<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-07-24T13:49:46</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1759247378" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1759247378" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1759247378" source="CLSA"/>
        <reference ref_id="CVE-2019-17514" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-17514" source="CVE"/>
        <reference ref_id="CVE-2024-6232" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" source="CVE"/>
        <reference ref_id="CVE-2021-28861" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2021-28861" source="CVE"/>
        <reference ref_id="CVE-2022-37454" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-37454" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" source="CVE"/>
        <reference ref_id="CVE-2024-9287" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-9287" source="CVE"/>
        <reference ref_id="CVE-2023-24329" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" source="CVE"/>
        <reference ref_id="CVE-2024-7592" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" source="CVE"/>
        <description>* SECURITY UPDATE: DOS, buffer overflow in SHA3, Possible Bypass Blocklisting
     Redirection vulnerability in http.server, regex DOS, Quadratic complexity,
     pathname quoting for venv
     - debian/patches/CVE-2022-37454.patch: fix a buffer overflow in
       Modules/_sha3/kcp/KeccakSponge.inc, Lib/test/test_hashlib.py
       (LP: #1995197).
     - debian/patches/CVE-2022-45061.patch: fix quadratic time idna decoding
       in Lib/encodings/idna.py, Lib/test/test_codecs.py.
     - debian/patches/CVE-2023-24329.patch: enforce
       that a scheme must begin with an alphabetical ASCII character
       in Lib/urllib/parse.py, Lib/test/test_urlparse.py.
       start stripping C0 control and space chars in `urlsplit`
     - debian/patches/CVE-2021-28861.patch: Fix an open
       redirection vulnerability in the `http.server` module
       when an URI path starts with `//`
     - debian/patches/CVE-2024-6232.patch: Fix header parsing vulnerability that
       could lead to ReDoS
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in parsing
       "-quoted cookie values with backslashes
     - debian/patches/CVE-2024-9287.patch: Quote template strings in `venv` activation
     - CVE-2022-37454
     - CVE-2022-45061
     - CVE-2023-24329
     - CVE-2021-28861
     - CVE-2024-6232
     - CVE-2024-7592
     - CVE-2024-9287</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-09-30"/>
          <updated date="2025-09-30"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-682" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-17514" impact="important" public="20191012">CVE-2019-17514</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" impact="important" public="20240903">CVE-2024-6232</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" cwe="CWE-601" href="https://cve.tuxcare.com/els-lang/cve/CVE-2021-28861" impact="important" public="20220823">CVE-2021-28861</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-37454" impact="critical" public="20221021">CVE-2022-37454</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-428" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-9287" impact="important" public="20241022">CVE-2024-9287</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" impact="important" public="20230217">CVE-2023-24329</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" impact="important" public="20240819">CVE-2024-7592</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-14" test_ref="oval:com.tuxcare.clsa:tst:1759247378007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1759509928" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2019-20907, CVE-2019-9674</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1759509928" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1759509928" source="CLSA"/>
        <reference ref_id="CVE-2019-9674" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" source="CVE"/>
        <description>* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py
     - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module
       documentation
     - CVE-2019-9674
   * SECURITY UPDATE: Infinite loop
     - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the
       tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py.
     - CVE-2019-20907</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-03"/>
          <updated date="2025-10-03"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" impact="important" public="20200204">CVE-2019-9674</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-3" test_ref="oval:com.tuxcare.clsa:tst:1759509928008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760093456" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760093456" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760093456" source="CLSA"/>
        <reference ref_id="CVE-2019-20907" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" source="CVE"/>
        <reference ref_id="CVE-2021-3737" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" source="CVE"/>
        <reference ref_id="CVE-2022-48565" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565" source="CVE"/>
        <reference ref_id="CVE-2022-0391" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-0391" source="CVE"/>
        <reference ref_id="CVE-2024-7592" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-7592" source="CVE"/>
        <reference ref_id="CVE-2022-48560" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48560" source="CVE"/>
        <reference ref_id="CVE-2024-6232" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6232" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-45061" source="CVE"/>
        <reference ref_id="CVE-2023-24329" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-24329" source="CVE"/>
        <description>* SECURITY UPDATE: DoS in case of malicious XML entity declarations
     - debian/patches/CVE-2022-48565.patch: reject XML entity declarations
       in plist files
     - CVE-2022-48565
   * SECURITY UPDATE: Bypassing blocklisting methods by supplying a URL
     that starts with blank characters
     - debian/patches/CVE-2023-24329.patch,
       debian/patches/CVE-2023-24329-2.patch: prevent urllib.parse.urlparse
       from accepting schemes that don't begin with an alphabetical ASCII
       character
     - CVE-2023-24329
   * SECURITY UPDATE: ReDoS via specifically-crafted tar archives
     - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing
       tarfile
     - CVE-2024-6232
   * SECURITY UPDATE: Excessive CPU usage while parsing a cookie value
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in
       parsing double-quoted cookie values with backslashes
     - CVE-2024-7592
   * SECURITY UPDATE: CPU DoS by crafting inputs to the IDNA decoder
     - debian/patches/CVE-2022-45061.patch: fix quadratic time idna
       decoding
     - CVE-2022-45061
   * SECURITY UPDATE: Use-after-free via heappushpop in heapq
     - debian/patches/CVE-2022-48560.patch: fix posible crash in heapq with
       custom comparison operators
     - debian/patches/CVE-2022-48560-2.patch: add tests for CVE-2022-48560
     - CVE-2022-48560
   * SECURITY UPDATE: DoS by HTTP client infinite line reading from
     malicious server after a 100 Continue response
     - debian/patches/CVE-2021-3737.patch: stop reading a header if it's
       too long
     - CVE-2021-3737
   * SECURITY UPDATE: A flaw in the urllib.parse module
     - debian/patches/CVE-2022-0391.patch: make urlparse sanitize URLs
       containing ASCII newline and tabs
     - CVE-2022-0391</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-10"/>
          <updated date="2025-10-10"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" impact="important" public="20200713">CVE-2019-20907</cve>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" impact="important" public="20220304">CVE-2021-3737</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-611" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565" impact="critical" public="20230822">CVE-2022-48565</cve>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-0391" impact="important" public="20220209">CVE-2022-0391</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-7592" impact="important" public="20240819">CVE-2024-7592</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48560" impact="important" public="20230822">CVE-2022-48560</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6232" impact="important" public="20240903">CVE-2024-6232</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-24329" impact="important" public="20230217">CVE-2023-24329</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-6" test_ref="oval:com.tuxcare.clsa:tst:1760093456008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760369775" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2020-26116, CVE-2020-8492</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760369775" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760369775" source="CLSA"/>
        <reference ref_id="CVE-2020-26116" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" source="CVE"/>
        <reference ref_id="CVE-2020-8492" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-8492" source="CVE"/>
        <description>* SECURITY UPDATE: DoS in regular expression because of
     urllib.request.AbstractBasicAuthHandler catastrophic backtracking
     - debian/patches/CVE-2020-8492.patch: fix DoS in the urllib regexp
     - CVE-2020-8492
   * SECURITY UPDATE: a header injection vulnerability for http methods
     in the httplib
     - debian/patches/CVE-2020-26116.patch: prevent header injection in
     http methods in httplib
     - CVE-2020-26116</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-13"/>
          <updated date="2025-10-13"/>
          <cve cvss2="6.4/AV:N/AC:L/Au:N/C:P/I:P/A:N" cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" impact="important" public="20200927">CVE-2020-26116</cve>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-8492" impact="moderate" public="20200130">CVE-2020-8492</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-7" test_ref="oval:com.tuxcare.clsa:tst:1760369775008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760705964" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760705964" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760705964" source="CLSA"/>
        <reference ref_id="CVE-2021-3733" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3733" source="CVE"/>
        <reference ref_id="CVE-2023-40217" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" source="CVE"/>
        <reference ref_id="CVE-2022-48566" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48566" source="CVE"/>
        <reference ref_id="CVE-2021-23336" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-23336" source="CVE"/>
        <reference ref_id="CVE-2023-27043" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" source="CVE"/>
        <description>* SECURITY UPDATE: Web cache poisoning vulnerability
     - debian/patches/CVE-2021-23336.patch: fix web cache poisoning
       via urllib.parse.parse_qsl and urllib.parse.parse_qs
     - CVE-2021-23336
   * SECURITY UPDATE: Regular expression denial of service
     - debian/patches/CVE-2021-3733.patch: fix flaw in urllib’s
       AbstractBasicAuthHandler that could lead to a denial of service
       by leveraging a regular expression
     - CVE-2021-3733
   * SECURITY UPDATE: Constant-time-defeating optimisations issue
     - debian/patches/CVE-2022-48566.patch: make compare_digest more
       constant-time
     - CVE-2022-48566
   * SECURITY UPDATE: Incorrect parsing of email addresses containing special
     characters
     - debian/patches/CVE-2023-27043.patch: Fix email address parsing errors by
       adding optional 'strict' parameter to getaddresses() and parseaddr()
       functions
     - CVE-2023-27043
   * SECURITY UPDATE: TLS handshake bypass
     - debian/patches/CVE-2023-40217.patch: Check for &amp; avoid the ssl
       pre-close flaw. Update SSL tests
     - CVE-2023-40217</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-17"/>
          <updated date="2025-10-17"/>
          <cve cvss2="4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3733" impact="moderate" public="20220310">CVE-2021-3733</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-40217" impact="moderate" public="20230825">CVE-2023-40217</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48566" impact="moderate" public="20230822">CVE-2022-48566</cve>
          <cve cvss2="4.0/AV:N/AC:H/Au:N/C:N/I:P/A:P" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H" cwe="CWE-444" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-23336" impact="moderate" public="20210215">CVE-2021-23336</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-27043" impact="moderate" public="20230419">CVE-2023-27043</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-8" test_ref="oval:com.tuxcare.clsa:tst:1760705964008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1762527688" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1762527688" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1762527688" source="CLSA"/>
        <reference ref_id="CVE-2024-12718" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" source="CVE"/>
        <reference ref_id="CVE-2025-4330" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" source="CVE"/>
        <reference ref_id="CVE-2025-4138" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" source="CVE"/>
        <reference ref_id="CVE-2025-4517" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" source="CVE"/>
        <reference ref_id="CVE-2025-4435" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" source="CVE"/>
        <description>* SECURITY UPDATE: Traversing outside chmod directory
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: re-filters directory members
       before chmod/chown
     - CVE-2024-12718
   * SECURITY UPDATE: Symlink exfiltration
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: properly handles different link
       semantics
     - CVE-2025-4138
   * SECURITY UPDATE: Hardlink Fallback Attack
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: re-filter the source if hardlink
       extraction falls back to copying
     - CVE-2025-4330
   * SECURITY UPDATE: Errorlevel=0 Extracts Rejected Members
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: account errorlevel
     - CVE-2025-4435
   * SECURITY UPDATE: PATH_MAX Attack
     - debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
       -2025-4435-CVE-2025-4517.patch: prevents PATH_MAX overflow
       attacks
     - CVE-2025-4517
   * TEST UPDATE: Incorrect encoding leading to an unexpected
     exception in test_tarfile.py
     - debian/patch/fix_test_tarfile-enconding.patch: fix encoding</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-11-07"/>
          <updated date="2025-11-07"/>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" impact="important" public="20250603">CVE-2024-12718</cve>
          <cve cvss3="7.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" impact="important" public="20250603">CVE-2025-4330</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" impact="important" public="20250603">CVE-2025-4138</cve>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" impact="important" public="20250603">CVE-2025-4517</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-706" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" impact="important" public="20250603">CVE-2025-4435</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-19" test_ref="oval:com.tuxcare.clsa:tst:1762527688007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1765793732" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-6597</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2025:1765793732" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1765793732" source="CLSA"/>
        <reference ref_id="CVE-2023-6597" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-6597" source="CVE"/>
        <description>* SECURITY UPDATE: Ability to modify permissions with privileged programs
     - debian/patches/CVE-2023-6597: prevent tempfile.TemporaryDirectory
       class dereference symlinks
     - CVE-2023-6597</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-12-15"/>
          <updated date="2025-12-15"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" cwe="CWE-61" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-6597" impact="important" public="20240319">CVE-2023-6597</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-20" test_ref="oval:com.tuxcare.clsa:tst:1765793732007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1771342958" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-13837</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1771342958" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1771342958" source="CLSA"/>
        <reference ref_id="CVE-2025-13837" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" source="CVE"/>
        <description>* SECURITY UPDATE: Memory denial of service in plistlib
     - debian/patches/CVE-2025-13837.patch: read large data by chunks,
       therefore the upper limit of consumed memory is proportional to the
       size of the input file.
     - CVE-2025-13837</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-17"/>
          <updated date="2026-02-17"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" impact="moderate" public="20251201">CVE-2025-13837</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-23" test_ref="oval:com.tuxcare.clsa:tst:1771342958007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1771868964" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2015-20107</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1771868964" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1771868964" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>* SECURITY UPDATE: Shell command injection in mailcap module
     - debian/patches/CVE-2015-20107.patch: sanitize the second
       argument which allowing shell commands injection
     - CVE-2015-20107</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-23"/>
          <updated date="2026-02-23"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-9" test_ref="oval:com.tuxcare.clsa:tst:1771868964008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772099114" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2015-20107</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772099114" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772099114" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>* SECURITY UPDATE: Shell command injection in the mailcap module
     - debian/patches/CVE-2015-20107.patch: sanitize the second
       argument which allowing shell command injection
     - CVE-2015-20107</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-25" test_ref="oval:com.tuxcare.clsa:tst:1772099114007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772109537" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-12084</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772109537" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772109537" source="CLSA"/>
        <reference ref_id="CVE-2025-12084" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" source="CVE"/>
        <description>* SECURITY UPDATE: Quadratic complexity in xml.minidom node ID cache
     clearing
     - debian/patches/CVE-2025-12084.patch: remove quadratic behavior in
       xml.minidom node ID cache clearing
     - CVE-2025-12084</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" impact="moderate" public="20251203">CVE-2025-12084</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-10" test_ref="oval:com.tuxcare.clsa:tst:1772109537008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772444571" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-6075</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772444571" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772444571" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>* SECURITY UPDATE: Quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in
       os.path.expandvars() by replacing the character-by-character loop
       with regex-based substitution in both posixpath and ntpath modules.
     - CVE-2025-6075</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-02"/>
          <updated date="2026-03-02"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-27" test_ref="oval:com.tuxcare.clsa:tst:1772444571007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772618241" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-8194</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772618241" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772618241" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>* SECURITY UPDATE: defect in 'tarfile' module leads to infinite loop and
     deadlock in parsing of maliciously crafted tar archives
     - debian/patches/CVE-2025-8194.patch: Validate archives to ensure member
       offsets are non-negative
     - CVE-2025-8194</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-04"/>
          <updated date="2026-03-04"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-28" test_ref="oval:com.tuxcare.clsa:tst:1772618241007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772700745" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-8194</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772700745" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772700745" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>* SECURITY UPDATE: defect in 'tarfile' module leads to infinite loop and
     deadlock in parsing of maliciously crafted tar archives
     - debian/patches/CVE-2025-8194.patch: Validate archives to ensure member
       offsets are non-negative
     - CVE-2025-8194</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-05"/>
          <updated date="2026-03-05"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-11" test_ref="oval:com.tuxcare.clsa:tst:1772700745008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1773222322" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-6075</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1773222322" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1773222322" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>* SECURITY UPDATE: quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: replace character-by-character loop
       with regex-based substitution to fix quadratic complexity
     - CVE-2025-6075</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-11"/>
          <updated date="2026-03-11"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-12" test_ref="oval:com.tuxcare.clsa:tst:1773222322008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776420007" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-4519</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776420007" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1776420007" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>* SECURITY UPDATE: command-line option injection in webbrowser.open()
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in
       webbrowser.open() URLs to prevent command-line option injection
       in browser subprocesses
     - CVE-2026-4519</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-17"/>
          <updated date="2026-04-17"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="low" public="20260320">CVE-2026-4519</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-14" test_ref="oval:com.tuxcare.clsa:tst:1776420007008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776421032" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-4519</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776421032" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1776421032" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>* SECURITY UPDATE: command-line option injection in webbrowser.open()
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in
       webbrowser.open() URLs to prevent command-line option injection
       in browser subprocesses
     - CVE-2026-4519</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-17"/>
          <updated date="2026-04-17"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="low" public="20260320">CVE-2026-4519</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-29" test_ref="oval:com.tuxcare.clsa:tst:1776421032007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777384579" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-0450, CVE-2026-6100</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777384579" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777384579" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <description>* SECURITY UPDATE: zipfile quoted-overlap zip bomb
     - debian/patches/CVE-2024-0450.patch: raise BadZipFile when an
       archive entry overlaps with another entry or the central
       directory, preventing quoted-overlap zip bombs with extreme
       compression ratios.
     - CVE-2024-0450
   * SECURITY UPDATE: use-after-free in lzma/bz2 decompressors
     - debian/patches/CVE-2026-6100.patch: null next_in at the error:
       label of decompress() in Modules/_bz2module.c and
       Modules/_lzmamodule.c so the decompressor cannot be re-used
       with a stale buffer pointer after a MemoryError.
     - CVE-2026-6100</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-28"/>
          <updated date="2026-04-28"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-30" test_ref="oval:com.tuxcare.clsa:tst:1777384579007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777478454" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-6100</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777478454" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777478454" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2020-27619" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <reference ref_id="CVE-2021-3177" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" source="CVE"/>
        <reference ref_id="CVE-2021-4189" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in
     BZ2Decompressor when MemoryError is raised in the C-level
     decompress() helper
     - debian/patches/CVE-2026-6100.patch: defensively null
       bzs-&gt;next_in on the error: path of BZ2Decomp_decompress in
       Modules/bz2module.c.
     - CVE-2026-6100</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-29"/>
          <updated date="2026-04-29"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" impact="critical" public="20201022">CVE-2020-27619</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-120" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" impact="critical" public="20210119">CVE-2021-3177</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" impact="moderate" public="20220824">CVE-2021-4189</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-16" test_ref="oval:com.tuxcare.clsa:tst:1777478454008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777623116" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2021-28861, CVE-2024-0397, CVE-2024-6923, CVE-2026-1299</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777623116" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777623116" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <reference ref_id="CVE-2021-28861" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>* SECURITY UPDATE: header injection via newline in email.Generator
     - debian/patches/CVE-2026-1299.patch: add HeaderWriteError exception
       to Lib/email/errors.py, add NEWLINE_WITHOUT_FWSP regex to
       Lib/email/generator.py and check the header *value* in all four
       branches of Generator._write_headers(), raising HeaderWriteError
       when a CR/LF without folding whitespace is found. Updates
       test_embedded_header_via_string_rejected to expect
       HeaderWriteError instead of HeaderParseError. In Python 2.7 this
       single Generator-class hardening covers both upstream
       CVE-2026-1299 (BytesGenerator) and CVE-2024-6923 because
       BytesGenerator does not exist in 2.7.
     - CVE-2026-1299
   * SECURITY UPDATE: missing header-name newline check in email.Generator
     - debian/patches/CVE-2024-6923.patch: add NEWLINE_WITHOUT_FWSP check
       on the header *name* at the top of Generator._write_headers() in
       Lib/email/generator.py, raising HeaderWriteError when a CR/LF
       without folding whitespace is found in the header name. Documents
       HeaderWriteError in Doc/library/email.errors.rst and adds a
       test_invalid_header_format regression test in
       Lib/email/test/test_email_renamed.py.
     - CVE-2024-6923
   * SECURITY UPDATE: ssl.SSLContext data race in cert_store_stats /
     get_ca_certs
     - debian/patches/CVE-2024-0397.patch: backport of upstream 3.8
       commit 29c97287d2 ("[3.8] gh-114572: Fix locking in
       cert_store_stats and get_ca_certs"). Adds a polyfill of
       OpenSSL 3.3's X509_STORE_get1_objects() (deep-copy under
       X509_STORE_lock()) and replaces the shared, unlocked
       X509_STORE_get0_objects() calls in cert_store_stats() and
       get_ca_certs() in Modules/_ssl.c, preventing a memory race
       and potential use-after-free when an SSLContext is shared
       across multiple threads.
     - CVE-2024-0397
   * SECURITY UPDATE: open redirect in BaseHTTPServer when path starts
     with //
     - debian/patches/CVE-2021-28861.patch: backport of upstream commit
       4abab6b603 ("gh-87389: Fix an open redirection vulnerability in
       http.server"). In Lib/BaseHTTPServer.py, after the request line
       is parsed, collapse any leading run of '/' characters to a
       single '/' so an attacker-controlled '//evil.example/...' path
       cannot become an absolute scheme-less URI in a 301 Location
       header. Adds a regression test in Lib/test/test_httpservers.py.
     - CVE-2021-28861</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" cwe="CWE-601" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" impact="important" public="20220823">CVE-2021-28861</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-17" test_ref="oval:com.tuxcare.clsa:tst:1777623116008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777635079" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-0397, CVE-2024-4032, CVE-2024-6923, CVE-2026-1299</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777635079" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777635079" source="CLSA"/>
        <reference ref_id="CVE-2024-4032" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>* SECURITY UPDATE: email BytesGenerator header injection
     - debian/patches/CVE-2026-1299.patch: verify generated headers in
       email.generator.BytesGenerator and Generator. Adds the
       HeaderWriteError exception, NEWLINE_WITHOUT_FWSP /
       NEWLINE_WITHOUT_FWSP_BYTES regexes, and the
       Policy.verify_generated_headers attribute, then raises
       HeaderWriteError when the folded header does not end with the
       policy linesep or contains a stray newline. Includes the
       CVE-2024-6923 prerequisite hardening of the string Generator.
     - CVE-2026-1299
   * SECURITY UPDATE: ssl.SSLContext memory race in cert_store_stats /
     get_ca_certs
     - debian/patches/CVE-2024-0397.patch: backport the upstream
       X509_STORE_get1_objects shim and the x509_object_dup helper
       from cpython 29c97287d205bf2f410f4895ebce3f43b5160524, then
       switch _ssl__SSLContext_cert_store_stats_impl and
       _ssl__SSLContext_get_ca_certs_impl to take a deep-copy snapshot
       of the X509_STORE under lock, freeing the snapshot before
       returning. Closes a use-after-free triggered by loading
       certificates concurrently from another thread.
     - CVE-2024-0397
   * SECURITY UPDATE: ipaddress is_private / is_global misclassification
     - debian/patches/CVE-2024-4032.patch: backport upstream
       gh-113171 / gh-65056. Update Lib/ipaddress.py to align the
       _private_networks lists with the IANA special-purpose registries
       and add _private_networks_exceptions so that
       is_private / is_global no longer misclassify addresses in
       192.0.0.0/24 (with 192.0.0.9 and 192.0.0.10 exceptions),
       64:ff9b:1::/48, 2002::/16, and the 2001::/23 sub-range
       exceptions (2001:1::1, 2001:1::2, 2001:3::/32, 2001:4:112::/48,
       2001:20::/28, 2001:30::/28). Includes the matching docs and
       test updates.
     - CVE-2024-4032</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-440" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" impact="important" public="20240617">CVE-2024-4032</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-31" test_ref="oval:com.tuxcare.clsa:tst:1777635079007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778157333" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-3446</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778157333" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778157333" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>* SECURITY UPDATE: binascii.a2b_base64 / base64.b64decode stop decoding
     after the first padded quad, silently dropping any excess data. The
     behaviour can lead to data being accepted that other implementations
     process differently.
     - debian/patches/CVE-2026-3446.patch: backport of upstream commits
       4561f6418a (main), e31c55121620 (3.14), 1f9958f909c1 (3.13). Treats
       the pad character as non-alphabet data per RFC 4648 section 3.3:
       the loop in binascii_a2b_base64_impl no longer breaks out on a pad
       sequence; a `pads` counter is added so post-loop validation still
       raises "Incorrect padding" for inputs that do not satisfy
       `quad_pos + pads == 4`. The unused `binascii_find_valid` helper
       is removed.
     - CVE-2026-3446</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-07"/>
          <updated date="2026-05-07"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-32" test_ref="oval:com.tuxcare.clsa:tst:1778157333007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778193425" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-3446</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778193425" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778193425" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>* SECURITY UPDATE: binascii.a2b_base64 / base64.b64decode stop decoding
     after the first padded quad, silently dropping any excess data. The
     behaviour can lead to data being accepted that other implementations
     process differently.
     - debian/patches/CVE-2026-3446.patch: backport of upstream commits
       4561f6418a (main), e31c55121620 (3.14), 1f9958f909c1 (3.13). Treats
       the pad character as non-alphabet data per RFC 4648 section 3.3:
       the loop in binascii_a2b_base64 no longer breaks out on a pad
       sequence; a `pads` counter is added so post-loop validation still
       raises "Incorrect padding" for inputs that do not satisfy
       `quad_pos + pads == 4`. The unused `binascii_find_valid` helper
       is removed.
     - CVE-2026-3446</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-07"/>
          <updated date="2026-05-07"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-18" test_ref="oval:com.tuxcare.clsa:tst:1778193425008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779270551" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-0672, CVE-2026-3644, CVE-2026-4224</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779270551" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779270551" source="CLSA"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>* SECURITY UPDATE: Modules/pyexpat.c conv_content_model could overflow
     the C stack when an Expat parser with a registered ElementDeclHandler
     parsed a deeply nested DTD content model, causing a denial-of-service.
     - debian/patches/CVE-2026-4224.patch: C-level backport of cpython
       eb0e8be3a7 (gh-145986, Stan Ulbrych + Bénédikt Tran). Wraps
       conv_content_model with Py_EnterRecursiveCall / Py_LeaveRecursiveCall
       so deep nesting raises RuntimeError instead of crashing. The
       upstream Lib/test/test_pyexpat.py test addition is skipped: it
       depends on test.support.infinite_recursion() which only exists
       in Python 3.x test.support.
     - CVE-2026-4224
   * SECURITY UPDATE: Lib/Cookie.py Morsel accepts control characters
     in reserved-attribute values, in key/value/coded_value via .set(),
     and via the inherited dict.update() / pickle restoration paths,
     allowing newline-based HTTP header injection via Set-Cookie. The
     upstream CVE description and py3 fix target Lib/http/cookies.py
     (which does not exist in py2); a runtime POC confirmed the same
     vulnerability class is reachable through py2's Cookie module via
     five distinct write paths.
     - debian/patches/CVE-2026-0672-CVE-2026-3644.patch: py2 adaptation
       of cpython 95746b3a13 (gh-143919, Seth Larson) and 57e88c1cf9
       (gh-145599, Stan Ulbrych + Victor Stinner). Adds a
       _has_control_character helper and validates at Morsel.__setitem__,
       .setdefault, .set, an explicit .update, an explicit .__setstate__,
       plus re-validates the assembled output in Morsel.js_output and
       BaseCookie.output (defence-in-depth against direct attribute
       mutation). The py3 __ior__ hunk is not ported (py2 dict has no
       `|=` operator). Doctest fixture `keebler="...fudge=\012;"` is
       updated to drop the embedded newline, mirroring the upstream
       doctest fix.
     - CVE-2026-0672, CVE-2026-3644</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-20"/>
          <updated date="2026-05-20"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-19" test_ref="oval:com.tuxcare.clsa:tst:1779270551008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779275645" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-15282, CVE-2026-0672, CVE-2026-3644, CVE-2026-4224</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779275645" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779275645" source="CLSA"/>
        <reference ref_id="CVE-2025-15282" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>* SECURITY UPDATE: urllib.request.DataHandler accepted data: URLs whose
     mediatype contained control characters, allowing newline-based HTTP
     header injection downstream.
     - debian/patches/CVE-2025-15282.patch: backport of cpython
       f25509e78e (gh-143925, Seth Larson). Adds a [\\x00-\\x1F\\x7F]
       regex check in data_open() and a matching test_invalid_mediatype.
     - CVE-2025-15282
   * SECURITY UPDATE: http.cookies.Morsel did not reject control characters
     in keys / values / coded_value, allowing cookie injection via
     __setitem__, setdefault, set, and BaseCookie.output.
     - debian/patches/CVE-2026-0672.patch: backport of cpython
       95746b3a13 (gh-143919, Seth Larson). Adds _has_control_character
       helper and inserts validation in __setitem__, setdefault, set,
       plus a wrap of BaseCookie.OutputString / output.
     - CVE-2026-0672
   * SECURITY UPDATE: the CVE-2026-0672 fix was incomplete; control
     characters could still bypass via Morsel.update(), |=, __setstate__
     (pickle), and BaseCookie.js_output().
     - debian/patches/CVE-2026-3644.patch: backport of cpython
       57e88c1cf9 (gh-145599, Stan Ulbrych + Victor Stinner). Adds
       validation to Morsel.update(), defines explicit Morsel.__ior__
       (was inherited from dict and bypassed validation), validates
       __setstate__ before assigning attributes, and re-validates the
       assembled output string in js_output().
     - CVE-2026-3644
   * SECURITY UPDATE: Modules/pyexpat.c conv_content_model could overflow
     the C stack when an Expat parser with a registered ElementDeclHandler
     parsed a deeply nested DTD content model, causing a denial-of-service.
     - debian/patches/CVE-2026-4224.patch: backport of cpython
       eb0e8be3a7 (gh-145986, Stan Ulbrych + Bénédikt Tran). Wraps
       conv_content_model with Py_EnterRecursiveCall / Py_LeaveRecursiveCall
       so deep nesting raises RecursionError instead of crashing.
     - CVE-2026-4224</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-20"/>
          <updated date="2026-05-20"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" impact="moderate" public="20260120">CVE-2025-15282</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-33" test_ref="oval:com.tuxcare.clsa:tst:1779275645007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779876526" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-41080, CVE-2026-7210</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779876526" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779876526" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: CVE-2026-7210 + CVE-2026-41080 (paired) — backport
     the libexpat 16-byte salt API (XML_SetHashSalt16Bytes) into bundled
     expat 2.4.1 and wire pyexpat/_elementtree to use it. Together these
     restore proper hash-flood mitigation for xml.parsers.expat and
     xml.etree.ElementTree.
     - debian/patches/CVE-2026-7210.patch: backport of cpython
       24b8f12544 (gh-149018, Stan Ulbrych). Adds a new 16-byte
       _Py_HashSecret.expat.hashsalt16 slot in Include/pyhash.h
       (overlapping the existing padding), extends the PyExpat CAPI in
       Include/pyexpat.h with SetHashSalt16Bytes, and prefers the new
       API in Modules/pyexpat.c and Modules/_elementtree.c when built
       against libexpat exposing it; falls back to the legacy
       XML_SetHashSalt path otherwise. The two XML_COMBINED_VERSION
       gates are extended with `|| defined(XML_HAS_HASHSALT16BYTES_BACKPORT)`
       so the new code path activates against the bundled patched
       libexpat without bumping its advertised version, while
       --with-system-expat builds (Alpine) keep the upstream
       `&gt;= 20800` semantics.
     - debian/patches/CVE-2026-41080.patch: backport of libexpat
       PR #1183. Widens the parser's internal hash salt from
       `unsigned long m_hash_secret_salt` to a full
       `struct sipkey m_hash_secret_salt_128` (+ an
       m_hash_secret_salt_set flag), adds the new
       XML_SetHashSalt16Bytes API and the matching
       XML_HAS_HASHSALT16BYTES_BACKPORT marker in expat.h, and namespaces
       the new symbol via pyexpatns.h. Applied to bundled
       Modules/expat/; on Alpine `prepare()` deletes Modules/expat
       after the patch, so the libexpat backport is a no-op there and
       the system libexpat decides whether the new API is available.
     - CVE-2026-7210
     - CVE-2026-41080</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-34" test_ref="oval:com.tuxcare.clsa:tst:1779876526007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779883069" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-41080, CVE-2026-7210</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779883069" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779883069" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: CVE-2026-7210 + CVE-2026-41080 (paired): backport
     the libexpat 16-byte salt API (XML_SetHashSalt16Bytes) into bundled
     expat 2.2.8 and wire pyexpat/_elementtree to use it. Together these
     restore proper hash-flood mitigation. xml.parsers.expat and
     xml.etree.ElementTree previously used only the legacy 8-byte
     XML_SetHashSalt API; that salt is brute-forceable with modern
     hardware, allowing a crafted XML document to trigger hash
     collisions and a denial of service.
     - debian/patches/CVE-2026-7210.patch: backport of cpython
       24b8f12544 (gh-149018, Stan Ulbrych). Switches pyexpat and
       _elementtree to XML_SetHashSalt16Bytes when built/linked against
       libexpat &gt;= 2.8.0, falling back to the legacy XML_SetHashSalt on
       older expat. Adds a hashsalt16[16] field to _Py_HashSecret_t in
       Include/object.h (seeded by _PyRandom_Init alongside prefix /
       suffix) and a NULL-able SetHashSalt16Bytes function pointer in
       the pyexpat CAPI struct so _elementtree can dispatch at runtime.
       No upstream backport to 2.7 exists; upstream backports landed
       only to 3.14 / 3.15.
     - debian/patches/CVE-2026-41080.patch: backport of libexpat
       PR #1183 into the bundled Modules/expat/ tree (libexpat 2.2.8).
       Widens m_hash_secret_salt from `unsigned long` to a 128-bit
       `struct sipkey` and adds the new public XML_SetHashSalt16Bytes()
       entry point. Since pyexpat.so / _elementtree.so are statically
       linked against this tree, the cpython half now consumes full
       16-byte entropy without requiring an external libexpat
       &gt;= 2.8.0 at runtime.
     - CVE-2026-7210
     - CVE-2026-41080</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-20" test_ref="oval:com.tuxcare.clsa:tst:1779883069008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1780512337" version="1">
      <metadata>
        <title>Fix of 12 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1780512337" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1780512337" source="CLSA"/>
        <reference ref_id="CVE-2025-4516" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2024-50602" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2025-11468" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" source="CVE"/>
        <description>* SECURITY UPDATE: tarfile applied AREGTYPE -&gt; DIRTYPE normalization
     even during multi-block GNU long members (GNUTYPE_LONGNAME /
     GNUTYPE_LONGLINK), enabling a parsing differential vs. other tar
     implementations.
     - debian/patches/CVE-2025-13462.patch: backport of cpython
       42d754e3 (gh-143934, Seth Larson + Eashwar Ranganathan).
       Threads a dircheck flag through frombuf / fromtarfile so
       normalization is skipped on the inner header during GNU long
       name / link handling.
     - CVE-2025-13462
   * SECURITY UPDATE: wsgiref.headers.Headers did not reject control
     characters in header names / values, allowing HTTP header
     injection from WSGI applications.
     - debian/patches/CVE-2026-0865.patch: combined backport of
       cpython f7fceed7 (gh-143917) which adds the control-char regex
       check, 66da7bf6 (gh-143916 HTAB follow-up) which splits the
       check so HTAB is allowed in header values (RFC 9110 Section
       5.5) but still rejected in header names, plus d931725b
       (gh-144370) which disallows control characters in status in
       wsgiref.handlers.start_response.
     - CVE-2026-0865
   * SECURITY UPDATE: http.client did not reject CR/LF in HTTPConnection
     CONNECT tunnel host / per-tunnel-header values, enabling request
     injection through a proxy tunnel.
     - debian/patches/CVE-2026-1502.patch: backport of cpython
       05ed7ce7 + b1cf9016 (gh-146212, Seth Larson). Adapted to 3.6's
       per-line self.send() form (no headers=[] list in _tunnel until
       3.9+). Validates _tunnel_host and per-header name / value in
       _tunnel().
     - CVE-2026-1502
   * SECURITY UPDATE: http.cookies.Morsel.js_output() emitted an inline
     &lt;script&gt; snippet that only escaped " and left &lt;/script&gt; intact,
     enabling HTML injection when a cookie value contains &lt;/script&gt;.
     - debian/patches/CVE-2026-6019.patch: backport of cpython
       76b3923d (gh-148848, Seth Larson). Base64-encodes the cookie
       value and emits document.cookie = atob("...") instead of
       pasting the raw cookie string into the JavaScript snippet.
       Composes on top of CVE-2026-3644's js_output() control-character
       recheck (preserved).
     - CVE-2026-6019</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-03"/>
          <updated date="2026-06-03"/>
          <cve cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" impact="moderate" public="20250515">CVE-2025-4516</cve>
          <cve cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-237" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-754" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" impact="moderate" public="20241027">CVE-2024-50602</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-140" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" impact="moderate" public="20260120">CVE-2025-11468</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-37" test_ref="oval:com.tuxcare.clsa:tst:1780512337007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781101094" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-15366, CVE-2025-15367</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781101094" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1781101094" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <description>* SECURITY UPDATE: command injection via control characters in imaplib
     - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of
       cpython 6262704b (gh-143921, Seth Michael Larson).
       imaplib.IMAP4._command() concatenated each argument into the
       wire-level command without inspecting it, so user-controlled text
       (e.g. a username passed to IMAP4.login()) containing CR/LF or other
       control characters could inject a second IMAP command. Adds a
       module-level _control_chars regex to Lib/imaplib.py and a guard in
       _command() that rejects any argument containing a byte in
       [\x00-\x1F\x7F] with ValueError before concatenation. Adds a
       test_control_characters regression test to Lib/test/test_imaplib.py.
     - CVE-2025-15366
   * SECURITY UPDATE: command injection via control characters in poplib
     - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of
       cpython b234a2b6 (gh-143923, Seth Michael Larson).
       poplib.POP3._putcmd() sent its argument to the server without
       inspecting it, so user-controlled text passed to
       user()/pass_()/apop()/rpop()/top() could inject a second POP3
       command. Adds a guard in _putcmd() (Lib/poplib.py) that rejects any
       argument containing a byte in [\x00-\x1F\x7F] with ValueError before
       sending. Adds a test_control_characters regression test to
       Lib/test/test_poplib.py.
     - CVE-2025-15367</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-10"/>
          <updated date="2026-06-10"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-21" test_ref="oval:com.tuxcare.clsa:tst:1781101094008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781519474" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-15366, CVE-2025-15367</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781519474" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1781519474" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <description>* SECURITY UPDATE: imaplib.IMAP4._command() concatenated each command
     argument into the wire-level command without inspecting it, so a
     caller passing user-controlled text could inject additional IMAP
     commands using CR/LF or other control characters.
     - debian/patches/CVE-2025-15366.patch: backport of cpython
       6262704b (gh-143921, Seth Larson). Adds a module-level
       _control_chars regex and rejects any byte in [\x00-\x1F\x7F] with
       ValueError before concatenating each argument. Upstream-main-only
       fix; mirrors Red Hat's python3-3.6.8-21.el7_9.4 (RHSA-2026:6464).
     - CVE-2025-15366
   * SECURITY UPDATE: poplib.POP3._putcmd() encoded its argument and sent
     it to the server without inspecting it, allowing the same command
     injection via user() / pass_() / apop() / rpop() / top().
     - debian/patches/CVE-2025-15367.patch: backport of cpython
       b234a2b6 (gh-143923, Seth Larson). Rejects any byte in
       [\x00-\x1F\x7F] with ValueError before sending. Upstream-main-only
       fix; mirrors Red Hat's python3-3.6.8-21.el7_9.4 (RHSA-2026:6464).
     - CVE-2025-15367</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-15"/>
          <updated date="2026-06-15"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-38" test_ref="oval:com.tuxcare.clsa:tst:1781519474007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1782295755" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-9669</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1782295755" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1782295755" source="CLSA"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <description>* SECURITY UPDATE: a bz2.BZ2Decompressor could be reused after a libbz2
     decompression error. Re-entering BZ2_bzDecompress() once libbz2 had
     reported an error could write past the end of a stack buffer
     (CWE-121, possible stack buffer overflow).
     - debian/patches/CVE-2026-9669.patch: backport of cpython
       5755d0f0 (gh-150599, Stan Ulbrych). Records the libbz2 error in a
       new bzerror field, clears needs_input on the error path, and makes
       decompress() raise ValueError ("Decompressor is unusable after a
       previous error") on any subsequent call. Adapted to 3.6: plain
       needs_input reset (no free-threading atomics) and the existing
       ACQUIRE_LOCK/RELEASE_LOCK wrappers; NEWS.d fragment omitted as
       3.6.15 ships a single Misc/NEWS.
     - CVE-2026-9669</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-24"/>
          <updated date="2026-06-24"/>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-39" test_ref="oval:com.tuxcare.clsa:tst:1782295755007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1782995116" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-11168, CVE-2024-50602, CVE-2025-0938</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1782995116" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1782995116" source="CLSA"/>
        <reference ref_id="CVE-2024-50602" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <description>* SECURITY UPDATE: improper validation of bracketed hosts in urlparse
     - debian/patches/CVE-2024-11168.patch: backport of cpython
       b2171a2fd4 (gh-103848). urlparse.urlsplit() accepted bracketed
       hosts that are neither valid IPv6 nor IPvFuture literals. Adds
       _check_bracketed_host() to Lib/urlparse.py, called from both the
       "http" fast-path and the generic branch. Python 2.7 has no
       ipaddress module, so the bracket content is validated with
       socket.inet_pton() (IPv4 in brackets rejected; otherwise must
       parse as IPv6).
     - CVE-2024-11168
   * SECURITY UPDATE: NULL deref in bundled libexpat XML_StopParser
     - debian/patches/CVE-2024-50602.patch: backport of libexpat PR
       #915 (51c7019069b8) into the bundled Modules/expat/ (2.2.8).
       XML_StopParser() on a parser in the XML_INITIALIZED state left it
       in a state where XML_ResumeParser() crashed via a NULL
       dereference. XML_StopParser() now refuses to stop/suspend an
       unstarted parser, returning the new XML_ERROR_NOT_STARTED.
     - CVE-2024-50602
   * SECURITY UPDATE: square brackets allowed in parsed URL domain names
     - debian/patches/CVE-2025-0938.patch: backport of cpython
       b8b4b713c5 (gh-105704). Completes CVE-2024-11168 by rejecting
       square brackets in plain domain names. Adds
       _check_bracketed_netloc() to Lib/urlparse.py (mirroring
       NetlocResultMixins._hostinfo()) and uses it in both branches of
       urlsplit() in place of the inline bracket extraction.
     - CVE-2025-0938</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-02"/>
          <updated date="2026-07-02"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-754" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" impact="moderate" public="20241027">CVE-2024-50602</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-22" test_ref="oval:com.tuxcare.clsa:tst:1782995116008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1783341577" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1783341577" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1783341577" source="CLSA"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2013-0340" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2013-0340" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <description>* SECURITY UPDATE: expat billion-laughs / entity-expansion amplification DoS
     - debian/patches/CVE-2013-0340.patch: backport libexpat's billion-laughs
       attack protection (libexpat PR #466 / 2.4.0) into the bundled expat
       2.2.8 tree (Modules/expat/xmlparse.c, expat.h, internal.h). Adds the
       accounting machinery, XML_ERROR_AMPLIFICATION_LIMIT_BREACH and the
       XML_SetBillionLaughsAttackProtection{MaximumAmplification,
       ActivationThreshold} setters (default 100x after 8 MiB). The fix is
       applied to the bundled copy (not system expat) so it coexists with the
       CloudLinux XML_SetHashSalt16Bytes extension; new public symbols are
       namespaced in pyexpatns.h.
     - CVE-2013-0340
   * SECURITY UPDATE: control characters accepted in wsgiref response headers
     - debian/patches/CVE-2026-0865.patch: backport of cpython gh-143916
       (GH-143917) and the HTAB follow-up (GH-144762). wsgiref.headers.Headers
       (Lib/wsgiref/headers.py) now rejects C0/DEL control characters in header
       names and values; HTAB remains legal in values, not names. Adapted to
       2.7 (positional _convert_string_type flag, no keyword-only argument).
     - CVE-2026-0865
   * SECURITY UPDATE: CR/LF injection in HTTP CONNECT tunnel headers
     - debian/patches/CVE-2026-1502.patch: backport of cpython gh-146211
       (GH-146212). HTTPConnection._tunnel() (Lib/httplib.py) validates the
       tunnel host and each tunnel request header with the existing
       _contains_disallowed_url_pchar_re / _is_legal_header_name /
       _is_illegal_header_value helpers, rejecting control characters.
     - CVE-2026-1502
   * SECURITY UPDATE: template injection via cookie values in js_output()
     - debian/patches/CVE-2026-6019.patch: backport of cpython gh-90309
       (GH-148889), on top of CVE-2026-3644. Cookie.Morsel.js_output()
       (Lib/Cookie.py) base64-encodes the cookie value and emits it via
       atob() so it cannot break out of the JS string literal.
     - CVE-2026-6019
   * SECURITY UPDATE: bz2 decompressor reuse-after-error stack overflow
     - debian/patches/CVE-2026-9669.patch: port of cpython gh-150599
       (GH-150600) to the 2.7 bz2 wrapper (Modules/bz2module.c). After libbz2
       reports a decompression error the stream is inconsistent and reusing it
       can write past the output buffer; the decompressor now records the
       error and raises ValueError on any further decompress() call.
     - CVE-2026-9669</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-06"/>
          <updated date="2026-07-06"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cwe="CWE-611" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2013-0340" impact="unknown" public="20140121">CVE-2013-0340</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-24" test_ref="oval:com.tuxcare.clsa:tst:1783341577008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784307159" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-6923</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784307159" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784307159" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <description>* ALTPYTH-591: Update to 3.11.15 version</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159001"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159002"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159003"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159004"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159005"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159006"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-1" test_ref="oval:com.tuxcare.clsa:tst:1784307159007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784308844" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-6923</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784308844" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784308844" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <description>* ALTPYTH-592: Update to 3.10.20 version</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844001"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844002"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844003"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844004"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844005"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844006"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-1" test_ref="oval:com.tuxcare.clsa:tst:1784308844007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784800201" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784800201" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784800201" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <description>* SECURITY UPDATE: reject control characters in imaplib IMAP4 commands
     - debian/patches/CVE-2025-15366.patch: guard IMAP4._command()
     - CVE-2025-15366
   * SECURITY UPDATE: reject control characters in poplib POP3 commands
     - debian/patches/CVE-2025-15367.patch: guard POP3._putcmd()
     - CVE-2025-15367
   * SECURITY UPDATE: control-character injection via http.cookies paths
     - debian/patches/CVE-2026-3644.patch: guard Morsel.update()/|=/unpickle/js_output
     - CVE-2026-3644
   * SECURITY UPDATE: uncontrolled recursion in pyexpat content model
     - debian/patches/CVE-2026-4224.patch: recursion guard in conv_content_model()
     - CVE-2026-4224
   * SECURITY UPDATE: webbrowser argument injection via leading-dash URL
     - debian/patches/CVE-2026-4519.patch: reject URLs starting with '-'
     - CVE-2026-4519</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201001"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201002"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201003"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201004"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201005"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201006"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-3" test_ref="oval:com.tuxcare.clsa:tst:1784800201007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784803760" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-15308</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784803760" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784803760" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>* SECURITY UPDATE: quadratic-complexity CPU DoS in incremental HTML parsing
     - debian/patches/CVE-2026-15308.patch: port of cpython gh-153030
       (GH-153031). HTMLParser.feed() (Lib/HTMLParser.py) previously
       concatenated new data onto the unparsed buffer and re-scanned it from
       the start on every call, so feeding an unterminated construct in many
       small chunks was quadratic. New data is now accumulated in a list and
       only joined and parsed once enough has piled up; close() flushes the
       pending buffer.
     - CVE-2026-15308</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760001"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760002"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760003"/>
        <criterion comment="alt-python27-idle is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760004"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760005"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760006"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760007"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-25" test_ref="oval:com.tuxcare.clsa:tst:1784803760008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784819045" version="1">
      <metadata>
        <title>Fix of 9 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784819045" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784819045" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-4786" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: webbrowser.open() dash-prefix check bypass via the action token
     - debian/patches/CVE-2026-4786.patch: validate the action-expanded URL
       and reorder the action/URL substitution so a URL containing the action
       token cannot expand into a dash-prefixed browser flag (CVE-2026-4519
       bypass).
     - CVE-2026-4786
   * SECURITY UPDATE: dangling input pointer (UAF) in bz2/lzma decompressors
     - debian/patches/CVE-2026-6100.patch: clear next_in on the MemoryError
       error path in _bz2/_lzma decompress() so a reused decompressor cannot
       read or write through a stale pointer to the released input buffer.
     - CVE-2026-6100
   * SECURITY UPDATE: insufficient Expat hash-flooding entropy
     - debian/patches/CVE-2026-7210.patch: seed Expat with 16 bytes of
       entropy via XML_SetHashSalt16Bytes when libexpat exposes it (weak
       symbol), falling back to the legacy 8-byte salt otherwise.
     - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes
       into the BUNDLED expat (applied on ubuntu16.04 only; el7 on the RPM
       side) so the 16-byte salt path above is not inert; other platforms
       link system expat.
     - CVE-2026-7210
   * SECURITY UPDATE: bz2.BZ2Decompressor reuse after error (stack overflow)
     - debian/patches/CVE-2026-9669.patch: record the libbz2 error and raise
       ValueError on any subsequent decompress() call instead of re-entering
       libbz2 on an inconsistent stream (CWE-121).
     - CVE-2026-9669</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-88" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" impact="important" public="20260413">CVE-2026-4786</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045001"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045002"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045003"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045004"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045005"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045006"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-3" test_ref="oval:com.tuxcare.clsa:tst:1784819045007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784823365" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-15308</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784823365" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784823365" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>* SECURITY UPDATE: html.parser.HTMLParser had quadratic complexity in
     incremental parsing. An unterminated construct (e.g. a tag or comment)
     fed across many feed() calls made the parser rescan the growing buffer
     and reconcatenate new data onto it on every call, both quadratic in the
     input size, allowing a CPU denial-of-service on uncontrolled data
     (CWE-407, algorithmic complexity).
     - debian/patches/CVE-2026-15308.patch: backport of cpython bcf98ddb
       (gh-153030, Serhiy Storchaka). feed() now accumulates new data in a
       list and only joins and parses it once enough has piled up, and
       close() flushes any pending buffer. Adapted to 3.6: feed()/close()/
       reset() logic identical to upstream (3.6 already has list.clear());
       the regression test is added with "from test import support"; the
       NEWS.d fragment is omitted as 3.6.15 ships a single Misc/NEWS.
     - CVE-2026-15308</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365001"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365002"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365003"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365004"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365005"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365006"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-40" test_ref="oval:com.tuxcare.clsa:tst:1784823365007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784825498" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-4786, CVE-2026-6100, CVE-2026-7210, CVE-2026-9669</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784825498" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784825498" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-4786" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>* SECURITY UPDATE: webbrowser argument injection via action-token substitution
     - debian/patches/CVE-2026-4786.patch: validate expanded command (bypass of CVE-2026-4519)
     - CVE-2026-4786
   * SECURITY UPDATE: use-after-free in bz2/lzma decompressor reuse after MemoryError
     - debian/patches/CVE-2026-6100.patch: clear next_in on the decompress error path
     - CVE-2026-6100
   * SECURITY UPDATE: insufficient entropy for Expat hash-flooding protection
     - debian/patches/CVE-2026-7210.patch: use XML_SetHashSalt16Bytes 16-byte entropy
     - CVE-2026-7210
   * SECURITY UPDATE: insufficient entropy in bundled Expat (libexpat) hash-flooding protection
     - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the bundled expat so the CVE-2026-7210 16-byte salt path is not inert on bundled-expat builds
     - CVE-2026-41080
   * SECURITY UPDATE: stack buffer overflow via bz2 decompressor reuse after error
     - debian/patches/CVE-2026-9669.patch: refuse reuse after a previous error
     - CVE-2026-9669</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-88" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" impact="important" public="20260413">CVE-2026-4786</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498001"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498002"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498003"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498004"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498005"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498006"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-4" test_ref="oval:com.tuxcare.clsa:tst:1784825498007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784900909" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-15308</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784900909" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784900909" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>* SECURITY UPDATE: quadratic-complexity CPU denial of service in html.parser
     - debian/patches/CVE-2026-15308.patch: accumulate incremental feed() data
       to avoid re-scanning/concatenating unterminated constructs quadratically
     - CVE-2026-15308</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-24"/>
          <updated date="2026-07-24"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909001"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909002"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909003"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909004"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909005"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909006"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-5" test_ref="oval:com.tuxcare.clsa:tst:1784900909007"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-14" id="oval:com.tuxcare.clsa:tst:1759247378007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759247378001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-3" id="oval:com.tuxcare.clsa:tst:1759509928008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1759509928001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-6" id="oval:com.tuxcare.clsa:tst:1760093456008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760093456001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-7" id="oval:com.tuxcare.clsa:tst:1760369775008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760369775001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-8" id="oval:com.tuxcare.clsa:tst:1760705964008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1760705964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-19" id="oval:com.tuxcare.clsa:tst:1762527688007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1762527688001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-20" id="oval:com.tuxcare.clsa:tst:1765793732007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1765793732001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-23" id="oval:com.tuxcare.clsa:tst:1771342958007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771342958001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-9" id="oval:com.tuxcare.clsa:tst:1771868964008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1771868964001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-25" id="oval:com.tuxcare.clsa:tst:1772099114007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772099114001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-10" id="oval:com.tuxcare.clsa:tst:1772109537008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772109537001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-27" id="oval:com.tuxcare.clsa:tst:1772444571007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772444571001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-28" id="oval:com.tuxcare.clsa:tst:1772618241007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772618241001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-11" id="oval:com.tuxcare.clsa:tst:1772700745008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1772700745001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-12" id="oval:com.tuxcare.clsa:tst:1773222322008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1773222322001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-14" id="oval:com.tuxcare.clsa:tst:1776420007008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776420007001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-29" id="oval:com.tuxcare.clsa:tst:1776421032007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776421032001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-30" id="oval:com.tuxcare.clsa:tst:1777384579007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777384579001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-16" id="oval:com.tuxcare.clsa:tst:1777478454008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777478454001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-17" id="oval:com.tuxcare.clsa:tst:1777623116008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777623116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-31" id="oval:com.tuxcare.clsa:tst:1777635079007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1777635079001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-32" id="oval:com.tuxcare.clsa:tst:1778157333007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778157333001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-18" id="oval:com.tuxcare.clsa:tst:1778193425008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1778193425001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-19" id="oval:com.tuxcare.clsa:tst:1779270551008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779270551001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-33" id="oval:com.tuxcare.clsa:tst:1779275645007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779275645001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-34" id="oval:com.tuxcare.clsa:tst:1779876526007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779876526001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-20" id="oval:com.tuxcare.clsa:tst:1779883069008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1779883069001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-37" id="oval:com.tuxcare.clsa:tst:1780512337007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1780512337001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-21" id="oval:com.tuxcare.clsa:tst:1781101094008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781101094001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-38" id="oval:com.tuxcare.clsa:tst:1781519474007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781519474001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-39" id="oval:com.tuxcare.clsa:tst:1782295755007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782295755001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-22" id="oval:com.tuxcare.clsa:tst:1782995116008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1782995116001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-24" id="oval:com.tuxcare.clsa:tst:1783341577008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1783341577001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-1" id="oval:com.tuxcare.clsa:tst:1784307159007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784307159001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-1" id="oval:com.tuxcare.clsa:tst:1784308844007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784308844001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-3" id="oval:com.tuxcare.clsa:tst:1784800201007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784800201001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-idle is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-25" id="oval:com.tuxcare.clsa:tst:1784803760008" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759509928008"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784803760001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-3" id="oval:com.tuxcare.clsa:tst:1784819045007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784307159007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784819045001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-40" id="oval:com.tuxcare.clsa:tst:1784823365007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1759247378007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784823365001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-4" id="oval:com.tuxcare.clsa:tst:1784825498007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784825498001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-5" id="oval:com.tuxcare.clsa:tst:1784900909007" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1784308844007"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1784900909001"/>
    </linux:dpkginfo_test>
  </tests>
  <objects>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378001" version="1">
      <linux:name>alt-python36</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378002" version="1">
      <linux:name>alt-python36-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378003" version="1">
      <linux:name>alt-python36-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378004" version="1">
      <linux:name>alt-python36-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378005" version="1">
      <linux:name>alt-python36-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378006" version="1">
      <linux:name>alt-python36-tkinter</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759247378007" version="1">
      <linux:name>alt-python36-tools</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928001" version="1">
      <linux:name>alt-python27</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928002" version="1">
      <linux:name>alt-python27-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928003" version="1">
      <linux:name>alt-python27-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928004" version="1">
      <linux:name>alt-python27-idle</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928005" version="1">
      <linux:name>alt-python27-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928006" version="1">
      <linux:name>alt-python27-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928007" version="1">
      <linux:name>alt-python27-tkinter</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1759509928008" version="1">
      <linux:name>alt-python27-tools</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159001" version="1">
      <linux:name>alt-python311</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159002" version="1">
      <linux:name>alt-python311-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159003" version="1">
      <linux:name>alt-python311-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159004" version="1">
      <linux:name>alt-python311-idle</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159005" version="1">
      <linux:name>alt-python311-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159006" version="1">
      <linux:name>alt-python311-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784307159007" version="1">
      <linux:name>alt-python311-tkinter</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844001" version="1">
      <linux:name>alt-python310</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844002" version="1">
      <linux:name>alt-python310-debug</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844003" version="1">
      <linux:name>alt-python310-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844004" version="1">
      <linux:name>alt-python310-idle</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844005" version="1">
      <linux:name>alt-python310-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844006" version="1">
      <linux:name>alt-python310-test</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1784308844007" version="1">
      <linux:name>alt-python310-tkinter</linux:name>
    </linux:dpkginfo_object>
  </objects>
  <states>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1759247378001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-14</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1759509928001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-3</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760093456001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-6</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760369775001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1760705964001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-8</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1762527688001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-19</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1765793732001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-20</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1771342958001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-23</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1771868964001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-9</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772099114001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-25</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772109537001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-10</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772444571001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-27</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772618241001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-28</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1772700745001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-11</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1773222322001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-12</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776420007001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-14</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776421032001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-29</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777384579001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-30</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777478454001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-16</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777623116001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-17</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1777635079001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-31</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1778157333001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-32</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1778193425001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-18</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779270551001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-19</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779275645001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-33</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779876526001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-34</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1779883069001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-20</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1780512337001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-37</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1781101094001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-21</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1781519474001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-38</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1782295755001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-39</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1782995116001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-22</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1783341577001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-24</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784307159001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.11.15-1</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784308844001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.10.20-1</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784800201001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.10.20-3</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784803760001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.7.18-25</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784819045001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.11.15-3</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784823365001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.6.15-40</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784825498001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.10.20-4</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1784900909001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:3.10.20-5</linux:evr>
    </linux:dpkginfo_state>
  </states>
</oval_definitions>
