Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 134792
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: orgoz2@gmail.com
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 134792 depends on: 135035 Show dependency tree
Bug 134792 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-29 08:59 0000
This new 2.1.2 version is a BUGFIX version, STABLE version, based on 2.1.1 and
NOT on current development code.

------- Comment #1 From Jakub Moc (RETIRED) 2006-05-29 09:06:32 0000 -------
http://www.amule.org/
<snip>
aMule 2.1.2 released!
Posted by: Kry, 28.05.06 at 17:24
</snip>

# date
Mon May 29 18:04:43 CEST 2006

So yeah, pardon us that we didn't manage to release this in 30 minutes. Damnit,
we are such slackers!

http://allen.brooker.gb.net/misc/kitten-0day.jpg

------- Comment #2 From Raphael Marichez 2006-05-29 14:55:27 0000 -------
Hi all,

congrats for the very fast bump :)

i recommend you assign now this bug to the security team (product Gentoo
Security / component vulns) because of an information disclosure vulnerability
which could allow an attacker to read HTML, PHP or image files on the server,
on versions <2.1.2 . This will call a vote on a GLSA issuing or not. Thanks in
advance.

------- Comment #3 From Stefan Cornelius (RETIRED) 2006-05-30 02:55:10 0000 -------
jup, shamelessly stealing the bug now.

Arches, please test and stable version 2.1.2, thanks.

------- Comment #4 From Stefan Cornelius (RETIRED) 2006-05-30 02:56:08 0000 -------
accepting/setting severity

------- Comment #5 From Markus Rothe 2006-05-30 04:44:41 0000 -------
hrm.. I just did an cvs up in *cvs*/net-p2p/amule/ and I don't see version
2.1.2 in there.

Same for emerge --sync and then looking for this version.

you might forgot to commit?

------- Comment #6 From Stefan Cornelius (RETIRED) 2006-05-30 04:50:34 0000 -------
Sorry, seems like I was a bit too trigger happy. waiting for net-p2p to provide
fixed packages

------- Comment #7 From Stefan Cornelius (RETIRED) 2006-06-08 06:59:39 0000 -------
arches, please test and stable 2.1.2, thanks

------- Comment #8 From Markus Rothe 2006-06-08 08:01:33 0000 -------
stable on ppc64

------- Comment #9 From Luis Medinas (RETIRED) 2006-06-08 11:11:32 0000 -------
ding ding amd64 stableeeeee ding ding

------- Comment #10 From Tobias Scherbaum 2006-06-08 14:58:02 0000 -------
ppc stable

------- Comment #11 From Raphael Marichez 2006-06-08 16:48:38 0000 -------
CVE-2006-2691 & CVE-2006-2692

------- Comment #12 From Joshua Jackson 2006-06-08 21:33:39 0000 -------
the mule heha'd at me so I marked it stable on x86.

------- Comment #13 From Joshua Jackson 2006-06-08 21:35:25 0000 -------
and lagging bugs didn't remove x86 from the bug.

------- Comment #14 From Thomas Cort (RETIRED) 2006-06-10 07:59:28 0000 -------
no go for alpha. I get the following when attempting to run amule...

//////////////////////////////////////////////
Initialising aMule
Checking if there is an instance already running...
No other instances are running.
        aMule Version: aMule 2.1.2 using wxGTK2 v2.6.2

Terminated after throwing an instance of 'std::bad_alloc'
        what(): St9bad_alloc
        backtrace:
[2] ?? in amule [0x12006dfc8]
[3] wxEntry(int&, char**) in /usr/lib/libwx_base-2.6.so.0[0x2000089f2c0]
[4] ?? in amule [0x120153b90]
[5] __libc_start_main in /lib/libc.so.6.1[0x20000b77a30]
[6] ?? in amule [0x120058a58]

Aborted
//////////////////////////////////////////////

I get the same results with wxGTK 2.6.2-r1 and 2.6.3.2. I masked amule in
profiles/default-linux/alpha/package.mask and dropped the ~alpha keyword from
2.1.2. If you need anything else, please re-add us.

------- Comment #15 From Jon Hood (RETIRED) 2006-06-12 08:25:55 0000 -------
tcort, please test amule-2.1.3 and let me know if it seems to work for alpha.

------- Comment #16 From Thomas Cort (RETIRED) 2006-06-15 09:30:58 0000 -------
(In reply to comment #15)
> tcort, please test amule-2.1.3 and let me know if it seems to work for alpha.

amule-2.1.3 still crashes.

$ amule
Initialising aMule
Checking if there is an instance already running...
No other instances are running.

--------------------------------------------------------------------------------
A fatal error has occurred and aMule has crashed.
Please assist us in fixing this problem by posting the backtrace below in our
'aMule Crashes' forum and include as much information as possible regarding the
circumstances of this crash. The forum is located here:
    http://forum.amule.org/board.php?boardid=67
If possible, please try to generate a real backtrace of this crash:
    http://www.amule.org/wiki/index.php/Backtraces

----------------------------=| BACKTRACE FOLLOWS:
|=----------------------------
Current version is: aMule 2.1.3 using wxGTK2 v2.6.3 (Unicoded)
Running on: Linux 2.6.16.5 alpha

[2] ?? in amule [0x120061850]
[3] wxFatalSignalHandler in /usr/lib/libwx_baseu-2.6.so.0[0x200008c6528]
[4] ?? in /lib/libpthread.so.0 [0x20000056300]
[5] __pthread_mutex_lock in /lib/libpthread.so.0[0x2000004f2e4]
[6] wxMutexInternal::Lock() in /usr/lib/libwx_baseu-2.6.so.0[0x200008b7a58]


--------------------------------------------------------------------------------
Aborted

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-06-15 10:52:36 0000 -------
net-p2p please advise.

------- Comment #18 From Jon Hood (RETIRED) 2006-06-15 22:29:02 0000 -------
This seems to be isolated on alpha; I cannot reproduce it. Is there any way we
can drop alpha support until an amule dev can take a look at this? Your advice
in this situation is better than any I could give.

------- Comment #19 From stefanero 2006-06-16 00:39:58 0000 -------
Hey

tcort can you enable debug on the ebuild and run aMule in gdb to produce a real
backtrace?
also a good idear might be to move your old .aMule dir out of the way and start
for this test with a clean one.

stefanero

------- Comment #20 From Thomas Cort (RETIRED) 2006-06-16 05:47:05 0000 -------
(In reply to comment #18)
> This seems to be isolated on alpha; I cannot reproduce it. Is there any way we
> can drop alpha support until an amule dev can take a look at this? Your advice
> in this situation is better than any I could give.

Alpha support has already been dropped, see comment #14, "I masked amule in
profiles/default-linux/alpha/package.mask and dropped the ~alpha keyword from
2.1.2."

(In reply to comment #19)
> tcort can you enable debug on the ebuild and run aMule in gdb to produce a 
> real backtrace?

stefanero, sure. I'll do that and post the results to the "aMule crashes"
forums mentioned in the error message.

------- Comment #21 From Sune Kloppenborg Jeppesen 2006-06-30 08:57:23 0000 -------
Did this ever get fixed for alpha?

------- Comment #22 From Thomas Cort (RETIRED) 2006-06-30 09:15:10 0000 -------
(In reply to comment #21)
> Did this ever get fixed for alpha?

No, see comment #14 and comment #16.

I filed an upstream crash report[1]. I guess I forgot to set e-mail
notification on the aMule forums because I just noticed the reply. I'll post
more debugging information to the crash report when I have some time to spare
(I've been busy testing and stabilizing stuff for 2006.1). I'm hoping it will
get fix. In the meantime, amule is masked on alpha (as I stated in Comment #14)
because the amule versions in portage either crash at startup or are
vulnerable.

[1] http://forum.amule.org/thread.php?threadid=10352

------- Comment #23 From Thierry Carrez (RETIRED) 2006-07-29 05:51:36 0000 -------
I think this is ready for GLSA vote, I tend to vote no.

------- Comment #24 From Matthias Geerdsen 2006-07-29 09:44:19 0000 -------
0.5 for no glsa

------- Comment #25 From Wolf Giesen (RETIRED) 2006-07-30 00:01:56 0000 -------
I can't really decide (with the info being quite vague, too). On one hand it's
cheesy, and of course amuleweb is nothing to be trusted in the first place
(read: don't make it world-accessible). But then again, I would not want my
phpBB config.php or DokuWiki user.auth.php shared with the world...

.5 for "yes" :]

------- Comment #26 From Sune Kloppenborg Jeppesen 2006-07-30 12:19:38 0000 -------
Voting a NO and closing. Feel free to reopen if you disagree.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug