Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 188638 - mail-filter/assp < 1.3.3.1-r4 Unspecified Vulnerability
Summary: mail-filter/assp < 1.3.3.1-r4 Unspecified Vulnerability
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26316/
Whiteboard: B3? []
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-12 20:28 UTC by Matt Fleming (RETIRED)
Modified: 2007-09-13 06:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Fleming (RETIRED) gentoo-dev 2007-08-12 20:28:12 UTC
A vulnerability with an unknown impact has been reported in ASSP.

The vulnerability is caused due to an unspecified error within assp.pl. No further details are available.

The vulnerability is reported in version 1.3.3.
Comment 1 Matt Fleming (RETIRED) gentoo-dev 2007-08-12 20:37:03 UTC
CC'ing maintainer and setting whiteboard status.
Comment 2 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:53:15 UTC
I will see about getting 1.3.3.1 into tree ASAP
Comment 3 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-17 21:56:18 UTC
1.3.3.1 is in tree. Could use some testing, and once others sign off, we can look to rush stabilize to address vulnerability. Sorry for delay in bump, have to make a large patch which has to be mirrored due to size :(
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-19 18:58:04 UTC
Thx William. What do you mean by "and once others sign off"? Is it ready for stable marking or not?
Comment 5 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-19 19:10:10 UTC
(In reply to comment #4)
> Thx William. What do you mean by "and once others sign off"?

I would like others to test and confirm if it's stable or it's condition. Just today I ran into an issue, and bumped it to -r2. Not sure how I did not run into that locally, and it did start for me, or so I imagined :)

> Is it ready for stable marking or not?

I would say not, but I am putting it on some low volume/importance mail servers for testing. Trying to confirm it's stability or not ASAP. But since this is pretty much all me this time with creating the patches, and modifying paths etc. I would like others feedback that use ASSP. How to get their attention?


Comment 6 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-19 19:11:08 UTC
Sorry accidentally clicked radio button and changed status
Comment 7 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-25 14:17:00 UTC
I completely screwed up 1.3.1, I will take another stab at it tomorrow.
Comment 8 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-09-05 19:03:55 UTC
Ok finally got it right this time I believe. I have it running on two production mail severs and so far so good. So 1.3.3.1-r3 should be good to go. Not sure how long it will take for patches to be mirrored or etc, but they have been uploaded to d.g.o. Otherwise, I guess we can go ahead and look to stabilize now.

I would still like a few others to test and comment. But in their absence unless I run into any issues in the next day or so. We can proceed with stabilization.
Comment 9 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-09-06 15:48:00 UTC
Ok I got some pier review and had a few things off path wise in my patch. Mostly effected admin web gui, but still. The new 1.3.3.1-r4 that I just committed should be good to go.

Sorry about all this. Would be much easier if upstream supported absolute paths vs relative, so we could split things up easier for FHS. Unfortunately upstream seems to be developing ASSP on windows. So their are likely stuck with a single dir due to that platform. :( Not receptive to absolute path or split layout requests :(
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-06 15:57:30 UTC
Thanks william. 
Arches, please test and mark stable mail-filter/assp-1.3.3.1-r4:
target keywords are "amd64 x86"
Comment 11 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-09 12:11:35 UTC
Based on Secunia's advisory I propose B3.
Comment 12 Markus Meier gentoo-dev 2007-09-09 13:02:58 UTC
!!! Couldn't download 'assp-1.3.3.1-r4.patch.tbz2'. Aborting.
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-09-09 19:06:12 UTC
Back to ebuild to get the patches mirrored.
Comment 14 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-09-12 22:38:09 UTC
Odd others got patches without a problem. I re-uploaded the patch to d.g.o so it would be picked up and mirrored. Hopefully that did the trick.

Also it seems we can close this bug. I got confirmation from upstream the security issue was specific to 1.3.3 which was never in tree. Much less we would not have been effected since we run assp as assp:assp with perms on /etc/assp so only it has access to it.

http://sourceforge.net/mailarchive/message.php?msg_name=1189636482.18987.34.camel%40wlt.obsidian-studios.com

Requesting this bug be closed as invalid. I think I can do that, but don't want to deviate from security's procedures or etc. So will leave to another to mark as invalid and close :)
Comment 15 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-13 06:43:49 UTC
well okay, if we're not affected, no need to keep it open. closing as invalid.