failed start cause)
- Fixed bz227743 (Intermittent/recurring problem - when cluster is deleted, sometimes a node is not affected)
- Fixed bz227682 (saslauthd[2274]: Deprecated pam_stack module called from service 'ricci')
- Fixed bz238726 (Conga provides no way to remove a dead node from a cluster)
- Fixed bz239389 (conga cluster: make 'enable shared storage' the default)
- Fixed bz239596
- Fixed bz240034 (rpm verify fails on luci)
- Fixed bz240361 (Conga storage UI front-end is too slow rendering storage)
- Fixed bz241415 (Installation using Conga shows 'error' in message during reboot cycle.)
- Fixed bz241418 (Conga tries to configurage cluster snaps, though they are not available.)
- Fixed bz241706 (Eliminate confusion in add fence flow)
- Fixed bz241727 (can't set user permissions in luci)
- Fixed bz242668 (luci init script can return non-LSB-compliant return codes)
- Fixed bz243701 (ricci init script can exit with non-LSB-compliant return codes)
- Fixed bz244146 (Add port number to message when ricci is not started/firewalled on cluster nodes.)
- Fixed bz244878 (Successful login results in an infinite redirection loop with MSIE)
- Fixed bz239388 (conga storage: default VG creation should be clustered if a cluster node)
- Fixed bz239327 (Online User Manual needs modification)
- Fixed bz227852 (Lack of debugging information in logs - support issue)
- Fixed bz245025 (Conga does not accept '&amp;amp;' character in password field for Fence configuration)
- Fixed bz225588 (luci web app does not enforce selection of fence port)
- Fixed bz212022 (cannot create cluster using ip addresses)
- Fixed bz223162 (Error trying to create a new fence device for a cluster node)
- Upgraded to the latest Plone (2.5.3)
- Added a 'reprobe storage' button that invalidates cached storage reports
  and forces a new probe.
- Resolves: bz238655, bz221899, bz225782, bz227682, bz227743, bz239389,
- Resolves: bz239596, bz240034, bz240361, bz241415, bz241418, bz241706,
- Resolves: bz241727, bz242668, bz243701, bz244146, bz244878, bz238726,
- Resolves: bz239388, bz239327, bz227852, bz245025, bz225588, bz212022

</description>
<!--
 ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ 
-->
<advisory>
<severity>MODERATE</severity>
<rights>Copyright 2007 Oracle, Inc.</rights>
<issued date="2007-11-19"/>
<cve cvss2="5/AV:N/AC:L/Au:N/C:N/I:N/A:P" href="https://linux.oracle.com/cve/CVE-2007-4136.html" public="20071114">CVE-2007-4136</cve>


</advisory>
</metadata>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640001" comment="Oracle Linux 5 is installed"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640002" comment="Oracle Linux arch is x86_64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640003" comment="luci is earlier than 0:0.10.0-6.el5.0.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20070640004" comment="luci is signed with the Oracle Linux 5 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640005" comment="ricci is earlier than 0:0.10.0-6.el5.0.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20070640006" comment="ricci is signed with the Oracle Linux 5 key"/>
</criteria>
</criteria>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640007" comment="Oracle Linux arch is i386"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640003" comment="luci is earlier than 0:0.10.0-6.el5.0.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20070640004" comment="luci is signed with the Oracle Linux 5 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20070640005" comment="ricci is earlier than 0:0.10.0-6.el5.0.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20070640006" comment="ricci is signed with the Oracle Linux 5 key"/>
</criteria>
</criteria>
</criteria>
</criteria>
</criteria>

</definition>
</definitions>
<!--
 ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<tests>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640001"  version="501" comment="Oracle Linux 5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640001" />
<state state_ref="oval:com.oracle.elsa:ste:20070640002" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640002"  version="501" comment="Oracle Linux arch is x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640001" />
<state state_ref="oval:com.oracle.elsa:ste:20070640003" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640003"  version="501" comment="luci is earlier than 0:0.10.0-6.el5.0.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640002" />
<state state_ref="oval:com.oracle.elsa:ste:20070640004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640004"  version="501" comment="luci is signed with the Oracle Linux 5 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640002" />
<state state_ref="oval:com.oracle.elsa:ste:20070640001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640005"  version="501" comment="ricci is earlier than 0:0.10.0-6.el5.0.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640003" />
<state state_ref="oval:com.oracle.elsa:ste:20070640004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640006"  version="501" comment="ricci is signed with the Oracle Linux 5 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640003" />
<state state_ref="oval:com.oracle.elsa:ste:20070640001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20070640007"  version="501" comment="Oracle Linux arch is i386" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20070640001" />
<state state_ref="oval:com.oracle.elsa:ste:20070640005" />
</rpminfo_test>

</tests>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ 
-->
<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20070640003" version="501">
<name>ricci</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20070640002" version="501">
<name>luci</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20070640001" version="501">
<name>oraclelinux-release</name>
</rpminfo_object>

</objects>
<states>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20070640001" version="501">
<signature_keyid operation="equals">66ced3de1e5e0159</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20070640002" version="501">
<version operation="pattern match">^5</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20070640003" version="501">
<arch operation="pattern match">x86_64</arch>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20070640004" version="501">
<evr datatype="evr_string" operation="less than">0:0.10.0-6.el5.0.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20070640005" version="501">
<arch operation="pattern match">i386</arch>
</rpminfo_state>

</states>
</oval_definitions>
