Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 563100 - <dev-db/pgpool2-3.5.2: Abruptly terminated connections hang
Summary: <dev-db/pgpool2-3.5.2: Abruptly terminated connections hang
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-15 07:07 UTC by Agostino Sarubbo
Modified: 2016-06-08 08:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-10-15 07:07:18 UTC
From ${URL} :

A vulnerability in pgpool was found leading to DoS of pgpool. If a connection is terminated abruptly, the connection is no longer usable, eventually causing the connection pool to be exhausted.

Reproducing steps and more info can be found here:

http://www.pgpool.net/mantisbt/view.php?id=147
https://bugzilla.redhat.com/show_bug.cgi?id=1265185


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-29 09:44:11 UTC
Fix is in the 3.4 branch upstream:

http://www.pgpool.net/mantisbt/view.php?id=147

Please bump and cleanup the vulnerable versions.

Upstream download:

http://www.pgpool.net/mediawiki/index.php/Downloads
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-06-06 10:03:17 UTC
Still awaiting an ebuild from maintainer with appropriate patch or new code base.  Candidate for last rites.

@maintainer(s), please confirm patch or bump.
Comment 3 Aaron W. Swenson gentoo-dev 2016-06-07 11:07:44 UTC
commit ace051e1dfc0a27513384af32dd2b1e8be24fb44
Author: Aaron W. Swenson <titanofold@gentoo.org>
Date:   Tue Jun 7 07:06:57 2016 -0400

    dev-db/pgpool2: Remove Old
    
    Bug: 563100
    
    Package-Manager: portage-2.2.28

commit 7416f943e514cc8683c5d33041af046be9803421
Author: Aaron W. Swenson <titanofold@gentoo.org>
Date:   Tue Jun 7 06:51:36 2016 -0400

    dev-db/pgpool2: Version Bump
    
    Bug: 529508, 563100
    
    Package-Manager: portage-2.2.28
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-06-08 08:31:40 UTC
@Aaron, thanks for the bump and cleanup!