Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
tagasulat committed Dec 16, 2016
1 parent a6137b6 commit acdaba6
Show file tree
Hide file tree
Showing 20 changed files with 169 additions and 6 deletions.
@@ -0,0 +1,99 @@
<oval-def:definition xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" class="vulnerability" id="oval:com.dtcc.oval:def:2340" version="0">
<oval-def:metadata>
<oval-def:title>Windows Crypto Driver Information Disclosure Vulnerability - CVE-2016-7219 (MS16-149)</oval-def:title>
<oval-def:affected family="windows">
<oval-def:platform>Microsoft Windows Vista</oval-def:platform>
<oval-def:platform>Microsoft Windows Server 2008</oval-def:platform>
<oval-def:platform>Microsoft Windows Server 2008 R2</oval-def:platform>
<oval-def:platform>Microsoft Windows Server 2012</oval-def:platform>
<oval-def:platform>Microsoft Windows Server 2012 R2</oval-def:platform>
<oval-def:platform>Microsoft Windows Server 2016</oval-def:platform>
<oval-def:platform>Microsoft Windows 7</oval-def:platform>
<oval-def:platform>Microsoft Windows 8.1</oval-def:platform>
<oval-def:platform>Microsoft Windows 10</oval-def:platform>
</oval-def:affected>
<oval-def:reference ref_id="CVE-2016-7219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7219" source="CVE" />
<oval-def:reference ref_id="MS16-149" ref_url="https://technet.microsoft.com/en-us/library/security/ms16-149.aspx" source="MS16-149" />
<oval-def:description>Windows Crypto Driver Information Disclosure Vulnerability</oval-def:description>
<oval-def:oval_repository>
<oval-def:dates>
<oval-def:submitted date="2016-12-15T21:00:00+08:00">
<oval-def:contributor organization="DTCC">Jeff Albert</oval-def:contributor>
</oval-def:submitted>
</oval-def:dates>
<oval-def:status>INITIAL SUBMISSION</oval-def:status>
<oval-def:min_schema_version>5.10</oval-def:min_schema_version>
</oval-def:oval_repository>
</oval-def:metadata>
<oval-def:criteria operator="OR">
<oval-def:criteria comment="Vista/2008 + file version" operator="AND">
<oval-def:criteria comment="Vista/2008" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124" />
<oval-def:extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594" />
<oval-def:extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653" />
<oval-def:extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216" />
<oval-def:extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150" />
</oval-def:criteria>
<oval-def:criteria comment="file version" operator="OR">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 6.0.6002.19720" test_ref="oval:com.dtcc.oval:tst:23400" />
<oval-def:criteria comment="LDR" operator="AND">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 6.0.6002.24042" test_ref="oval:com.dtcc.oval:tst:23401" />
<oval-def:criterion comment="Check if the version of Bcrypt.dll is greater than or equal 6.0.6002.24000" test_ref="oval:com.dtcc.oval:tst:23402" />
</oval-def:criteria>
</oval-def:criteria>
</oval-def:criteria>
<oval-def:criteria comment="Win7/2008 R2 + file version" operator="AND">
<oval-def:criteria comment="Win7/2008 R2" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292" />
<oval-def:extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627" />
<oval-def:extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567" />
<oval-def:extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583" />
</oval-def:criteria>
<oval-def:criteria comment="file version">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 6.1.7601.23601" test_ref="oval:com.dtcc.oval:tst:23403" />
</oval-def:criteria>
</oval-def:criteria>
<oval-def:criteria comment="2012 + file version" operator="AND">
<oval-def:extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359" />
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 6.2.9200.22037" test_ref="oval:com.dtcc.oval:tst:23404" />
</oval-def:criteria>
<oval-def:criteria comment="Win8.1/2012 R2 + file version" operator="AND">
<oval-def:criteria comment="Win8.1/2012 R2" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924" />
<oval-def:extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956" />
<oval-def:extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858" />
</oval-def:criteria>
<oval-def:criteria comment="file version">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 6.3.9600.18541" test_ref="oval:com.dtcc.oval:tst:23405" />
</oval-def:criteria>
</oval-def:criteria>
<oval-def:criteria comment="Win10 + file version" operator="AND">
<oval-def:criteria comment="Win10" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:29471" />
<oval-def:extend_definition comment="Microsoft Windows 10 (x64) is installed" definition_ref="oval:org.mitre.oval:def:29117" />
</oval-def:criteria>
<oval-def:criteria comment="file version">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 10.0.10240.17202" test_ref="oval:com.dtcc.oval:tst:23406" />
</oval-def:criteria>
</oval-def:criteria>
<oval-def:criteria comment="1511 + file version" operator="AND">
<oval-def:criteria comment="Win10" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows 10 Version 1511 (32-bit) is installed" definition_ref="oval:org.cisecurity:def:379" />
<oval-def:extend_definition comment="Microsoft Windows 10 Version 1511 (64-bit) is installed" definition_ref="oval:org.cisecurity:def:378" />
</oval-def:criteria>
<oval-def:criteria comment="file version">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 10.0.10586.713" test_ref="oval:com.dtcc.oval:tst:23407" />
</oval-def:criteria>
</oval-def:criteria>
<oval-def:criteria comment="1607/2016 + file version" operator="AND">
<oval-def:criteria comment="1607/2016" operator="OR">
<oval-def:extend_definition comment="Microsoft Windows 10 Version 1607 (32-bit) is installed" definition_ref="oval:org.cisecurity:def:1377" />
<oval-def:extend_definition comment="Microsoft Windows 10 Version 1607 (64-bit) is installed" definition_ref="oval:org.cisecurity:def:1379" />
<oval-def:extend_definition comment="Microsoft Windows Server 2016 is installed" definition_ref="oval:org.cisecurity:def:1269" />
</oval-def:criteria>
<oval-def:criteria comment="file version">
<oval-def:criterion comment="Check if the version of Bcrypt.dll is less than 10.0.14393.576" test_ref="oval:com.dtcc.oval:tst:23408" />
</oval-def:criteria>
</oval-def:criteria>
</oval-def:criteria>
</oval-def:definition>
@@ -0,0 +1,4 @@
<file_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="Object holds the file Bcrypt.dll" id="oval:com.dtcc.oval:obj:2340" version="0">
<path var_check="all" var_ref="oval:org.mitre.oval:var:200" />
<filename>Bcrypt.dll</filename>
</file_object>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 6.0.6002.19720" id="oval:com.dtcc.oval:ste:23400" version="0">
<version datatype="version" operation="less than">6.0.6002.19720</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 6.0.6002.24042" id="oval:com.dtcc.oval:ste:23401" version="0">
<version datatype="version" operation="less than">6.0.6002.24042</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 6.1.7601.23601" id="oval:com.dtcc.oval:ste:23403" version="0">
<version datatype="version" operation="less than">6.1.7601.23601</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 6.2.9200.22037" id="oval:com.dtcc.oval:ste:23404" version="0">
<version datatype="version" operation="less than">6.2.9200.22037</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 6.3.9600.18541" id="oval:com.dtcc.oval:ste:23405" version="0">
<version datatype="version" operation="less than">6.3.9600.18541</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 10.0.10240.17202" id="oval:com.dtcc.oval:ste:23406" version="0">
<version datatype="version" operation="less than">10.0.10240.17202</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 10.0.10586.713" id="oval:com.dtcc.oval:ste:23407" version="0">
<version datatype="version" operation="less than">10.0.10586.713</version>
</file_state>
@@ -0,0 +1,3 @@
<file_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" comment="State holds if the version is less than 10.0.14393.576" id="oval:com.dtcc.oval:ste:23408" version="0">
<version datatype="version" operation="less than">10.0.14393.576</version>
</file_state>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 6.0.6002.19720" id="oval:com.dtcc.oval:tst:23400" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23400" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 6.0.6002.24042" id="oval:com.dtcc.oval:tst:23401" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23401" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is greater than or equal 6.0.6002.24000" id="oval:com.dtcc.oval:tst:23402" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:org.cisecurity:ste:1629" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 6.1.7601.23601" id="oval:com.dtcc.oval:tst:23403" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23403" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 6.2.9200.22037" id="oval:com.dtcc.oval:tst:23404" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23404" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 6.3.9600.18541" id="oval:com.dtcc.oval:tst:23405" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23405" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 10.0.10240.17202" id="oval:com.dtcc.oval:tst:23406" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23406" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 10.0.10586.713" id="oval:com.dtcc.oval:tst:23407" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23407" />
</file_test>
@@ -0,0 +1,4 @@
<file_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" check="all" check_existence="at_least_one_exists" comment="Check if the version of Bcrypt.dll is less than 10.0.14393.576" id="oval:com.dtcc.oval:tst:23408" version="0">
<object object_ref="oval:com.dtcc.oval:obj:2340" />
<state state_ref="oval:com.dtcc.oval:ste:23408" />
</file_test>
12 changes: 6 additions & 6 deletions repository/variables/oval_org.mitre.oval_var_200.xml
@@ -1,6 +1,6 @@
<local_variable xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" comment="Windows System32 directory" datatype="string" id="oval:org.mitre.oval:var:200" version="10">
<concat>
<object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219" />
<literal_component>\System32</literal_component>
</concat>
</local_variable>
<oval-def:local_variable xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" comment="Windows System32 directory" datatype="string" id="oval:org.mitre.oval:var:200" version="10">
<oval-def:concat>
<oval-def:object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219" />
<oval-def:literal_component>\System32</oval-def:literal_component>
</oval-def:concat>
</oval-def:local_variable>

0 comments on commit acdaba6

Please sign in to comment.