Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 180203 - media-sound/pulseaudio-0.9.5 multiple DoS vulnerabilities (CVE-2007-1804)
Summary: media-sound/pulseaudio-0.9.5 multiple DoS vulnerabilities (CVE-2007-1804)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://pulseaudio.org/ticket/67
Whiteboard: B3 [noglsa] jaervosz
Keywords:
Depends on: 180117
Blocks:
  Show dependency tree
 
Reported: 2007-05-29 10:45 UTC by Diego Elio Pettenò (RETIRED)
Modified: 2007-06-24 23:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Diego Elio Pettenò (RETIRED) gentoo-dev 2007-05-29 10:45:10 UTC
Florian Steinel reported this to me as I didn't know about it at all; I'll look into backporting the fixes to 0.9.5, but I'm not really sure if that's feasible, considering the sheer quantity.

Security team please advise.

Thanks in Advance,
Diego
Comment 1 Diego Elio Pettenò (RETIRED) gentoo-dev 2007-05-29 11:17:47 UTC
I've added pulseaudio-0.9.5-r5 with a patch that should fix all the vulnerabilities. There should be no problem with that going stable, as 0.9.6 stable right now is not something I'd like to see myself.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-30 05:58:56 UTC
Thx Diego!

Arches please test and mark stable. Target keywords are:

pulseaudio-0.9.5-r5.ebuild:KEYWORDS="alpha amd64 arm hppa ia64 ppc ppc64 sh sparc x86 ~x86-fbsd"
Comment 3 Andrej Kacian (RETIRED) gentoo-dev 2007-05-30 09:54:42 UTC
Looks like it's not all fixed:

ticho@hiker ~ $ ps ax | grep pulse
29103 ?        Ss     0:00 /usr/bin/pulseaudio --log-target=syslog --disallow-module-loading=1 --system --fail=1 --daemonize=1 --system
29118 pts/3    R+     0:00 grep --colour=auto pulse
ticho@hiker ~ $ ./p 1 localhost

Pulseaudio <= 0.9.5 (rev 1437) termination 0.1
by Luigi Auriemma
e-mail: aluigi@autistici.org
web:    aluigi.org

- check localhost
- connect to 127.0.0.1:4713
- check if the server is still up:

  Server doesn't seem vulnerable

ticho@hiker ~ $ ./p 2 localhost

Pulseaudio <= 0.9.5 (rev 1437) termination 0.1
by Luigi Auriemma
e-mail: aluigi@autistici.org
web:    aluigi.org

- check localhost
- connect to 127.0.0.1:4713
- check if the server is still up:

  Server IS vulnerable!!!

ticho@hiker ~ $ ps ax | grep pulse
29126 pts/3    S+     0:00 grep --colour=auto pulse
ticho@hiker ~ $ 


The "p" binary comes from compiling the pulsex.zip source at http://aluigi.org/poc/pulsex.zip
Comment 4 Andrej Kacian (RETIRED) gentoo-dev 2007-05-30 09:59:17 UTC
Oh, and of course:

ticho@hiker ~ $ emerge -pv pulseaudio --nodeps

These are the packages that would be merged, in order:

[ebuild   R   ] media-sound/pulseaudio-0.9.5-r5  USE="X alsa hal oss tcpd -avahi -caps -jack -lirc" 0 kB 

Total: 1 package (1 reinstall), Size of downloads: 0 kB
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-30 12:23:55 UTC
Back to ebuild.
Comment 6 Diego Elio Pettenò (RETIRED) gentoo-dev 2007-05-30 15:06:51 UTC
Sigh, I missed one revision; I've bumped to -r6 and should be fine now; I probably forgot to restart pulseaudio when I testcased the patch (and I had 0.9.6 running).
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-30 17:25:28 UTC
Thx Diego and Ticho for checking.

Please test and mark stable. Target keywords are:

pulseaudio-0.9.5-r6.ebuild:KEYWORDS="alpha amd64 arm hppa ia64 ppc ppc64 sh sparc x86 ~x86-fbsd"
Comment 8 Gustavo Zacarias (RETIRED) gentoo-dev 2007-05-30 18:40:13 UTC
sparc stable.
Comment 9 René Nussbaumer (RETIRED) gentoo-dev 2007-05-30 20:52:34 UTC
stable on hppa
Comment 10 Andrej Kacian (RETIRED) gentoo-dev 2007-05-30 21:25:52 UTC
Gah, back from work at last. -r6 looks good, marked stable on x86.
Comment 11 Peter Weller (RETIRED) gentoo-dev 2007-06-01 08:14:33 UTC
amd64 done
Comment 12 Markus Rothe (RETIRED) gentoo-dev 2007-06-02 08:07:24 UTC
ppc64 stable
Comment 13 René Nussbaumer (RETIRED) gentoo-dev 2007-06-02 18:57:47 UTC
forgot to take a note about the ppc stablize. Done that now.
Comment 14 Raúl Porcel (RETIRED) gentoo-dev 2007-06-02 21:08:43 UTC
alpha/ia64 stable
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-03 06:32:58 UTC
This one is ready for GLSA vote. I vote NO.
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2007-06-03 09:25:37 UTC
voting NO.