Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 107679 - net-mail/up-imapproxy Format String Vulnerability
Summary: net-mail/up-imapproxy Format String Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.imapproxy.org/
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-29 23:34 UTC by Janne Pikkarainen
Modified: 2006-03-06 13:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
up-imapproxy v1.2.4 (up-imapproxy-1.2.4.ebuild,1.17 KB, text/plain)
2005-10-13 02:53 UTC, Janne Pikkarainen
no flags Details
Fix for string format specifier bug (imapproxy-bug.patch,264 bytes, patch)
2005-11-19 11:03 UTC, Michael, A. Toth
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Janne Pikkarainen 2005-09-29 23:34:34 UTC
Latest version of IMAP Proxy has been out about one month. It's also been in
production use on our heavily loaded (lots of logins every second) servers
without problems. 

ebuild requires no modifications, simply rename the ebuild file to be
up-imapproxy-1.2.4.ebuild. Please upgrade. :)

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Janne Pikkarainen 2005-10-13 02:53:02 UTC
Created attachment 70539 [details]
up-imapproxy v1.2.4

An ebuild for up-imapproxy v1.2.4 (actually just renamed v1.2.3 ebuild). Since
there seems to be a significant lag in up-imapproxy ebuild maintenance, I'm
willing to take over it's maintenance. I need to keep myself and our servers
up-to-date with up-imapproxy, so I might as well keep it up-to-date in Portage.
Comment 2 Michael, A. Toth 2005-11-19 11:03:24 UTC
Created attachment 73191 [details, diff]
Fix for string format specifier bug

http://www.securiteam.com/unixfocus/6O0010AEKW.html
http://lists.andrew.cmu.edu/pipermail/imapproxy-info/2005-October/000481.html

Please add this fix to portage tree!
Comment 3 Janne Pikkarainen 2006-02-09 00:05:34 UTC
*bump*

Since this is a security-related bug and a trivially fixed one, this should be fixed ASAP.
Comment 4 Torsten Veller (RETIRED) gentoo-dev 2006-02-09 03:16:51 UTC
Thanks for the bug report.
1.2.4 with fix commited.

@security: haven't seen this bug before. Please, do what's needed.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2006-02-26 09:16:22 UTC
Cleaning up so that it doesn't fall in the cracks
x86 please test and mark 1.2.4 stable
Comment 6 Janne Pikkarainen 2006-02-26 10:02:06 UTC
Has been working for me since last September... :-)
Comment 7 Chris White (RETIRED) gentoo-dev 2006-02-26 14:25:39 UTC
This really isn't working for me.  I set up the config file, started the server, it said "OK", then just died.  I tried from console and it didn't do anything.  It provides no debug or log messages, so I can't tell exactly what the problem might be..
Comment 8 Tuan Van (RETIRED) gentoo-dev 2006-02-26 20:44:20 UTC
(In reply to comment #7)
> This really isn't working for me.  I set up the config file, started the
> server, it said "OK", then just died.  I tried from console and it didn't do
> anything.  It provides no debug or log messages, so I can't tell exactly what
> the problem might be..
> 

please post your /etc/imapproxy.conf .
Do you have an imap server listening on the port that you have set in server_port ?
Comment 9 Joshua Jackson (RETIRED) gentoo-dev 2006-03-05 00:22:45 UTC
funky configuration for what it actually want's as the server name..quite odd...I had the same issue as chris but tried something and it worked.

Stable on x86 (X_X) <---gets that for the funky config server name
Comment 10 Torsten Veller (RETIRED) gentoo-dev 2006-03-05 01:14:31 UTC
Removed old versions and reopened this bug.
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2006-03-05 01:43:36 UTC
Ready for GLSA
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2006-03-06 13:21:48 UTC
GLSA 200603-04