Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 178986 - app-arch/zoo Denial of Service Vulnerability (CVE-2007-1669)
Summary: app-arch/zoo Denial of Service Vulnerability (CVE-2007-1669)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: B3 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2007-05-18 11:20 UTC by Lars Hartmann
Modified: 2007-06-01 15:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Patchfile (zoo-2.10-CVE-2007-1673.patch,2.32 KB, text/plain)
2007-05-22 09:51 UTC, Icebird2000
no flags Details
modified patch (cve-2007-1669.patch,2.56 KB, patch)
2007-05-23 21:51 UTC, Lars Hartmann
no flags Details | Diff
ebuild (zoo-2.10-r3.ebuild,921 bytes, text/plain)
2007-05-23 21:52 UTC, Lars Hartmann
no flags Details
fixed patch (zoo-2.10-CVE-2007-1669.patch,2.45 KB, patch)
2007-05-23 21:56 UTC, Lars Hartmann
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-05-18 11:20:15 UTC
A vulnerability has been reported in Amavis, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to Amavis potentially invoking an insecure version of zoo or unzoo. This can be exploited to cause an infinite loop resulting in high CPU utilisation.

Solution:
The vendor recommends disabling the use of zoo or unzoo, or using a patched version of zoo.

Provided and/or discovered by:
The vendor credits Jean-Sebastien Guay-Leroux.

Original Advisory:
http://www.amavis.org/security/asa-2007-2.txt

Reproducible: Always
Comment 1 Lars Hartmann 2007-05-18 11:36:51 UTC
maintainers - please advice
Comment 2 Andrej Kacian (RETIRED) gentoo-dev 2007-05-18 19:14:27 UTC
I suggest patching app-arch/zoo with patch found in section VII here: <http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded>. We can then make amavisd-new depend on patched version of zoo, after stabilizing it for arches.

This would be more bearable than to wait for amavisd-new-2.5.1 and then stabilize it - 2.5.x brings some new stuff and config file changes which are not yet so well tested as 2.4.x.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-19 06:52:43 UTC
Not an amavisd-new issue. Unfortunately zoo is without a maintainer. Ticho, could you patch it?
Comment 4 Icebird2000 2007-05-22 09:51:38 UTC
Created attachment 119979 [details]
Patchfile

this is the patch as diff-file
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-22 15:06:32 UTC
Ticho ping.
Comment 6 Lars Hartmann 2007-05-23 21:51:54 UTC
Created attachment 120137 [details, diff]
modified patch

i modified the patch to let it patch cleanly.
Comment 7 Lars Hartmann 2007-05-23 21:52:49 UTC
Created attachment 120138 [details]
ebuild

an ebuild which uses my modified patch
Comment 8 Lars Hartmann 2007-05-23 21:56:57 UTC
Created attachment 120139 [details, diff]
fixed patch

now the finaly one (uploaded the wrong one first) - sorry for that
Comment 9 Andrej Kacian (RETIRED) gentoo-dev 2007-05-23 22:32:33 UTC
Sorry guys. I was, uhh... distracted, from all technology for past few days.

zoo-2.10-r3 is in the tree now.
Comment 10 Stefan Cornelius (RETIRED) gentoo-dev 2007-05-23 23:00:53 UTC
arches, please test and stable zoo-2.10-r3. thanks
Comment 11 Christian Faulhammer (RETIRED) gentoo-dev 2007-05-24 06:37:19 UTC
x86/amd64 stable
Comment 12 Gustavo Zacarias (RETIRED) gentoo-dev 2007-05-24 12:57:35 UTC
sparc stable.
Comment 13 Markus Rothe (RETIRED) gentoo-dev 2007-05-24 15:31:26 UTC
ppc64 stable
Comment 14 Raúl Porcel (RETIRED) gentoo-dev 2007-05-25 11:06:03 UTC
alpha stable
Comment 15 Tobias Scherbaum (RETIRED) gentoo-dev 2007-05-25 17:51:46 UTC
ppc stable
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-25 17:55:57 UTC
This one is ready for GLSA decision. I tend to vote YES.
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-05-31 09:27:58 UTC
I tend to vote NO.
Comment 18 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-06-01 15:14:30 UTC
no and closing, feel free to reopen if you disagree