Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 353955

Summary: <net-misc/stunnel-4.35: file descriptor leaks
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: gentoo, ramereth
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.stunnel.org/?page=sdf_ChangeLog
Whiteboard: B3 [glsa?]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 344117    
Attachments:
Description Flags
stunnel-4.35-libwrap.patch
none
stunnel-4.35-xforwarded-for.diff
none
stunnel-4.34-listen-queue.diff
none
stunnel-4.35.ebuild
none
stunnel-4.35.ebuild none

Description Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 12:12:26 UTC
From Changelog:

- CLOEXEC file descriptor leaks fixed on Linux >= 2.6.28 with glibc >= 2.10.

    Irreparable race condition leaks remain on other Unix platforms.
    This issue may have security implications on some deployments.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:00:15 UTC
Created attachment 261731 [details, diff]
stunnel-4.35-libwrap.patch
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:37:32 UTC
Created attachment 261735 [details, diff]
stunnel-4.35-xforwarded-for.diff

Man pages changed
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:40:34 UTC
Created attachment 261737 [details, diff]
stunnel-4.34-listen-queue.diff
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:45:19 UTC
Created attachment 261739 [details]
stunnel-4.35.ebuild
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:47:48 UTC
xforwarded-for was already stable (4.31-r1).

The listen-queue patch is new, (#344117) and was not in portage yet, so normally for security bumps, we would leave out the listen-queue patch.
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:51:17 UTC
Created attachment 261741 [details]
stunnel-4.35.ebuild

new SRC_URI
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 17:01:57 UTC
I've tested and can confirm that X-Forwarded-For works with 4.35.
Comment 8 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-09 15:47:15 UTC
4.36 is out, it includes the listen-queue and libwrap patch.
I hope Mike will decide to include x-forwarded-for in 4.37.
Comment 9 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-10 15:25:21 UTC
When asked for elaboration of the isse, Mike wrote:
------------------
Try this link:
http://kerneltrap.org/mailarchive/git-commits-head/2008/11/20/4175544
Comment 10 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-10 20:59:53 UTC
4.36 is considered "in-development", but the changelog already listed it, thus my confusion. So let's got with 4.35 for now.
Comment 11 Lance Albertson (RETIRED) gentoo-dev 2011-03-02 06:17:20 UTC
Committed. Thanks for the patches and ebuild!
Comment 12 Lance Albertson (RETIRED) gentoo-dev 2011-03-02 06:18:09 UTC
Oops, I forgot this was a security bug. It still needs to be stabilized and tested. 
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2011-03-30 08:47:53 UTC
Is this ready for stabilization?
Comment 14 Lance Albertson (RETIRED) gentoo-dev 2011-05-26 18:28:11 UTC
Pushed to the tree, thanks for the report!
Comment 15 Tim Sammut (RETIRED) gentoo-dev 2011-05-26 18:35:23 UTC
Hi, Lance, thanks for committing this. Please do not close security bugs. Is =net-misc/stunnel-4.35 suitable for stabilization?
Comment 16 Lance Albertson (RETIRED) gentoo-dev 2011-05-26 18:36:42 UTC
Oops, sorry about that. Yes it is.
Comment 17 Tim Sammut (RETIRED) gentoo-dev 2011-05-26 18:42:16 UTC
(In reply to comment #16)
> Oops, sorry about that. Yes it is.

Great, thanks, and no problemo.

Arches, please test and mark stable:
=net-misc/stunnel-4.35
Target keywords : "alpha amd64 arm hppa ppc ppc64 sparc x86"
Comment 18 Agostino Sarubbo gentoo-dev 2011-05-26 18:56:55 UTC
amd64 ok
Comment 19 Jeroen Roovers (RETIRED) gentoo-dev 2011-05-26 19:26:26 UTC
Stable for HPPA.
Comment 20 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-05-26 22:04:15 UTC
*** Bug 349074 has been marked as a duplicate of this bug. ***
Comment 21 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-05-27 06:15:02 UTC
ppc/ppc64 stable and x86/amd64 already done by ramereth
Comment 22 Raúl Porcel (RETIRED) gentoo-dev 2011-05-28 16:50:20 UTC
alpha/arm/ia64/sparc stable
Comment 23 Tim Sammut (RETIRED) gentoo-dev 2011-05-28 17:09:33 UTC
Thanks, everyone. GLSA Vote: no.
Comment 24 Pierre-Yves Rofes (RETIRED) gentoo-dev 2011-10-08 21:10:16 UTC
no too, closing