First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 50217
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
koon: ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 50217 depends on: Show dependency tree
Bug 50217 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-05-06 06:18 0000
two bugs in exim 3.35, one of them present in exim 4.32

http://www.guninski.com/exim1.html

------- Comment #1 From Thierry Carrez (RETIRED) 2004-05-07 12:07:52 0000 -------
Confirmed :

CAN-2004-0400 :
    When headers_check_syntax is configured in exim.conf a buffer
    overflow can happen during the header check.

CAN-2004-0399 only applies to exim3, which disappeared from the tree since Nov 2002.

Apparently version 4.33 does not include the fix, Debian seems to have applied a patch to it to fix, see :

http://packages.qa.debian.org/e/exim4.html
http://www.debian.org/security/2004/dsa-501

------- Comment #2 From Rajiv Aaron Manglani 2004-05-09 00:32:45 0000 -------
*** Bug 50492 has been marked as a duplicate of this bug. ***

------- Comment #3 From Kurt Lieber 2004-05-09 04:59:50 0000 -------
adding peitolm to the bug sine he's not on the net-mail alias, but is the
maintainer of exim.

------- Comment #4 From Thierry Carrez (RETIRED) 2004-05-09 11:06:36 0000 -------
OK I cleared this up :
4.33 is not sufficient to fix, we need 4.33 + Philip Hazel patch at :
http://www.exim.org/pipermail/exim-users/Week-of-Mon-20040503/071126.html

------- Comment #5 From Colin Morey 2004-05-09 11:36:02 0000 -------
I've added this patch to the exim 4.33-r1 ebuild that's been in portage for 3
hours or so (forgot to update this bug to say). I personally don't use
headers_check_syntax, so I've not immediatly bumped it to stable, but it does
appear to work, and If I can get independant confirmation from someone that
uses headers_check_syntax, then I'll bump, if not I'll bump it tomorrow.

------- Comment #6 From solar 2004-05-09 13:53:01 0000 -------
Arch maintainers please read this bug then test/(stable?) if you can.

------- Comment #7 From solar 2004-05-09 19:14:47 0000 -------
Arch maintainer ignore the previous test request. Peti says he can test for all
arches.

------- Comment #8 From Colin Morey 2004-05-10 01:20:23 0000 -------
Some confusion here, I can test and will mark a stable for both x86 and sparc,
however I've never tested exim on any other arch, even though they've got
previous stable flags,
could hppa, ppc, amd64 and alpha please test.

Arch           Last Stable Revision
x86            exim-4.32-r1
sparc          exim-4.32-r1
ppc            exim-4.24-r3
hppa           exim-4.21
amd64          exim-4.21
alpha          None in Portage


Arch-maintainers, I'll leave it up to you to let me know if exim-4.33-r1 is
stable for you, (minimum of being able to compile, start and send an email
through it). I'm happy to do the testing myself, I just don't have access to
these archs yet.

------- Comment #9 From Thierry Carrez (RETIRED) 2004-05-10 02:34:20 0000 -------
Adding in the relevant arch-maintainers

------- Comment #10 From Colin Morey 2004-05-10 09:13:13 0000 -------
Philip Hazel (Exim author), has release 4.34, which includes a fix for this, so
If you haven't tested 4.31-r1, or indeed if you have and haven't told me, can
you test 4.34 please, I'll add this to portage within the next few hours. (I'll
update this bug when it's in). 

------- Comment #11 From Colin Morey 2004-05-10 11:17:18 0000 -------
exim 4.34 now in cvs, would the relevant archs please test.

------- Comment #12 From Thierry Carrez (RETIRED) 2004-05-11 06:21:55 0000 -------
GLSA drafted, waiting for stable on 4.33-r1 and/or 4.34

------- Comment #13 From Jon Portnoy (RETIRED) 2004-05-11 10:14:32 0000 -------
Fixed on amd64

------- Comment #14 From Guy Martin 2004-05-11 15:59:38 0000 -------
Marked 4.34 stable on hppa.

------- Comment #15 From Thierry Carrez (RETIRED) 2004-05-12 02:17:33 0000 -------
Obviously I forgot a few arches,

Target keywords are : x86 ppc sparc ~alpha hppa amd64
We currently have : ~x86 ~sparc alpha hppa amd64

x86, sparc, ppc : please test and mark net-mail/exim-4.34 stable

------- Comment #16 From Colin Morey 2004-05-12 06:05:00 0000 -------
Koon, please read back through my previous comments, specifically " I can test
and will mark a stable for both x86 and sparc". so I'm removing those archs
again, and we're just waiting for ppc to respond.

------- Comment #17 From Colin Morey 2004-05-13 03:09:01 0000 -------
Well, I've marked Exim 4.34 stable on x86 and sparc, so we're just waiting for
ppc to confirm then we can go ahead and start to mask the old versions

------- Comment #18 From Kurt Lieber 2004-05-13 10:07:42 0000 -------
ppc folks -- can you please test/mark stable? 

------- Comment #19 From Luca Barbato 2004-05-13 15:14:41 0000 -------
marked ppc sorry for the delay

------- Comment #20 From Thierry Carrez (RETIRED) 2004-05-14 00:55:49 0000 -------
GLSA drafted

------- Comment #21 From Thierry Carrez (RETIRED) 2004-05-14 13:23:30 0000 -------
GLSA 200405-07

First Last Prev Next    No search results available      Search page      Enter new bug