Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 342705 - <dev-vcs/monotone-0.48.1: Remote Denial of Service
Summary: <dev-vcs/monotone-0.48.1: Remote Denial of Service
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.monotone.ca/NEWS
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-10-26 06:05 UTC by Tim Sammut (RETIRED)
Modified: 2010-11-21 16:54 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2010-10-26 06:05:55 UTC
From $URL:

        0.48.1 bugfix release.

        Security related changes:

        - Running "mtn ''" or "mtn ls ''" doesn't cause an internal
          error anymore. In monotone 0.48 and earlier this behavior
          could be used to crash a server remotely (but only if it was
          configured to allow execution of remote commands).

          Therefore everyone running such a server should update as
          soon as possible.
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2010-10-29 07:59:03 UTC
Thank you for report, Tim. 0.99 version, that fixes this issue is in the tree. Arch teams, please, stabilize.

Tim, please, CC _all_ maintainers to bug reports, or they may stall longer then needed.
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2010-10-29 10:13:16 UTC
Why arches are here? There is no target as far as I can see
Comment 3 Markos Chandras (RETIRED) gentoo-dev 2010-10-29 12:34:42 UTC
Ok ignore me
Comment 4 Andreas Schürch gentoo-dev 2010-10-29 14:03:33 UTC
Do you really want to fast-track stabilize the fresh 0.99 version with that huge changelog in $URL, while there would be a bugfix-minor-release?!?
Personally, i'd rather go with the bugfixrelease and wait at least 30 days for 0.99...
Comment 5 Peter Volkov (RETIRED) gentoo-dev 2010-10-29 15:24:02 UTC
Ok, I've reviewed upstream blog and found that 0.99 has some problem on amd64. Although patch is there (and I've applied it in 0.99-r1) I've decided to push 0.48.1 for fast stabilization.

Arch teams please STABILIZE =dev-vcs/monotone-0.48.1. TIA.
Comment 6 Andreas Schürch gentoo-dev 2010-10-30 14:26:10 UTC
Tests passed over here, looks good to go on x86.
Comment 7 Markos Chandras (RETIRED) gentoo-dev 2010-10-31 12:25:21 UTC
amd64 done. One test failed but this is a security bug so I choose to proceed
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2010-11-01 12:02:58 UTC
stable x86, thanks Andreas
Comment 9 Brent Baude (RETIRED) gentoo-dev 2010-11-09 14:19:23 UTC
ppc done; closing as last arch
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2010-11-09 16:31:47 UTC
Peter or Daniel, a quick question on this note: 

> In monotone 0.48 and earlier this behavior
> could be used to crash a server remotely (but only if it was
> configured to allow execution of remote commands).

Do you know if the capability to run remote commands is enabled by default? Thanks.
Comment 11 Peter Volkov (RETIRED) gentoo-dev 2010-11-09 19:04:59 UTC
Tim, I've contacted upstream and got following answer:

(21:47:38) thm: I don't think any distribution packages a mtn server package that has remote stdio enabled.
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2010-11-09 19:09:42 UTC
Great, thanks, Peter.

GLSA Vote: No,
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2010-11-21 16:54:39 UTC
Vote: NO. Closing noglsa.