<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-06-10T14:45:21</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1756829128" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2019-9674</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1756829128" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1756829128" source="CLSA"/>
        <reference ref_id="CVE-2019-9674" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" source="CVE"/>
        <description>* SECURITY UPDATE: Denial of service via a ZIP bomb
     - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module
       documentation
     - CVE-2019-9674</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-09-02"/>
          <updated date="2025-09-02"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" impact="important" public="20200204">CVE-2019-9674</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-11" test_ref="oval:com.tuxcare.clsa:tst:1756829128007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1759251979" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1759251979" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1759251979" source="CLSA"/>
        <reference ref_id="CVE-2019-17514" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-17514" source="CVE"/>
        <description>* SECURITY UPDATE: DOS, buffer overflow in SHA3, Possible Bypass Blocklisting
     Redirection vulnerability in http.server, regex DOS, Quadratic complexity,
     pathname quoting for venv
     - debian/patches/CVE-2022-37454.patch: fix a buffer overflow in
       Modules/_sha3/kcp/KeccakSponge.inc, Lib/test/test_hashlib.py
       (LP: #1995197).
     - debian/patches/CVE-2022-45061.patch: fix quadratic time idna decoding
       in Lib/encodings/idna.py, Lib/test/test_codecs.py.
     - debian/patches/CVE-2023-24329.patch: enforce
       that a scheme must begin with an alphabetical ASCII character
       in Lib/urllib/parse.py, Lib/test/test_urlparse.py.
       start stripping C0 control and space chars in `urlsplit`
     - debian/patches/CVE-2021-28861.patch: Fix an open
       redirection vulnerability in the `http.server` module
       when an URI path starts with `//`
     - debian/patches/CVE-2024-6232.patch: Fix header parsing vulnerability that
       could lead to ReDoS
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in parsing
       "-quoted cookie values with backslashes
     - debian/patches/CVE-2024-9287.patch: Quote template strings in `venv` activation
     - CVE-2022-37454
     - CVE-2022-45061
     - CVE-2023-24329
     - CVE-2021-28861
     - CVE-2024-6232
     - CVE-2024-7592
     - CVE-2024-9287</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-09-30"/>
          <updated date="2025-09-30"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-682" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-17514" impact="important" public="20191012">CVE-2019-17514</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759251979007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1759510256" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2019-20907, CVE-2019-9674</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1759510256" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1759510256" source="CLSA"/>
        <reference ref_id="CVE-2019-9674" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" source="CVE"/>
        <description>* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py
     - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module
       documentation
     - CVE-2019-9674
   * SECURITY UPDATE: Infinite loop
     - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the
       tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py.
     - CVE-2019-20907</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-03"/>
          <updated date="2025-10-03"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" impact="important" public="20200204">CVE-2019-9674</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759510256008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760093905" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760093905" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760093905" source="CLSA"/>
        <reference ref_id="CVE-2019-20907" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" source="CVE"/>
        <reference ref_id="CVE-2021-3737" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" source="CVE"/>
        <reference ref_id="CVE-2024-7592" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-7592" source="CVE"/>
        <reference ref_id="CVE-2024-6232" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6232" source="CVE"/>
        <reference ref_id="CVE-2023-24329" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-24329" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-45061" source="CVE"/>
        <reference ref_id="CVE-2022-48565" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565" source="CVE"/>
        <reference ref_id="CVE-2022-48560" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48560" source="CVE"/>
        <description>* SECURITY UPDATE: DoS in case of malicious XML entity declarations
     - debian/patches/CVE-2022-48565.patch: reject XML entity declarations
       in plist files
     - CVE-2022-48565
   * SECURITY UPDATE: Bypassing blocklisting methods by supplying a URL
     that starts with blank characters
     - debian/patches/CVE-2023-24329.patch,
       debian/patches/CVE-2023-24329-2.patch: prevent urllib.parse.urlparse
       from accepting schemes that don't begin with an alphabetical ASCII
       character
     - CVE-2023-24329
   * SECURITY UPDATE: ReDoS via specifically-crafted tar archives
     - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing
       tarfile
     - CVE-2024-6232
   * SECURITY UPDATE: Excessive CPU usage while parsing a cookie value
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in
       parsing double-quoted cookie values with backslashes
     - CVE-2024-7592
   * SECURITY UPDATE: CPU DoS by crafting inputs to the IDNA decoder
     - debian/patches/CVE-2022-45061.patch: fix quadratic time idna
       decoding
     - CVE-2022-45061
   * SECURITY UPDATE: Use-after-free via heappushpop in heapq
     - debian/patches/CVE-2022-48560.patch: fix posible crash in heapq with
       custom comparison operators
     - debian/patches/CVE-2022-48560-2.patch: add tests for CVE-2022-48560
     - CVE-2022-48560
   * SECURITY UPDATE: DoS by HTTP client infinite line reading from
     malicious server after a 100 Continue response
     - debian/patches/CVE-2021-3737.patch: stop reading a header if it's
       too long
     - CVE-2021-3737
   * SECURITY UPDATE: A flaw in the urllib.parse module
     - debian/patches/CVE-2022-0391.patch: make urlparse sanitize URLs
       containing ASCII newline and tabs
     - CVE-2022-0391</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-10"/>
          <updated date="2025-10-10"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" impact="important" public="20200713">CVE-2019-20907</cve>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" impact="important" public="20220304">CVE-2021-3737</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-7592" impact="important" public="20240819">CVE-2024-7592</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6232" impact="important" public="20240903">CVE-2024-6232</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-24329" impact="important" public="20230217">CVE-2023-24329</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-611" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565" impact="critical" public="20230822">CVE-2022-48565</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48560" impact="important" public="20230822">CVE-2022-48560</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093905008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760367079" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2007-4559, CVE-2023-27043, CVE-2023-40217</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760367079" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760367079" source="CLSA"/>
        <reference ref_id="CVE-2007-4559" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2007-4559" source="CVE"/>
        <reference ref_id="CVE-2023-27043" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" source="CVE"/>
        <reference ref_id="CVE-2023-40217" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" source="CVE"/>
        <description>* SECURITY UPDATE: Overwriting of arbitrary files by remote attackers
     - debian/patches/CVE-2007-4559.patch: implement PEP 706 - a filter in
       the tarfile module to prevent directory traversal vulnerability
     - CVE-2007-4559
   * SECURITY UPDATE: Bypass of domain e-mail-based protection mechanism by
     incorrect parsing of e-mail addresses that contain a special character
     - debian/patches/CVE-2023-27043.patch: reject malformed addresses in
       email.parseaddr()
     - CVE-2023-27043
   * SECURITY UPDATE: Bypass of the TLS handshake and included protections
     - debian/patches/CVE-2023-40217.patch: check for &amp; avoid the ssl
       pre-close flaw
     - CVE-2023-40217</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-13"/>
          <updated date="2025-10-13"/>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2007-4559" impact="moderate" public="20070828">CVE-2007-4559</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" impact="moderate" public="20230419">CVE-2023-27043</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" impact="moderate" public="20230825">CVE-2023-40217</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-17" test_ref="oval:com.tuxcare.clsa:tst:1760367079007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760369449" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2020-26116, CVE-2020-8492</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760369449" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760369449" source="CLSA"/>
        <reference ref_id="CVE-2020-26116" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" source="CVE"/>
        <reference ref_id="CVE-2020-8492" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-8492" source="CVE"/>
        <description>* SECURITY UPDATE: DoS in regular expression because of
     urllib.request.AbstractBasicAuthHandler catastrophic backtracking
     - debian/patches/CVE-2020-8492.patch: fix DoS in the urllib regexp
     - CVE-2020-8492
   * SECURITY UPDATE: a header injection vulnerability for http methods
     in the httplib
     - debian/patches/CVE-2020-26116.patch: prevent header injection in
     http methods in httplib
     - CVE-2020-26116</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-13"/>
          <updated date="2025-10-13"/>
          <cve cvss2="6.4/AV:N/AC:L/Au:N/C:P/I:P/A:N" cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" impact="important" public="20200927">CVE-2020-26116</cve>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-8492" impact="moderate" public="20200130">CVE-2020-8492</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369449008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760706477" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760706477" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760706477" source="CLSA"/>
        <reference ref_id="CVE-2023-40217" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" source="CVE"/>
        <reference ref_id="CVE-2021-23336" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-23336" source="CVE"/>
        <reference ref_id="CVE-2023-27043" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" source="CVE"/>
        <reference ref_id="CVE-2021-3733" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3733" source="CVE"/>
        <reference ref_id="CVE-2022-48566" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48566" source="CVE"/>
        <description>* SECURITY UPDATE: Web cache poisoning vulnerability
     - debian/patches/CVE-2021-23336.patch: fix web cache poisoning
       via urllib.parse.parse_qsl and urllib.parse.parse_qs
     - CVE-2021-23336
   * SECURITY UPDATE: Regular expression denial of service
     - debian/patches/CVE-2021-3733.patch: fix flaw in urllib’s
       AbstractBasicAuthHandler that could lead to a denial of service
       by leveraging a regular expression
     - CVE-2021-3733
   * SECURITY UPDATE: Constant-time-defeating optimisations issue
     - debian/patches/CVE-2022-48566.patch: make compare_digest more
       constant-time
     - CVE-2022-48566
   * SECURITY UPDATE: Incorrect parsing of email addresses containing special
     characters
     - debian/patches/CVE-2023-27043.patch: Fix email address parsing errors by
       adding optional 'strict' parameter to getaddresses() and parseaddr()
       functions
     - CVE-2023-27043
   * SECURITY UPDATE: TLS handshake bypass
     - debian/patches/CVE-2023-40217.patch: Check for &amp; avoid the ssl
       pre-close flaw. Update SSL tests
     - CVE-2023-40217</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-17"/>
          <updated date="2025-10-17"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" impact="moderate" public="20230825">CVE-2023-40217</cve>
          <cve cvss2="4.0/AV:N/AC:H/Au:N/C:N/I:P/A:P" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H" cwe="CWE-444" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-23336" impact="moderate" public="20210215">CVE-2021-23336</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" impact="moderate" public="20230419">CVE-2023-27043</cve>
          <cve cvss2="4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3733" impact="moderate" public="20220310">CVE-2021-3733</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48566" impact="moderate" public="20230822">CVE-2022-48566</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760706477008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1762526853" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1762526853" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1762526853" source="CLSA"/>
        <reference ref_id="CVE-2025-4330" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" source="CVE"/>
        <reference ref_id="CVE-2025-4138" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" source="CVE"/>
        <reference ref_id="CVE-2025-4517" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" source="CVE"/>
        <reference ref_id="CVE-2025-4435" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" source="CVE"/>
        <reference ref_id="CVE-2024-12718" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" source="CVE"/>
        <description>* SECURITY UPDATE: Traversing outside chmod directory
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: re-filters directory members
       before chmod/chown
     - CVE-2024-12718
   * SECURITY UPDATE: Symlink exfiltration
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: properly handles different link
       semantics
     - CVE-2025-4138
   * SECURITY UPDATE: Hardlink Fallback Attack
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: re-filter the source if hardlink
       extraction falls back to copying
     - CVE-2025-4330
   * SECURITY UPDATE: Errorlevel=0 Extracts Rejected Members
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: account errorlevel
     - CVE-2025-4435
   * SECURITY UPDATE: PATH_MAX Attack
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: prevents PATH_MAX overflow
       attacks
     - CVE-2025-4517
   * TEST UPDATE: Incorrect encoding leading to an unexpected
     exception in test_tarfile.py
     - debian/patch/fix_test_tarfile-enconding.patch: fix encoding</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-11-07"/>
          <updated date="2025-11-07"/>
          <cve cvss3="7.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" impact="important" public="20250603">CVE-2025-4330</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" impact="important" public="20250603">CVE-2025-4138</cve>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" impact="important" public="20250603">CVE-2025-4517</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-706" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" impact="important" public="20250603">CVE-2025-4435</cve>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" impact="important" public="20250603">CVE-2024-12718</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762526853007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1765796351" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-6597</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2025:1765796351" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1765796351" source="CLSA"/>
        <reference ref_id="CVE-2023-6597" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-6597" source="CVE"/>
        <description>* SECURITY UPDATE: Ability to modify permissions with privileged programs
     - debian/patches/CVE-2023-6597: prevent tempfile.TemporaryDirectory
       class dereference symlinks
     - CVE-2023-6597</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-12-15"/>
          <updated date="2025-12-15"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" cwe="CWE-61" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-6597" impact="important" public="20240319">CVE-2023-6597</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765796351007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1771338704" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-13837</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1771338704" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1771338704" source="CLSA"/>
        <reference ref_id="CVE-2025-13837" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" source="CVE"/>
        <description>* SECURITY UPDATE: Memory denial of service in plistlib
     - debian/patches/CVE-2025-13837.patch: read large data by chunks,
       therefore the upper limit of consumed memory is proportional to the
       size of the input file.
     - CVE-2025-13837</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-17"/>
          <updated date="2026-02-17"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" impact="moderate" public="20251201">CVE-2025-13837</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771338704007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1771869828" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2015-20107</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1771869828" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1771869828" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>* SECURITY UPDATE: Shell command injection in mailcap module
     - debian/patches/CVE-2015-20107.patch: sanitize the second
       argument which allowing shell commands injection
     - CVE-2015-20107</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-23"/>
          <updated date="2026-02-23"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771869828008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772100202" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2015-20107</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772100202" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772100202" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>* SECURITY UPDATE: Shell command injection in the mailcap module
     - debian/patches/CVE-2015-20107.patch: sanitize the second
       argument which allowing shell command injection
     - CVE-2015-20107</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772100202007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772105938" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-12084</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772105938" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772105938" source="CLSA"/>
        <reference ref_id="CVE-2025-12084" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" source="CVE"/>
        <description>* SECURITY UPDATE: Quadratic complexity in xml.minidom node ID cache
     clearing
     - debian/patches/CVE-2025-12084.patch: remove quadratic behavior in
       xml.minidom node ID cache clearing
     - CVE-2025-12084</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" impact="moderate" public="20251203">CVE-2025-12084</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772105938008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772445677" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-6075</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772445677" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772445677" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>* SECURITY UPDATE: Quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in
       os.path.expandvars() by replacing the character-by-character loop
       with regex-based substitution in both posixpath and ntpath modules.
     - CVE-2025-6075</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-02"/>
          <updated date="2026-03-02"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772445677007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772556428" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-8194</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772556428" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772556428" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>* SECURITY UPDATE: defect in 'tarfile' module leads to infinite loop and
     deadlock in parsing of maliciously crafted tar archives
     - debian/patches/CVE-2025-8194.patch: Validate archives to ensure member
       offsets are non-negative
     - CVE-2025-8194</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-03"/>
          <updated date="2026-03-03"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772556428007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772701579" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-8194</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772701579" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772701579" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>* SECURITY UPDATE: defect in 'tarfile' module leads to infinite loop and
     deadlock in parsing of maliciously crafted tar archives
     - debian/patches/CVE-2025-8194.patch: Validate archives to ensure member
       offsets are non-negative
     - CVE-2025-8194</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-05"/>
          <updated date="2026-03-05"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772701579008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1773232803" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-6075</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1773232803" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1773232803" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>* SECURITY UPDATE: quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: replace character-by-character loop
       with regex-based substitution to fix quadratic complexity
     - CVE-2025-6075</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-11"/>
          <updated date="2026-03-11"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773232803008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776436355" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-4519</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776436355" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1776436355" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>* SECURITY UPDATE: command-line option injection in webbrowser.open()
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in
       webbrowser.open() URLs to prevent command-line option injection
       in browser subprocesses
     - CVE-2026-4519</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-17"/>
          <updated date="2026-04-17"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="low" public="20260320">CVE-2026-4519</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776436355008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776437499" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-4519</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776437499" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1776437499" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>* SECURITY UPDATE: command-line option injection in webbrowser.open()
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in
       webbrowser.open() URLs to prevent command-line option injection
       in browser subprocesses
     - CVE-2026-4519</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-17"/>
          <updated date="2026-04-17"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="low" public="20260320">CVE-2026-4519</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776437499007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777391230" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-0450, CVE-2026-6100</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777391230" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777391230" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <description>* SECURITY UPDATE: zipfile quoted-overlap zip bomb
     - debian/patches/CVE-2024-0450.patch: raise BadZipFile when an
       archive entry overlaps with another entry or the central
       directory, preventing quoted-overlap zip bombs with extreme
       compression ratios.
     - CVE-2024-0450
   * SECURITY UPDATE: use-after-free in lzma/bz2 decompressors
     - debian/patches/CVE-2026-6100.patch: null next_in at the error:
       label of decompress() in Modules/_bz2module.c and
       Modules/_lzmamodule.c so the decompressor cannot be re-used
       with a stale buffer pointer after a MemoryError.
     - CVE-2026-6100</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-28"/>
          <updated date="2026-04-28"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777391230007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777479294" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-6100</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777479294" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777479294" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2020-27619" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <reference ref_id="CVE-2021-3177" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" source="CVE"/>
        <reference ref_id="CVE-2021-4189" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in
     BZ2Decompressor when MemoryError is raised in the C-level
     decompress() helper
     - debian/patches/CVE-2026-6100.patch: defensively null
       bzs-&gt;next_in on the error: path of BZ2Decomp_decompress in
       Modules/bz2module.c.
     - CVE-2026-6100</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-29"/>
          <updated date="2026-04-29"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" impact="critical" public="20201022">CVE-2020-27619</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-120" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" impact="critical" public="20210119">CVE-2021-3177</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" impact="moderate" public="20220824">CVE-2021-4189</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777479294008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777636164" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-0397, CVE-2024-4032, CVE-2024-6923, CVE-2026-1299</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777636164" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777636164" source="CLSA"/>
        <reference ref_id="CVE-2024-4032" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>* SECURITY UPDATE: email BytesGenerator header injection
     - debian/patches/CVE-2026-1299.patch: verify generated headers in
       email.generator.BytesGenerator and Generator. Adds the
       HeaderWriteError exception, NEWLINE_WITHOUT_FWSP /
       NEWLINE_WITHOUT_FWSP_BYTES regexes, and the
       Policy.verify_generated_headers attribute, then raises
       HeaderWriteError when the folded header does not end with the
       policy linesep or contains a stray newline. Includes the
       CVE-2024-6923 prerequisite hardening of the string Generator.
     - CVE-2026-1299
   * SECURITY UPDATE: ssl.SSLContext memory race in cert_store_stats /
     get_ca_certs
     - debian/patches/CVE-2024-0397.patch: backport the upstream
       X509_STORE_get1_objects shim and the x509_object_dup helper
       from cpython 29c97287d205bf2f410f4895ebce3f43b5160524, then
       switch _ssl__SSLContext_cert_store_stats_impl and
       _ssl__SSLContext_get_ca_certs_impl to take a deep-copy snapshot
       of the X509_STORE under lock, freeing the snapshot before
       returning. Closes a use-after-free triggered by loading
       certificates concurrently from another thread.
     - CVE-2024-0397
   * SECURITY UPDATE: ipaddress is_private / is_global misclassification
     - debian/patches/CVE-2024-4032.patch: backport upstream
       gh-113171 / gh-65056. Update Lib/ipaddress.py to align the
       _private_networks lists with the IANA special-purpose registries
       and add _private_networks_exceptions so that
       is_private / is_global no longer misclassify addresses in
       192.0.0.0/24 (with 192.0.0.9 and 192.0.0.10 exceptions),
       64:ff9b:1::/48, 2002::/16, and the 2001::/23 sub-range
       exceptions (2001:1::1, 2001:1::2, 2001:3::/32, 2001:4:112::/48,
       2001:20::/28, 2001:30::/28). Includes the matching docs and
       test updates.
     - CVE-2024-4032</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-440" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" impact="important" public="20240617">CVE-2024-4032</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777636164007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777624143" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2021-28861, CVE-2024-0397, CVE-2024-6923, CVE-2026-1299</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777624143" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777624143" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <reference ref_id="CVE-2021-28861" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>* SECURITY UPDATE: header injection via newline in email.Generator
     - debian/patches/CVE-2026-1299.patch: add HeaderWriteError exception
       to Lib/email/errors.py, add NEWLINE_WITHOUT_FWSP regex to
       Lib/email/generator.py and check the header *value* in all four
       branches of Generator._write_headers(), raising HeaderWriteError
       when a CR/LF without folding whitespace is found. Updates
       test_embedded_header_via_string_rejected to expect
       HeaderWriteError instead of HeaderParseError. In Python 2.7 this
       single Generator-class hardening covers both upstream
       CVE-2026-1299 (BytesGenerator) and CVE-2024-6923 because
       BytesGenerator does not exist in 2.7.
     - CVE-2026-1299
   * SECURITY UPDATE: missing header-name newline check in email.Generator
     - debian/patches/CVE-2024-6923.patch: add NEWLINE_WITHOUT_FWSP check
       on the header *name* at the top of Generator._write_headers() in
       Lib/email/generator.py, raising HeaderWriteError when a CR/LF
       without folding whitespace is found in the header name. Documents
       HeaderWriteError in Doc/library/email.errors.rst and adds a
       test_invalid_header_format regression test in
       Lib/email/test/test_email_renamed.py.
     - CVE-2024-6923
   * SECURITY UPDATE: ssl.SSLContext data race in cert_store_stats /
     get_ca_certs
     - debian/patches/CVE-2024-0397.patch: backport of upstream 3.8
       commit 29c97287d2 ("[3.8] gh-114572: Fix locking in
       cert_store_stats and get_ca_certs"). Adds a polyfill of
       OpenSSL 3.3's X509_STORE_get1_objects() (deep-copy under
       X509_STORE_lock()) and replaces the shared, unlocked
       X509_STORE_get0_objects() calls in cert_store_stats() and
       get_ca_certs() in Modules/_ssl.c, preventing a memory race
       and potential use-after-free when an SSLContext is shared
       across multiple threads.
     - CVE-2024-0397
   * SECURITY UPDATE: open redirect in BaseHTTPServer when path starts
     with //
     - debian/patches/CVE-2021-28861.patch: backport of upstream commit
       4abab6b603 ("gh-87389: Fix an open redirection vulnerability in
       http.server"). In Lib/BaseHTTPServer.py, after the request line
       is parsed, collapse any leading run of '/' characters to a
       single '/' so an attacker-controlled '//evil.example/...' path
       cannot become an absolute scheme-less URI in a 301 Location
       header. Adds a regression test in Lib/test/test_httpservers.py.
     - CVE-2021-28861</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" cwe="CWE-601" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" impact="important" public="20220823">CVE-2021-28861</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777624143008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778161134" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-3446</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778161134" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778161134" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>* SECURITY UPDATE: binascii.a2b_base64 / base64.b64decode stop decoding
     after the first padded quad, silently dropping any excess data. The
     behaviour can lead to data being accepted that other implementations
     process differently.
     - debian/patches/CVE-2026-3446.patch: backport of upstream commits
       4561f6418a (main), e31c55121620 (3.14), 1f9958f909c1 (3.13). Treats
       the pad character as non-alphabet data per RFC 4648 section 3.3:
       the loop in binascii_a2b_base64_impl no longer breaks out on a pad
       sequence; a `pads` counter is added so post-loop validation still
       raises "Incorrect padding" for inputs that do not satisfy
       `quad_pos + pads == 4`. The unused `binascii_find_valid` helper
       is removed.
     - CVE-2026-3446</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-07"/>
          <updated date="2026-05-07"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778161134007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778165286" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-3446</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778165286" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778165286" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>* SECURITY UPDATE: binascii.a2b_base64 / base64.b64decode stop decoding
     after the first padded quad, silently dropping any excess data. The
     behaviour can lead to data being accepted that other implementations
     process differently.
     - debian/patches/CVE-2026-3446.patch: backport of upstream commits
       4561f6418a (main), e31c55121620 (3.14), 1f9958f909c1 (3.13). Treats
       the pad character as non-alphabet data per RFC 4648 section 3.3:
       the loop in binascii_a2b_base64 no longer breaks out on a pad
       sequence; a `pads` counter is added so post-loop validation still
       raises "Incorrect padding" for inputs that do not satisfy
       `quad_pos + pads == 4`. The unused `binascii_find_valid` helper
       is removed.
     - CVE-2026-3446</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-07"/>
          <updated date="2026-05-07"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778165286008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779271088" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-0672, CVE-2026-3644, CVE-2026-4224</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779271088" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779271088" source="CLSA"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>* SECURITY UPDATE: Modules/pyexpat.c conv_content_model could overflow
     the C stack when an Expat parser with a registered ElementDeclHandler
     parsed a deeply nested DTD content model, causing a denial-of-service.
     - debian/patches/CVE-2026-4224.patch: C-level backport of cpython
       eb0e8be3a7 (gh-145986, Stan Ulbrych + Bénédikt Tran). Wraps
       conv_content_model with Py_EnterRecursiveCall / Py_LeaveRecursiveCall
       so deep nesting raises RuntimeError instead of crashing. The
       upstream Lib/test/test_pyexpat.py test addition is skipped: it
       depends on test.support.infinite_recursion() which only exists
       in Python 3.x test.support.
     - CVE-2026-4224
   * SECURITY UPDATE: Lib/Cookie.py Morsel accepts control characters
     in reserved-attribute values, in key/value/coded_value via .set(),
     and via the inherited dict.update() / pickle restoration paths,
     allowing newline-based HTTP header injection via Set-Cookie. The
     upstream CVE description and py3 fix target Lib/http/cookies.py
     (which does not exist in py2); a runtime POC confirmed the same
     vulnerability class is reachable through py2's Cookie module via
     five distinct write paths.
     - debian/patches/CVE-2026-0672-CVE-2026-3644.patch: py2 adaptation
       of cpython 95746b3a13 (gh-143919, Seth Larson) and 57e88c1cf9
       (gh-145599, Stan Ulbrych + Victor Stinner). Adds a
       _has_control_character helper and validates at Morsel.__setitem__,
       .setdefault, .set, an explicit .update, an explicit .__setstate__,
       plus re-validates the assembled output in Morsel.js_output and
       BaseCookie.output (defence-in-depth against direct attribute
       mutation). The py3 __ior__ hunk is not ported (py2 dict has no
       `|=` operator). Doctest fixture `keebler="...fudge=\012;"` is
       updated to drop the embedded newline, mirroring the upstream
       doctest fix.
     - CVE-2026-0672, CVE-2026-3644</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-20"/>
          <updated date="2026-05-20"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779271088008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779278238" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-15282, CVE-2026-0672, CVE-2026-3644, CVE-2026-4224</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779278238" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779278238" source="CLSA"/>
        <reference ref_id="CVE-2025-15282" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>* SECURITY UPDATE: urllib.request.DataHandler accepted data: URLs whose
     mediatype contained control characters, allowing newline-based HTTP
     header injection downstream.
     - debian/patches/CVE-2025-15282.patch: backport of cpython
       f25509e78e (gh-143925, Seth Larson). Adds a [\\x00-\\x1F\\x7F]
       regex check in data_open() and a matching test_invalid_mediatype.
     - CVE-2025-15282
   * SECURITY UPDATE: http.cookies.Morsel did not reject control characters
     in keys / values / coded_value, allowing cookie injection via
     __setitem__, setdefault, set, and BaseCookie.output.
     - debian/patches/CVE-2026-0672.patch: backport of cpython
       95746b3a13 (gh-143919, Seth Larson). Adds _has_control_character
       helper and inserts validation in __setitem__, setdefault, set,
       plus a wrap of BaseCookie.OutputString / output.
     - CVE-2026-0672
   * SECURITY UPDATE: the CVE-2026-0672 fix was incomplete; control
     characters could still bypass via Morsel.update(), |=, __setstate__
     (pickle), and BaseCookie.js_output().
     - debian/patches/CVE-2026-3644.patch: backport of cpython
       57e88c1cf9 (gh-145599, Stan Ulbrych + Victor Stinner). Adds
       validation to Morsel.update(), defines explicit Morsel.__ior__
       (was inherited from dict and bypassed validation), validates
       __setstate__ before assigning attributes, and re-validates the
       assembled output string in js_output().
     - CVE-2026-3644
   * SECURITY UPDATE: Modules/pyexpat.c conv_content_model could overflow
     the C stack when an Expat parser with a registered ElementDeclHandler
     parsed a deeply nested DTD content model, causing a denial-of-service.
     - debian/patches/CVE-2026-4224.patch: backport of cpython
       eb0e8be3a7 (gh-145986, Stan Ulbrych + Bénédikt Tran). Wraps
       conv_content_model with Py_EnterRecursiveCall / Py_LeaveRecursiveCall
       so deep nesting raises RecursionError instead of crashing.
     - CVE-2026-4224</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-20"/>
          <updated date="2026-05-20"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" impact="moderate" public="20260120">CVE-2025-15282</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779278238007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779885159" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-41080, CVE-2026-7210</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779885159" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779885159" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: CVE-2026-7210 + CVE-2026-41080 (paired) — backport
     the libexpat 16-byte salt API (XML_SetHashSalt16Bytes) into bundled
     expat 2.4.1 and wire pyexpat/_elementtree to use it. Together these
     restore proper hash-flood mitigation for xml.parsers.expat and
     xml.etree.ElementTree.
     - debian/patches/CVE-2026-7210.patch: backport of cpython
       24b8f12544 (gh-149018, Stan Ulbrych). Adds a new 16-byte
       _Py_HashSecret.expat.hashsalt16 slot in Include/pyhash.h
       (overlapping the existing padding), extends the PyExpat CAPI in
       Include/pyexpat.h with SetHashSalt16Bytes, and prefers the new
       API in Modules/pyexpat.c and Modules/_elementtree.c when built
       against libexpat exposing it; falls back to the legacy
       XML_SetHashSalt path otherwise. The two XML_COMBINED_VERSION
       gates are extended with `|| defined(XML_HAS_HASHSALT16BYTES_BACKPORT)`
       so the new code path activates against the bundled patched
       libexpat without bumping its advertised version, while
       --with-system-expat builds (Alpine) keep the upstream
       `&gt;= 20800` semantics.
     - debian/patches/CVE-2026-41080.patch: backport of libexpat
       PR #1183. Widens the parser's internal hash salt from
       `unsigned long m_hash_secret_salt` to a full
       `struct sipkey m_hash_secret_salt_128` (+ an
       m_hash_secret_salt_set flag), adds the new
       XML_SetHashSalt16Bytes API and the matching
       XML_HAS_HASHSALT16BYTES_BACKPORT marker in expat.h, and namespaces
       the new symbol via pyexpatns.h. Applied to bundled
       Modules/expat/; on Alpine `prepare()` deletes Modules/expat
       after the patch, so the libexpat backport is a no-op there and
       the system libexpat decides whether the new API is available.
     - CVE-2026-7210
     - CVE-2026-41080</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779885159007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779891434" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-41080, CVE-2026-7210</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779891434" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779891434" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: CVE-2026-7210 + CVE-2026-41080 (paired): backport
     the libexpat 16-byte salt API (XML_SetHashSalt16Bytes) into bundled
     expat 2.2.8 and wire pyexpat/_elementtree to use it. Together these
     restore proper hash-flood mitigation. xml.parsers.expat and
     xml.etree.ElementTree previously used only the legacy 8-byte
     XML_SetHashSalt API; that salt is brute-forceable with modern
     hardware, allowing a crafted XML document to trigger hash
     collisions and a denial of service.
     - debian/patches/CVE-2026-7210.patch: backport of cpython
       24b8f12544 (gh-149018, Stan Ulbrych). Switches pyexpat and
       _elementtree to XML_SetHashSalt16Bytes when built/linked against
       libexpat &gt;= 2.8.0, falling back to the legacy XML_SetHashSalt on
       older expat. Adds a hashsalt16[16] field to _Py_HashSecret_t in
       Include/object.h (seeded by _PyRandom_Init alongside prefix /
       suffix) and a NULL-able SetHashSalt16Bytes function pointer in
       the pyexpat CAPI struct so _elementtree can dispatch at runtime.
       No upstream backport to 2.7 exists; upstream backports landed
       only to 3.14 / 3.15.
     - debian/patches/CVE-2026-41080.patch: backport of libexpat
       PR #1183 into the bundled Modules/expat/ tree (libexpat 2.2.8).
       Widens m_hash_secret_salt from `unsigned long` to a 128-bit
       `struct sipkey` and adds the new public XML_SetHashSalt16Bytes()
       entry point. Since pyexpat.so / _elementtree.so are statically
       linked against this tree, the cpython half now consumes full
       16-byte entropy without requiring an external libexpat
       &gt;= 2.8.0 at runtime.
     - CVE-2026-7210
     - CVE-2026-41080</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779891434008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1780514569" version="1">
      <metadata>
        <title>Fix of 12 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1780514569" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1780514569" source="CLSA"/>
        <reference ref_id="CVE-2025-4516" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2024-50602" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2025-11468" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" source="CVE"/>
        <description>* SECURITY UPDATE: tarfile applied AREGTYPE -&gt; DIRTYPE normalization
     even during multi-block GNU long members (GNUTYPE_LONGNAME /
     GNUTYPE_LONGLINK), enabling a parsing differential vs. other tar
     implementations.
     - debian/patches/CVE-2025-13462.patch: backport of cpython
       42d754e3 (gh-143934, Seth Larson + Eashwar Ranganathan).
       Threads a dircheck flag through frombuf / fromtarfile so
       normalization is skipped on the inner header during GNU long
       name / link handling.
     - CVE-2025-13462
   * SECURITY UPDATE: wsgiref.headers.Headers did not reject control
     characters in header names / values, allowing HTTP header
     injection from WSGI applications.
     - debian/patches/CVE-2026-0865.patch: combined backport of
       cpython f7fceed7 (gh-143917) which adds the control-char regex
       check, 66da7bf6 (gh-143916 HTAB follow-up) which splits the
       check so HTAB is allowed in header values (RFC 9110 Section
       5.5) but still rejected in header names, plus d931725b
       (gh-144370) which disallows control characters in status in
       wsgiref.handlers.start_response.
     - CVE-2026-0865
   * SECURITY UPDATE: http.client did not reject CR/LF in HTTPConnection
     CONNECT tunnel host / per-tunnel-header values, enabling request
     injection through a proxy tunnel.
     - debian/patches/CVE-2026-1502.patch: backport of cpython
       05ed7ce7 + b1cf9016 (gh-146212, Seth Larson). Adapted to 3.6's
       per-line self.send() form (no headers=[] list in _tunnel until
       3.9+). Validates _tunnel_host and per-header name / value in
       _tunnel().
     - CVE-2026-1502
   * SECURITY UPDATE: http.cookies.Morsel.js_output() emitted an inline
     &lt;script&gt; snippet that only escaped " and left &lt;/script&gt; intact,
     enabling HTML injection when a cookie value contains &lt;/script&gt;.
     - debian/patches/CVE-2026-6019.patch: backport of cpython
       76b3923d (gh-148848, Seth Larson). Base64-encodes the cookie
       value and emits document.cookie = atob("...") instead of
       pasting the raw cookie string into the JavaScript snippet.
       Composes on top of CVE-2026-3644's js_output() control-character
       recheck (preserved).
     - CVE-2026-6019</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-03"/>
          <updated date="2026-06-03"/>
          <cve cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" impact="moderate" public="20250515">CVE-2025-4516</cve>
          <cve cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-237" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-754" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" impact="moderate" public="20241027">CVE-2024-50602</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-140" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" impact="moderate" public="20260120">CVE-2025-11468</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780514569007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781102598" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-15366, CVE-2025-15367</title>
        <affected family="unix">
          <platform>Ubuntu 20.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781102598" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1781102598" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <description>* SECURITY UPDATE: command injection via control characters in imaplib
     - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of
       cpython 6262704b (gh-143921, Seth Michael Larson).
       imaplib.IMAP4._command() concatenated each argument into the
       wire-level command without inspecting it, so user-controlled text
       (e.g. a username passed to IMAP4.login()) containing CR/LF or other
       control characters could inject a second IMAP command. Adds a
       module-level _control_chars regex to Lib/imaplib.py and a guard in
       _command() that rejects any argument containing a byte in
       [\x00-\x1F\x7F] with ValueError before concatenation. Adds a
       test_control_characters regression test to Lib/test/test_imaplib.py.
     - CVE-2025-15366
   * SECURITY UPDATE: command injection via control characters in poplib
     - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of
       cpython b234a2b6 (gh-143923, Seth Michael Larson).
       poplib.POP3._putcmd() sent its argument to the server without
       inspecting it, so user-controlled text passed to
       user()/pass_()/apop()/rpop()/top() could inject a second POP3
       command. Adds a guard in _putcmd() (Lib/poplib.py) that rejects any
       argument containing a byte in [\x00-\x1F\x7F] with ValueError before
       sending. Adds a test_control_characters regression test to
       Lib/test/test_poplib.py.
     - CVE-2025-15367</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-10"/>
          <updated date="2026-06-10"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781102598008"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-11" id="oval:com.tuxcare.clsa:tst:1756829128007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1756829128001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759251979007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759251979001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759510256008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759510256001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093905008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093905001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-17" id="oval:com.tuxcare.clsa:tst:1760367079007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760367079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369449008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369449001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760706477008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760706477001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762526853007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762526853001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765796351007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765796351001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771338704007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771338704001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771869828008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771869828001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772100202007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772100202001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772105938008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772105938001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772445677007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772445677001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772556428007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772556428001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772701579008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772701579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773232803008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773232803001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776436355008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776436355001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776437499007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776437499001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777391230007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777391230001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777479294008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777479294001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777636164007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777636164001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777624143008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777624143001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778161134007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778161134001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778165286008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778165286001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779271088008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779271088001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779278238007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779278238001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779885159007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779885159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779891434008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779891434001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780514569007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1756829128007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780514569001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781102598008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759510256008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781102598001"/>
    </linux:dpkginfo_test>
  </tests>
  <objects>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128001" version="1">
      <linux:name>alt-python36</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128002" version="1">
      <linux:name>alt-python36-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128003" version="1">
      <linux:name>alt-python36-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128004" version="1">
      <linux:name>alt-python36-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128005" version="1">
      <linux:name>alt-python36-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128006" version="1">
      <linux:name>alt-python36-tkinter</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1756829128007" version="1">
      <linux:name>alt-python36-tools</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256001" version="1">
      <linux:name>alt-python27</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256002" version="1">
      <linux:name>alt-python27-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256003" version="1">
      <linux:name>alt-python27-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256004" version="1">
      <linux:name>alt-python27-idle</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256005" version="1">
      <linux:name>alt-python27-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256006" version="1">
      <linux:name>alt-python27-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256007" version="1">
      <linux:name>alt-python27-tkinter</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759510256008" version="1">
      <linux:name>alt-python27-tools</linux:name>
    </linux:dpkginfo_object>
  </objects>
  <states>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1756829128001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-11</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1759251979001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-14</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1759510256001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-3</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760093905001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-6</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760367079001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-17</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760369449001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760706477001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-8</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1762526853001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-19</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1765796351001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-20</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1771338704001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-23</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1771869828001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-9</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772100202001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-25</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772105938001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-10</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772445677001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-27</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772556428001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-28</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772701579001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-11</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1773232803001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-12</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776436355001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-14</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776437499001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-29</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777391230001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-30</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777479294001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-16</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777636164001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-31</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777624143001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-17</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1778161134001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-32</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1778165286001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-18</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779271088001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-19</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779278238001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-33</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779885159001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-34</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779891434001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-20</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1780514569001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-37</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1781102598001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-21</linux:evr>
    </linux:dpkginfo_state>
  </states>
</oval_definitions>
