Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 134792 - net-p2p/amule: Information leak (CVE-2006-2691, CVE-2006-2692)
Summary: net-p2p/amule: Information leak (CVE-2006-2691, CVE-2006-2692)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.amule.org
Whiteboard: B4 [noglsa] DerCorny
Keywords:
Depends on: 135035
Blocks:
  Show dependency tree
 
Reported: 2006-05-29 08:59 UTC by orgoz2
Modified: 2006-07-30 12:19 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description orgoz2 2006-05-29 08:59:15 UTC
This new 2.1.2 version is a BUGFIX version, STABLE version, based on 2.1.1 and NOT on current development code.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-05-29 09:06:32 UTC
http://www.amule.org/
<snip>
aMule 2.1.2 released!
Posted by: Kry, 28.05.06 at 17:24
</snip>

# date
Mon May 29 18:04:43 CEST 2006

So yeah, pardon us that we didn't manage to release this in 30 minutes. Damnit, we are such slackers!

http://allen.brooker.gb.net/misc/kitten-0day.jpg
Comment 2 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-05-29 14:55:27 UTC
Hi all,

congrats for the very fast bump :)

i recommend you assign now this bug to the security team (product Gentoo Security / component vulns) because of an information disclosure vulnerability which could allow an attacker to read HTML, PHP or image files on the server, on versions <2.1.2 . This will call a vote on a GLSA issuing or not. Thanks in advance.
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-30 02:55:10 UTC
jup, shamelessly stealing the bug now.

Arches, please test and stable version 2.1.2, thanks.
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-30 02:56:08 UTC
accepting/setting severity
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2006-05-30 04:44:41 UTC
hrm.. I just did an cvs up in *cvs*/net-p2p/amule/ and I don't see version 2.1.2 in there.

Same for emerge --sync and then looking for this version.

you might forgot to commit?
Comment 6 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-30 04:50:34 UTC
Sorry, seems like I was a bit too trigger happy. waiting for net-p2p to provide fixed packages
Comment 7 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-08 06:59:39 UTC
arches, please test and stable 2.1.2, thanks
Comment 8 Markus Rothe (RETIRED) gentoo-dev 2006-06-08 08:01:33 UTC
stable on ppc64
Comment 9 Luis Medinas (RETIRED) gentoo-dev 2006-06-08 11:11:32 UTC
ding ding amd64 stableeeeee ding ding
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-08 14:58:02 UTC
ppc stable
Comment 11 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-08 16:48:38 UTC
CVE-2006-2691 & CVE-2006-2692
Comment 12 Joshua Jackson (RETIRED) gentoo-dev 2006-06-08 21:33:39 UTC
the mule heha'd at me so I marked it stable on x86.
Comment 13 Joshua Jackson (RETIRED) gentoo-dev 2006-06-08 21:35:25 UTC
and lagging bugs didn't remove x86 from the bug.
Comment 14 Thomas Cort (RETIRED) gentoo-dev 2006-06-10 07:59:28 UTC
no go for alpha. I get the following when attempting to run amule...

//////////////////////////////////////////////
Initialising aMule
Checking if there is an instance already running...
No other instances are running.
        aMule Version: aMule 2.1.2 using wxGTK2 v2.6.2

Terminated after throwing an instance of 'std::bad_alloc'
        what(): St9bad_alloc
        backtrace:
[2] ?? in amule [0x12006dfc8]
[3] wxEntry(int&, char**) in /usr/lib/libwx_base-2.6.so.0[0x2000089f2c0]
[4] ?? in amule [0x120153b90]
[5] __libc_start_main in /lib/libc.so.6.1[0x20000b77a30]
[6] ?? in amule [0x120058a58]

Aborted
//////////////////////////////////////////////

I get the same results with wxGTK 2.6.2-r1 and 2.6.3.2. I masked amule in profiles/default-linux/alpha/package.mask and dropped the ~alpha keyword from 2.1.2. If you need anything else, please re-add us.
Comment 15 Jon Hood (RETIRED) gentoo-dev 2006-06-12 08:25:55 UTC
tcort, please test amule-2.1.3 and let me know if it seems to work for alpha.
Comment 16 Thomas Cort (RETIRED) gentoo-dev 2006-06-15 09:30:58 UTC
(In reply to comment #15)
> tcort, please test amule-2.1.3 and let me know if it seems to work for alpha.

amule-2.1.3 still crashes.

$ amule
Initialising aMule
Checking if there is an instance already running...
No other instances are running.

--------------------------------------------------------------------------------
A fatal error has occurred and aMule has crashed.
Please assist us in fixing this problem by posting the backtrace below in our
'aMule Crashes' forum and include as much information as possible regarding the
circumstances of this crash. The forum is located here:
    http://forum.amule.org/board.php?boardid=67
If possible, please try to generate a real backtrace of this crash:
    http://www.amule.org/wiki/index.php/Backtraces

----------------------------=| BACKTRACE FOLLOWS: |=----------------------------
Current version is: aMule 2.1.3 using wxGTK2 v2.6.3 (Unicoded)
Running on: Linux 2.6.16.5 alpha

[2] ?? in amule [0x120061850]
[3] wxFatalSignalHandler in /usr/lib/libwx_baseu-2.6.so.0[0x200008c6528]
[4] ?? in /lib/libpthread.so.0 [0x20000056300]
[5] __pthread_mutex_lock in /lib/libpthread.so.0[0x2000004f2e4]
[6] wxMutexInternal::Lock() in /usr/lib/libwx_baseu-2.6.so.0[0x200008b7a58]


--------------------------------------------------------------------------------
Aborted
Comment 17 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-15 10:52:36 UTC
net-p2p please advise.
Comment 18 Jon Hood (RETIRED) gentoo-dev 2006-06-15 22:29:02 UTC
This seems to be isolated on alpha; I cannot reproduce it. Is there any way we can drop alpha support until an amule dev can take a look at this? Your advice in this situation is better than any I could give.
Comment 19 stefanero 2006-06-16 00:39:58 UTC
Hey

tcort can you enable debug on the ebuild and run aMule in gdb to produce a real backtrace?
also a good idear might be to move your old .aMule dir out of the way and start for this test with a clean one.

stefanero
Comment 20 Thomas Cort (RETIRED) gentoo-dev 2006-06-16 05:47:05 UTC
(In reply to comment #18)
> This seems to be isolated on alpha; I cannot reproduce it. Is there any way we
> can drop alpha support until an amule dev can take a look at this? Your advice
> in this situation is better than any I could give.

Alpha support has already been dropped, see comment #14, "I masked amule in
profiles/default-linux/alpha/package.mask and dropped the ~alpha keyword from
2.1.2."

(In reply to comment #19)
> tcort can you enable debug on the ebuild and run aMule in gdb to produce a 
> real backtrace?

stefanero, sure. I'll do that and post the results to the "aMule crashes" forums mentioned in the error message.
Comment 21 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-30 08:57:23 UTC
Did this ever get fixed for alpha?
Comment 22 Thomas Cort (RETIRED) gentoo-dev 2006-06-30 09:15:10 UTC
(In reply to comment #21)
> Did this ever get fixed for alpha?

No, see comment #14 and comment #16.

I filed an upstream crash report[1]. I guess I forgot to set e-mail notification on the aMule forums because I just noticed the reply. I'll post more debugging information to the crash report when I have some time to spare (I've been busy testing and stabilizing stuff for 2006.1). I'm hoping it will get fix. In the meantime, amule is masked on alpha (as I stated in Comment #14) because the amule versions in portage either crash at startup or are vulnerable.

[1] http://forum.amule.org/thread.php?threadid=10352
Comment 23 Thierry Carrez (RETIRED) gentoo-dev 2006-07-29 05:51:36 UTC
I think this is ready for GLSA vote, I tend to vote no.
Comment 24 Matthias Geerdsen (RETIRED) gentoo-dev 2006-07-29 09:44:19 UTC
0.5 for no glsa
Comment 25 Wolf Giesen (RETIRED) gentoo-dev 2006-07-30 00:01:56 UTC
I can't really decide (with the info being quite vague, too). On one hand it's cheesy, and of course amuleweb is nothing to be trusted in the first place (read: don't make it world-accessible). But then again, I would not want my phpBB config.php or DokuWiki user.auth.php shared with the world...

.5 for "yes" :]
Comment 26 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-30 12:19:38 UTC
Voting a NO and closing. Feel free to reopen if you disagree.