Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 133800 - mail-filter/popfile: DoS (CVE-2006-0876)
Summary: mail-filter/popfile: DoS (CVE-2006-0876)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-05-19 11:36 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2006-06-12 02:22 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-05-19 11:36:40 UTC
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-05-19 11:38:30 UTC
Debian has chosen to patch (DSA 1061-1)
Otherwise, 0.22.4 is out
http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4
Comment 2 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-05-27 02:11:14 UTC
CCing mcummings in order to progress on this vuln.

(and adding CVE id)
Comment 3 Stuart Herbert (RETIRED) gentoo-dev 2006-05-31 00:13:01 UTC
POPfile 0.22.4 has been committed to the tree.  It will need stabilising on x86.

Best regards,
Stu
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-05-31 00:38:24 UTC
Thx SuperStu. x86 please test and mark stable.
Comment 5 Joshua Jackson (RETIRED) gentoo-dev 2006-06-01 20:55:55 UTC
popfile installs, however its failing while trying to locate the Loader.. The following is the error:

Can't Locate POPFile/Loader.pm at @INC (include is all the following locations, perl knows them).

Begin failed--compilation aborted at /usr/share/popfile/popfile.pl line75.

please advise.
Comment 6 Mark Loeser (RETIRED) gentoo-dev 2006-06-01 21:12:24 UTC
Current stable fails the same way, and also doesn't work out of the box due to a bad chmod.  The location of this file also sucks since it isn't in the user's path.  I'm wondering if we should just put this back to ~x86 until it is more developed and easier to use.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-02 06:06:06 UTC
Seems like a candidate for ~ rather than stable to me.

Stuart please advise.
Comment 8 Mark Loeser (RETIRED) gentoo-dev 2006-06-03 19:53:26 UTC
I removed "x86" from the only stable version we had, so now the only versions we have keyworded are ~x86.  I put that version to -* so that the maintainers can decide when to drop it.

So...we are done :)
Comment 9 Stuart Herbert (RETIRED) gentoo-dev 2006-06-04 03:03:20 UTC
Hi,

The popfile-0.22.4 install is working fine locally.  To run it,

  cd /usr/share/popfile && ./popfile.pl

I'd like to see this version stable on x86, to provide an upgrade for everyone running the older version.

Best regards,
Stu
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-04 04:10:43 UTC
SupterStu, does that mean that pkg_postinst is out of date or does running it like /usr/share/popfile/popfile.pl also work?

Security, since this is a B3 we at least need a vote on (mask) GLSA.
Comment 11 Mark Loeser (RETIRED) gentoo-dev 2006-06-04 13:10:55 UTC
I just talked to Stuart and we worked out a way to get this to work so everyone is happy.  He said he'll have time tomorrow to add the fix, and he'll mark it stable for us at the same time.  He's just going to add a little wrapper script into /usr/bin/ so that it will do the cd and everything for the user, so it'll "Just Work" (TM) :)  There are still some problems with it, but this will atleast make it a little better, imho.
Comment 12 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-08 03:42:14 UTC
(In reply to comment #11)
> I just talked to Stuart and we worked out a way to get this to work so everyone
> is happy.  He said he'll have time tomorrow to add the fix, and he'll mark it
> stable for us at the same time.  

stuart, any news on this ?
Comment 13 Stuart Herbert (RETIRED) gentoo-dev 2006-06-10 16:23:33 UTC
Sorry for the delay; I've been a bit unwell this week.

popfile-0.22.4 is now in the tree and (with Mark's permission) has been marked stable on x86.

Best regards,
Stu
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-10 23:33:47 UTC
- removing x86 from CC
- calling a vote for GLSA
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-10 23:51:53 UTC
I tend to vote NO.
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-11 02:04:29 UTC
yet another no
Comment 17 Stuart Herbert (RETIRED) gentoo-dev 2006-06-11 02:20:14 UTC
Why no GLSA?  The affected version of the package was stable ...

Best regards,
Stu
Comment 18 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-11 02:27:45 UTC
Not all vulnerable stable packages automatically force a GLSA. The vulnerability treatment policy (http://www.gentoo.org/security/en/vulnerability-policy.xml) says that there should be a vote for certain ratings (one of them is B3, like this one).
If you want a GLSA, you may comment this here and we might take you opinion into account (but don't have to).
Comment 19 Wolf Giesen (RETIRED) gentoo-dev 2006-06-11 23:39:55 UTC
One more "no".
Comment 20 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-12 02:22:14 UTC
Closing without GLSA, feel free to reopen if you disagree.