Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 188638
Alias:
Product:
Component:
Status: RESOLVED
Resolution: INVALID
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matt Fleming (RETIRED) <mjf@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 188638 depends on: Show dependency tree
Bug 188638 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-12 20:28 0000
A vulnerability with an unknown impact has been reported in ASSP.

The vulnerability is caused due to an unspecified error within assp.pl. No
further details are available.

The vulnerability is reported in version 1.3.3.

------- Comment #1 From Matt Fleming (RETIRED) 2007-08-12 20:37:03 0000 -------
CC'ing maintainer and setting whiteboard status.

------- Comment #2 From William L. Thomson Jr. (RETIRED) 2007-08-14 17:53:15 0000 -------
I will see about getting 1.3.3.1 into tree ASAP

------- Comment #3 From William L. Thomson Jr. (RETIRED) 2007-08-17 21:56:18 0000 -------
1.3.3.1 is in tree. Could use some testing, and once others sign off, we can
look to rush stabilize to address vulnerability. Sorry for delay in bump, have
to make a large patch which has to be mirrored due to size :(

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-08-19 18:58:04 0000 -------
Thx William. What do you mean by "and once others sign off"? Is it ready for
stable marking or not?

------- Comment #5 From William L. Thomson Jr. (RETIRED) 2007-08-19 19:10:10 0000 -------
(In reply to comment #4)
> Thx William. What do you mean by "and once others sign off"?

I would like others to test and confirm if it's stable or it's condition. Just
today I ran into an issue, and bumped it to -r2. Not sure how I did not run
into that locally, and it did start for me, or so I imagined :)

> Is it ready for stable marking or not?

I would say not, but I am putting it on some low volume/importance mail servers
for testing. Trying to confirm it's stability or not ASAP. But since this is
pretty much all me this time with creating the patches, and modifying paths
etc. I would like others feedback that use ASSP. How to get their attention?

------- Comment #6 From William L. Thomson Jr. (RETIRED) 2007-08-19 19:11:08 0000 -------
Sorry accidentally clicked radio button and changed status

------- Comment #7 From William L. Thomson Jr. (RETIRED) 2007-08-25 14:17:00 0000 -------
I completely screwed up 1.3.1, I will take another stab at it tomorrow.

------- Comment #8 From William L. Thomson Jr. (RETIRED) 2007-09-05 19:03:55 0000 -------
Ok finally got it right this time I believe. I have it running on two
production mail severs and so far so good. So 1.3.3.1-r3 should be good to go.
Not sure how long it will take for patches to be mirrored or etc, but they have
been uploaded to d.g.o. Otherwise, I guess we can go ahead and look to
stabilize now.

I would still like a few others to test and comment. But in their absence
unless I run into any issues in the next day or so. We can proceed with
stabilization.

------- Comment #9 From William L. Thomson Jr. (RETIRED) 2007-09-06 15:48:00 0000 -------
Ok I got some pier review and had a few things off path wise in my patch.
Mostly effected admin web gui, but still. The new 1.3.3.1-r4 that I just
committed should be good to go.

Sorry about all this. Would be much easier if upstream supported absolute paths
vs relative, so we could split things up easier for FHS. Unfortunately upstream
seems to be developing ASSP on windows. So their are likely stuck with a single
dir due to that platform. :( Not receptive to absolute path or split layout
requests :(

------- Comment #10 From Pierre-Yves Rofes 2007-09-06 15:57:30 0000 -------
Thanks william. 
Arches, please test and mark stable mail-filter/assp-1.3.3.1-r4:
target keywords are "amd64 x86"

------- Comment #11 From Christian Faulhammer 2007-09-09 12:11:35 0000 -------
Based on Secunia's advisory I propose B3.

------- Comment #12 From Markus Meier 2007-09-09 13:02:58 0000 -------
!!! Couldn't download 'assp-1.3.3.1-r4.patch.tbz2'. Aborting.

------- Comment #13 From Sune Kloppenborg Jeppesen 2007-09-09 19:06:12 0000 -------
Back to ebuild to get the patches mirrored.

------- Comment #14 From William L. Thomson Jr. (RETIRED) 2007-09-12 22:38:09 0000 -------
Odd others got patches without a problem. I re-uploaded the patch to d.g.o so
it would be picked up and mirrored. Hopefully that did the trick.

Also it seems we can close this bug. I got confirmation from upstream the
security issue was specific to 1.3.3 which was never in tree. Much less we
would not have been effected since we run assp as assp:assp with perms on
/etc/assp so only it has access to it.

http://sourceforge.net/mailarchive/message.php?msg_name=1189636482.18987.34.camel%40wlt.obsidian-studios.com

Requesting this bug be closed as invalid. I think I can do that, but don't want
to deviate from security's procedures or etc. So will leave to another to mark
as invalid and close :)

------- Comment #15 From Pierre-Yves Rofes 2007-09-13 06:43:49 0000 -------
well okay, if we're not affected, no need to keep it open. closing as invalid.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug