Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 133800
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 133800 depends on: Show dependency tree
Bug 133800 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-19 11:36 0000
POPFile before 0.22.4 allows remote attackers to cause a denial of service
(application crash) via unspecified vectors involving character sets within
e-mail messages.

------- Comment #1 From Raphael Marichez 2006-05-19 11:38:30 0000 -------
Debian has chosen to patch (DSA 1061-1)
Otherwise, 0.22.4 is out
http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4

------- Comment #2 From Raphael Marichez 2006-05-27 02:11:14 0000 -------
CCing mcummings in order to progress on this vuln.

(and adding CVE id)

------- Comment #3 From Stuart Herbert (RETIRED) 2006-05-31 00:13:01 0000 -------
POPfile 0.22.4 has been committed to the tree.  It will need stabilising on
x86.

Best regards,
Stu

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-05-31 00:38:24 0000 -------
Thx SuperStu. x86 please test and mark stable.

------- Comment #5 From Joshua Jackson 2006-06-01 20:55:55 0000 -------
popfile installs, however its failing while trying to locate the Loader.. The
following is the error:

Can't Locate POPFile/Loader.pm at @INC (include is all the following locations,
perl knows them).

Begin failed--compilation aborted at /usr/share/popfile/popfile.pl line75.

please advise.

------- Comment #6 From Mark Loeser 2006-06-01 21:12:24 0000 -------
Current stable fails the same way, and also doesn't work out of the box due to
a bad chmod.  The location of this file also sucks since it isn't in the user's
path.  I'm wondering if we should just put this back to ~x86 until it is more
developed and easier to use.

------- Comment #7 From Sune Kloppenborg Jeppesen 2006-06-02 06:06:06 0000 -------
Seems like a candidate for ~ rather than stable to me.

Stuart please advise.

------- Comment #8 From Mark Loeser 2006-06-03 19:53:26 0000 -------
I removed "x86" from the only stable version we had, so now the only versions
we have keyworded are ~x86.  I put that version to -* so that the maintainers
can decide when to drop it.

So...we are done :)

------- Comment #9 From Stuart Herbert (RETIRED) 2006-06-04 03:03:20 0000 -------
Hi,

The popfile-0.22.4 install is working fine locally.  To run it,

  cd /usr/share/popfile && ./popfile.pl

I'd like to see this version stable on x86, to provide an upgrade for everyone
running the older version.

Best regards,
Stu

------- Comment #10 From Sune Kloppenborg Jeppesen 2006-06-04 04:10:43 0000 -------
SupterStu, does that mean that pkg_postinst is out of date or does running it
like /usr/share/popfile/popfile.pl also work?

Security, since this is a B3 we at least need a vote on (mask) GLSA.

------- Comment #11 From Mark Loeser 2006-06-04 13:10:55 0000 -------
I just talked to Stuart and we worked out a way to get this to work so everyone
is happy.  He said he'll have time tomorrow to add the fix, and he'll mark it
stable for us at the same time.  He's just going to add a little wrapper script
into /usr/bin/ so that it will do the cd and everything for the user, so it'll
"Just Work" (TM) :)  There are still some problems with it, but this will
atleast make it a little better, imho.

------- Comment #12 From Raphael Marichez 2006-06-08 03:42:14 0000 -------
(In reply to comment #11)
> I just talked to Stuart and we worked out a way to get this to work so everyone
> is happy.  He said he'll have time tomorrow to add the fix, and he'll mark it
> stable for us at the same time.  

stuart, any news on this ?

------- Comment #13 From Stuart Herbert (RETIRED) 2006-06-10 16:23:33 0000 -------
Sorry for the delay; I've been a bit unwell this week.

popfile-0.22.4 is now in the tree and (with Mark's permission) has been marked
stable on x86.

Best regards,
Stu

------- Comment #14 From Raphael Marichez 2006-06-10 23:33:47 0000 -------
- removing x86 from CC
- calling a vote for GLSA

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-06-10 23:51:53 0000 -------
I tend to vote NO.

------- Comment #16 From Stefan Cornelius (RETIRED) 2006-06-11 02:04:29 0000 -------
yet another no

------- Comment #17 From Stuart Herbert (RETIRED) 2006-06-11 02:20:14 0000 -------
Why no GLSA?  The affected version of the package was stable ...

Best regards,
Stu

------- Comment #18 From Stefan Cornelius (RETIRED) 2006-06-11 02:27:45 0000 -------
Not all vulnerable stable packages automatically force a GLSA. The
vulnerability treatment policy
(http://www.gentoo.org/security/en/vulnerability-policy.xml) says that there
should be a vote for certain ratings (one of them is B3, like this one).
If you want a GLSA, you may comment this here and we might take you opinion
into account (but don't have to).

------- Comment #19 From Wolf Giesen (RETIRED) 2006-06-11 23:39:55 0000 -------
One more "no".

------- Comment #20 From Raphael Marichez 2006-06-12 02:22:14 0000 -------
Closing without GLSA, feel free to reopen if you disagree.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug