<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>109381</bug_id>
          
          <creation_ts>2005-10-15 10:06 0000</creation_ts>
          <short_desc>mail-mta/xmail: security update + init script forgets to copy resolve libs</short_desc>
          <delta_ts>2005-12-14 09:52:40 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>quinox_san_@hotmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>quinox_san_@hotmail.com</who>
            <bug_when>2005-10-15 10:06:01 0000</bug_when>
            <thetext>After upgrading packages on my system the XMail server didn&apos;t download pop3link
mail any more - in debug mode it would print messages like this:

&lt;&lt;
ErrCode   = -40
ErrString = Invalid server address
ErrInfo   = ***.homelinux.net
[PSYNC/MASQ] MasqDomain = &quot;qtea.nl,qtea.nl&quot; - RmtDomain = &quot;***.homelinux.net&quot; -
RmtName = &quot;quinox&quot; Failed !
&gt;&gt;

After some testing I found out that wget had the same problem in the chrooted
directory, and after some googling I found
http://blog.gmane.org/gmane.comp.apache.mod-security.user/day=20040711 . Copying
those 3 files mentioned in that post:

libnss_dns.so.2
libnss_files.so.2
libresolv.so.2

to the /chroot/xmail/lib directory fixed my problem.

ATM the init script copies all libs mentioned in ldd XMail - The resolve libs
are not listed there. IMO these will have to be copied by the init.d script too
before starting XMail

PS: 

XMail 1.22 has been released a few days ago and isn&apos;t in portage yet - it has a
security update to fix a buffer overflow with the local sendmail prog
(CAN-2005-2943):

http://www.xmailserver.org/ChangeLog.html#oct_12__2005_v_1_22
http://www.idefense.com/application/poi/display?id=321&amp;type=vulnerabilities


Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>quinox_san_@hotmail.com</who>
            <bug_when>2005-12-10 03:36:30 0000</bug_when>
            <thetext>Noone ? It is kind of bad if we leave an exploitable version of a mail server in
portage for this long :/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lcars@gentoo.org</who>
            <bug_when>2005-12-10 04:00:43 0000</bug_when>
            <thetext>1.22 is masked in the tree (wait a few minutes for mirrors to pick it up), could
you please test it and see if it works for you so that I can remove the vuln
package and have the sec team issuing a GLSA?

(Moving to Security)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>quinox_san_@hotmail.com</who>
            <bug_when>2005-12-10 05:10:39 0000</bug_when>
            <thetext>It compiles without any problems and it runs fine :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-12-11 10:01:06 0000</bug_when>
            <thetext>x86 or maintainer can go ahead and mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-12-12 07:23:57 0000</bug_when>
            <thetext>CVE-2005-2943
Local exploitation of a buffer overflow vulnerability in XMail, as
distributed with multiple vendors&apos; operating systems, allows local
attackers to execute arbitrary code with elevated privileges.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-12-14 09:52:40 0000</bug_when>
            <thetext>GLSA 200512-05</thetext>
          </long_desc>
      
    </bug>

</bugzilla>