First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 47918
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Dominik Schäfer <schaedpq2@gmx.de>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 47918 depends on: 48435 Show dependency tree
Bug 47918 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-04-15 05:40 0000
Two vulnerabilities in ssmtp were discovered, which allow compromising a
vulnerable system, resulting in server crash or execution of arbitrary code.
Rated by Secunia in their advisory as "highly critical", "system access from
remote".


Reproducible: Didn't try
Steps to Reproduce:
1.
2.
3.




The advisory Secunia issued today can be found here:
http://secunia.com/advisories/11378/

CVE reference: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0156

The vulnerabilities are caused by 2 format string errors in the functions die()
and log_event().

Secunia says, one should use a different product until the bugs have been
fixed,
there seem to exist no workaround or patched version until now.

------- Comment #1 From Dominik Schäfer 2004-04-15 07:32:26 0000 -------
I just received the Debian advisory about this issue:
http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00084.html
http://www.debian.org/security/2004/dsa-485

They seem to have fixed the problems in 2.50.6.1 (stable, woody), http://security.debian.org/pool/updates/main/s/ssmtp/ssmtp_2.50.6.1.tar.gz
The changelog says:

ssmtp (2.50.6.1) stable-security; urgency=high

  * Non-maintainer upload by the Security Team
  * Fix two format string vulnerabilities (die() and log_event())
    discovered by Max Vozeler <max@hinterhof.net> (CAN-2004-0156)

 -- Matt Zimmerman <mdz@debian.org>  Mon, 12 Apr 2004 09:21:54 -0700

The advisory states the update for 2.60.6 (debian unstable, sid) will come soon (I expect 2.60.6.1). The newest in portage is 2.60.4, the current stable on 2.48

------- Comment #2 From Thierry Carrez (RETIRED) 2004-04-15 07:58:18 0000 -------
Waiting for upstream 2.60.6.1.
Please note that exploit need that you forward mail to an untrusted server.

------- Comment #3 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-15 11:45:19 0000 -------
I can take this one if nobody else wants it.

------- Comment #4 From Thierry Carrez (RETIRED) 2004-04-19 02:06:50 0000 -------
2.60.7 is available upstream :
http://packages.qa.debian.org/s/ssmtp.html

net-mail people, can we have a bump to this one ?

CondorDes: this one is all yours :)

Thanks in advance,
-K

------- Comment #5 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-19 11:47:21 0000 -------
There was an email on Bugtraq today about an insecure file creation:
http://www.securityfocus.com/archive/1/360626/2004-04-16/2004-04-22/0

Having reviewed the source, it looks like 2.60.7 is vulnerable to this.  Should
we wait to bump?

------- Comment #6 From solar 2004-04-22 14:38:27 0000 -------
This is a fairly serious flaw.

security@g.o should not have to wait any longer.. If patches are ready
and net-mail@g.o is taking to long (>=48 hrs) and a CAN-XXXX-XXX exists
then we should add the patches in without having to wait on them.

------- Comment #7 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-22 15:31:49 0000 -------
This really should be a P1/blocker, not a P2/major, since it has the potential
of being a remote-root.

net-mail -- Please wake up.  I don't want to step on your turf, but if I don't
hear from you on this in 6 hours or so, we're going to start looking into
pushing this one ourselves.

solar -- I think we're also waiting on a fix for bug 48435.  However, someone
should check to see if that actually affects us.

------- Comment #8 From solar 2004-04-22 23:52:46 0000 -------
Bug 48435 does not affects us or seemly anybody for that matter.  That
support is just flat out broke. I'll still put a patch together however
to fix it, probably default the LOGFILE to /dev/stdout unless one is
passed in the form of CFLAGS="-DLOGFILE_FILENAME=blah" when I bump this
pkg.

------- Comment #9 From solar 2004-04-23 00:08:49 0000 -------
In portage as ssmtp-2.60.7.ebuild please test.
KEYWORDS="~x86 ~ppc ~sparc ~alpha ~hppa ~mips ~amd64 ~ia64 ~ppc64 ~s390"

------- Comment #10 From Bryan Østergaard (RETIRED) 2004-04-23 05:57:39 0000 -------
Stable on alpha.

------- Comment #11 From Luca Barbato 2004-04-23 20:06:58 0000 -------
Stable on ppc

------- Comment #12 From Jason Wever (RETIRED) 2004-04-24 07:13:09 0000 -------
Stable on sparc.

------- Comment #13 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-24 12:18:24 0000 -------
Draft GLSA submitted with temporary id c31342a3b17660a2a671ba94782fe1fe.

security@ -- reviews please?  Thanks.

------- Comment #14 From Joshua Kinard 2004-04-25 01:53:43 0000 -------
Marked stable on mips.

------- Comment #15 From solar 2004-04-25 14:00:12 0000 -------
Current keywords..
KEYWORDS="~x86 ppc sparc alpha ~hppa mips amd64 ~ia64 ~ppc64 ~s390"

Removing arch-maintainers and adding specific arches.

Remaining arch maintainers please test and mark stable so 
we can get this one out the door. -thanks

------- Comment #16 From Brandon Hale (RETIRED) 2004-04-25 15:14:41 0000 -------
Stable on x86.

------- Comment #17 From Michael McCabe (RETIRED) 2004-04-25 18:03:40 0000 -------
Marked stable on s390

------- Comment #18 From Aron Griffis (RETIRED) 2004-04-25 18:23:58 0000 -------
stable on alpha and ia64

------- Comment #19 From Tom Gall 2004-04-25 19:20:27 0000 -------
stable on ppc64

------- Comment #20 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-26 13:03:45 0000 -------
This is ready for a GLSA.  We have one drafted ... klieber and Koon reviewed
it, but it got changed after klieber reviewed it, so one more person needs to
look at it.

------- Comment #21 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-26 15:56:02 0000 -------
GLSA 200404-18.

------- Comment #22 From Guy Martin 2004-04-27 03:10:43 0000 -------
Stable on hppa thanks vapier.

First Last Prev Next    No search results available      Search page      Enter new bug